Skip to main content

How to manage a user's access

Beyond inviting people, the Users tab is where you suspend, restore and retire access. Each action fits a different situation, and picking the wrong one is the usual source of confusion.

Which action to use​

SituationActionEffect
Someone is away, or you suspect their account is compromisedDisable accountSign-in is refused immediately. Groups and grants are kept.
The person is backEnable accountAccess returns exactly as it was.
The person left the company or changed roles for goodArchiveThe person is retired and stops appearing in the default list.
An archived person came backUnarchiveThey return, with their previous access.
The invite never arrivedResend inviteA new invite e-mail is sent.
The invite was a mistake, or the person never joinedDelete userThe pending account is removed for good.

Disabling is the reversible, immediate one. Archiving is the tidy-up. Deleting only exists while the invite is still pending, because after that there is history attached to the account.

Prerequisites​

  • iam:users:update to disable, enable and archive.
  • iam:users:invite to resend an invite.
  • iam:users:remove to delete a pending user.

Where the actions are​

Some live on the row, some only inside the person's page:

ActionRow menuUser detail
Open detailsYes
Archive / UnarchiveYesYes
Delete user (pending only)YesYes
Resend invite (pending only)Yes
Disable / Enable accountYes
EditYes

To disable an account or resend an invite, open the person first: Users tab, click the row or choose Open details in the row menu.

Steps​

  1. Open IAM and go to the Users tab.
  2. Find the person. Use the search box, and the Show filter to include archived people.
  3. Open the row menu, or open their details for the full set of actions.
  4. Where a reason is asked, write it, because it goes to the audit log.
  5. Confirm.

User states​

A person is always in one of three states, and may additionally be archived:

  • Pending: invited, has not accepted yet. Cannot sign in.
  • Active: accepted the invite and can sign in.
  • Blocked: sign-in refused, permissions untouched. This is the state left by Disable account.

Notes​

  • You can only disable an active account. A pending or already disabled one is refused, so invite the person again, or enable first.
  • Archiving twice, or unarchiving someone who is not archived, is refused rather than silently ignored.
  • Resending only works while the invite is pending. Once accepted, there is nothing to resend.
  • Disabling does not remove groups or grants. When you enable the account again, the previous access comes back. If you wanted it gone, remove the assignments too.