User & Roles
User & Roles is where you manage membership and access for the organization. It has four tabs:
Open it from the sidebar gear → Platform settings → User & Roles.
Managing users and roles requires IAM Admin access (or Owner / Global Admin / Break the Glass, which include it).
Access model
Access has two layers:- Org roles — Owner, Global Admin, Break the Glass, plus product templates (Admin / Editor / Viewer). Owner and Global Admin have Admin on every product plus billing; Owner can also delete the organization. Break the Glass has the same permissions as Global Admin (emergency password login — see Break-glass).
- Product permissions — No access, Viewer, Editor, Admin — set per product (and optionally scoped to specific TrustGate gateways or TrustGuard collectors).
Structural roles
See Break-glass access for the difference between Break the Glass accounts and the SSO break-glass email list.
Product permission levels
Levels nest: Viewer ⊂ Editor ⊂ Admin.Capability summary by product
The Permissions tab in the UI shows the same cards filtered to the products contracted for your organization.
Predefined role templates
Custom roles let you pick an arbitrary matrix of product levels (and gateway / collector scopes for TrustGate / TrustGuard). Global Admin and Break the Glass templates are view-only — they cannot be edited or duplicated.
Users
The Users tab lists every active member. Columns:
Toolbar: search, filter by access level, refresh, Add User.
Add a user
- Click Add User.
- Enter the invitee’s email.
- Optionally apply a role template, or set the permission matrix manually (products + platform modules).
- For TrustGate / TrustGuard, optionally restrict access to specific gateways or collectors.
- If you choose Break the glass, set a password of at least 30 characters. The account is created active and the user is notified.
- Send the invitation.
Edit access
Use Edit on a user row to change their role template or permission matrix. The Owner row is read-only for access changes — transfer ownership instead.Transfer ownership
Owners can transfer ownership to an eligible member:- Open the row actions → Transfer ownership.
- Type the member’s email to confirm.
Remove a member
Removing a member immediately revokes their sessions and product access. Past audit events remain (actor email stays as-is). Anti-lockout rules prevent removing the last Global Admin path that would leave the organization unmanageable. If the user was provisioned by SCIM, they may be re-created on the next IdP sync unless you also remove them upstream. For SCIM-managed organizations, deprovision in the IdP.Invite sent
Lists invitations that have not been accepted yet (and related invite statuses). For each pending invite you can:- Resend — send the invitation email again.
- Cancel — revoke the invitation so the link stops working.
Roles
Create and manage custom roles, or view predefined templates.
When inviting or editing a user, picking a role applies its template in one step. SSO group mappings can also target platform roles.
Permissions tab
Educational reference cards for No access, Viewer, Editor, Admin, Global Admin, Owner, and Break the Glass — the same matrix documented above, filtered to your contracted products.Related
- General — organization name, leave, and delete.
- Microsoft Entra ID SSO / Generic OIDC SSO — sign-in for members.
- SCIM Provisioning — automate member creation and removal.
- User sync & group mappings — map IdP groups to platform roles.
- Break-glass access — SSO email allowlist and Break the Glass accounts.
- Audit Logs — invites, accepts, role changes, and removals are recorded.