Skip to main content

User & Roles

User & Roles is where you manage membership and access for the organization. It has four tabs: Open it from the sidebar gear → Platform settings → User & Roles. Managing users and roles requires IAM Admin access (or Owner / Global Admin / Break the Glass, which include it).

Access model

Access has two layers:
  1. Org roles — Owner, Global Admin, Break the Glass, plus product templates (Admin / Editor / Viewer). Owner and Global Admin have Admin on every product plus billing; Owner can also delete the organization. Break the Glass has the same permissions as Global Admin (emergency password login — see Break-glass).
  2. Product permissions — No access, Viewer, Editor, Admin — set per product (and optionally scoped to specific TrustGate gateways or TrustGuard collectors).
Roles in the Roles tab are reusable templates that apply an org role or a product permission matrix when you invite or edit a user. Normal users are passwordless (magic link or SSO). Only Break the Glass accounts use a password (minimum 30 characters).

Structural roles

See Break-glass access for the difference between Break the Glass accounts and the SSO break-glass email list.

Product permission levels

Levels nest: Viewer ⊂ Editor ⊂ Admin.

Capability summary by product

The Permissions tab in the UI shows the same cards filtered to the products contracted for your organization.

Predefined role templates

Custom roles let you pick an arbitrary matrix of product levels (and gateway / collector scopes for TrustGate / TrustGuard). Global Admin and Break the Glass templates are view-only — they cannot be edited or duplicated.

Users

The Users tab lists every active member. Columns: Toolbar: search, filter by access level, refresh, Add User.

Add a user

  1. Click Add User.
  2. Enter the invitee’s email.
  3. Optionally apply a role template, or set the permission matrix manually (products + platform modules).
  4. For TrustGate / TrustGuard, optionally restrict access to specific gateways or collectors.
  5. If you choose Break the glass, set a password of at least 30 characters. The account is created active and the user is notified.
  6. Send the invitation.
The invite appears under Invite sent. When accepted, the user moves to Users.
If the organization enforces SSO, invitees sign in through your identity provider. If SCIM or Entra user sync is enabled, most users should be provisioned automatically — see SCIM and User sync.

Edit access

Use Edit on a user row to change their role template or permission matrix. The Owner row is read-only for access changes — transfer ownership instead.

Transfer ownership

Owners can transfer ownership to an eligible member:
  1. Open the row actions → Transfer ownership.
  2. Type the member’s email to confirm.
The previous Owner becomes a Global Admin. There is always exactly one Owner.

Remove a member

Removing a member immediately revokes their sessions and product access. Past audit events remain (actor email stays as-is). Anti-lockout rules prevent removing the last Global Admin path that would leave the organization unmanageable. If the user was provisioned by SCIM, they may be re-created on the next IdP sync unless you also remove them upstream. For SCIM-managed organizations, deprovision in the IdP.

Invite sent

Lists invitations that have not been accepted yet (and related invite statuses). For each pending invite you can:
  • Resend — send the invitation email again.
  • Cancel — revoke the invitation so the link stops working.

Roles

Create and manage custom roles, or view predefined templates. When inviting or editing a user, picking a role applies its template in one step. SSO group mappings can also target platform roles.

Permissions tab

Educational reference cards for No access, Viewer, Editor, Admin, Global Admin, Owner, and Break the Glass — the same matrix documented above, filtered to your contracted products.