Every account has one of three roles:
| Role | In short |
|---|---|
| Administrator | Full access to the server. |
| Operator | Assigned sites only. |
| Read-only | Sees everything, changes nothing. |
The full table of what each role can do is in roles and permissions.
Add a user
- Open Users and press Add user.
- Fill in First name and Last name (optional), Email and a Password of at least 12 characters.
- Choose the Role.
- For an Operator, choose at least one site in Assigned sites.
- Press Add user.
The email is the name the person signs in with, and it is unique. Give the person the password over a safe channel: they can change it from Security.
Change the role or the sites
- In Users, open the row's Actions menu and choose Edit user.
- Change Role or Assigned sites.
- Press Save.
Role, sites and name change together: when the panel refuses the change, nothing changes. Taking the administrator role away from someone revokes their API tokens.
Disable an account
In Edit user switch on Account disabled and press Save. The person can no longer sign in, their sessions close and their API tokens are revoked. Switch it off to enable the account again.
Reset someone else's password
From the Actions menu choose Reset password, type the new password and press Reset password. That account's sessions and API tokens close. You change your own password from Security, not here.
Delete a user
From the Actions menu choose Delete and confirm. The account's sessions, tokens, site assignments and two-step verification go with it.
What the panel does not allow
- You cannot change your own role, or disable or delete your own account.
- The panel always keeps at least one enabled administrator: it refuses to demote, disable or delete the last one.
- There is no operator without sites: the panel asks for at least one.
- Users and tokens are managed only from a session in the panel, never with an API token.
Every change lands in the Audit log.
Next step
Protect the accounts with two-step verification.