Skip to main content

Manage users system-wide (admin)

Super-admin surface for user lifecycle: disable, reset password, reset 2FA. For org-scoped membership, see Manage members and roles.

Who can do this​

  • Super-admin only. The page lives at Admin → Users and doesn't show up for non-admins.

What you can do​

The page lists every user in the system regardless of org membership, with their email, name, super-admin flag, active flag, and 2FA enrolment state.

Per-row actions:

ActionWhat it does
EditChange name (rare; users self-edit too)
Set passwordSets a new password directly. Hand it to the user out-of-band; they change it on first login. Doesn't bypass the password policy.
Reset 2FAClears the user's TOTP secret. They log in with password only on next sign-in and re-enrol. Use when they've lost their authenticator + don't have recovery codes.
Toggle activeSoft-disable. The user can't log in until you flip it back. Existing sessions die on next request. Use for offboarding or compromised accounts.
Toggle super-adminPromote / demote. Be conservative — super-admin bypasses casbin.
DeleteSoft delete (deleted_at set). The user can't log in; their org memberships go away on next refresh. Their authored content (releases, alarms, audit log entries) keeps their snapshotted name + email.

Audit + compliance​

Every action on this page lands in the audit log (Admin → Audit Logs) with the actor (you), the target user (by ID), and a timestamp. The audit log is append-only.

For compliance reviews:

  • "Who has super-admin?" — filter the user list by the super_admin = true checkbox
  • "Who's been disabled?" — active = false
  • "Who hasn't enrolled in 2FA?" — 2fa_enabled = false (handy when you're enforcing 2FA across the company)

When to use this vs the org Members page​

QuestionUse…
"Add Alice to org X with role Y"Org Members page (org-scoped)
"Alice forgot her password"Admin Users → Set password
"Bob lost his phone"Admin Users → Reset 2FA
"Carla left the company"Admin Users → Disable (or delete)
"Make Dan a super-admin"Admin Users → Toggle super-admin

Common errors​

  • permission denied — you're not a super-admin
  • USER_NOT_FOUND — the row was deleted between when the page loaded and when you clicked. Refresh.
  • PASSWORD_TOO_SHORT etc. — your direct set didn't satisfy the policy

See also​