Manage users system-wide (admin)
Super-admin surface for user lifecycle: disable, reset password, reset 2FA. For org-scoped membership, see Manage members and roles.
Who can do this
- Super-admin only. The page lives at Admin → Users and doesn't show up for non-admins.
What you can do
The page lists every user in the system regardless of org membership, with their email, name, super-admin flag, active flag, and 2FA enrolment state.
Per-row actions:
| Action | What it does |
|---|---|
| Edit | Change name (rare; users self-edit too) |
| Set password | Sets a new password directly. Hand it to the user out-of-band; they change it on first login. Doesn't bypass the password policy. |
| Reset 2FA | Clears the user's TOTP secret. They log in with password only on next sign-in and re-enrol. Use when they've lost their authenticator + don't have recovery codes. |
| Toggle active | Soft-disable. The user can't log in until you flip it back. Existing sessions die on next request. Use for offboarding or compromised accounts. |
| Toggle super-admin | Promote / demote. Be conservative — super-admin bypasses casbin. |
| Delete | Soft delete (deleted_at set). The user can't log in; their org memberships go away on next refresh. Their authored content (releases, alarms, audit log entries) keeps their snapshotted name + email. |
Audit + compliance
Every action on this page lands in the audit log (Admin → Audit Logs) with the actor (you), the target user (by ID), and a timestamp. The audit log is append-only.
For compliance reviews:
- "Who has super-admin?" — filter the user list by the
super_admin = truecheckbox - "Who's been disabled?" —
active = false - "Who hasn't enrolled in 2FA?" —
2fa_enabled = false(handy when you're enforcing 2FA across the company)
When to use this vs the org Members page
| Question | Use… |
|---|---|
| "Add Alice to org X with role Y" | Org Members page (org-scoped) |
| "Alice forgot her password" | Admin Users → Set password |
| "Bob lost his phone" | Admin Users → Reset 2FA |
| "Carla left the company" | Admin Users → Disable (or delete) |
| "Make Dan a super-admin" | Admin Users → Toggle super-admin |
Common errors
permission denied— you're not a super-adminUSER_NOT_FOUND— the row was deleted between when the page loaded and when you clicked. Refresh.PASSWORD_TOO_SHORTetc. — your direct set didn't satisfy the policy
See also
- Manage members and roles — for org-scoped membership
- Reference: Admin pages
- Backend runbook: JWT/2FA issues