-
Notifications
You must be signed in to change notification settings - Fork 0
Gen3 Admin Users
- Open Users in the Control Panel.
- Locate operator or service accounts to adjust.
- Apply MFA and role policy per deployment standards.
- Avoid using tenant-app Users for operator identities—they are separate planes.
Control Panel users are operator accounts with a different trust boundary than tenant end users.
The Control Panel Users page is the deployment-wide identity workspace. It manages both Control Panel operator accounts and tenant-app accounts from one route, with filters that let you move between those two populations without leaving the page.
- viewing all accounts or switching to Control Panel-only or tenant-app-only views
- filtering by role and status
- searching by name, email, or tenant
- creating and editing users
- enabling or disabling accounts
- resetting MFA enrollment
- sending password resets
- resending welcome email
- importing users in bulk
- applying bulk actions to selected accounts
The page separates accounts into three operator-friendly views:
All accountsControl Panel accountsTenant accounts
Use those first before applying role or status filters.
The exact options depend on the selected account domain, but the current Gen 3 implementation distinguishes Control Panel operator roles such as super admin and environment admin from tenant-app roles such as tenant owner, tenant manager, and tenant user.
- Open
Users. - Choose the correct account domain first.
- Select Add User.
- Enter identity details.
- Choose the role and status.
- Save the account.
Use the row action or bulk action when a user must re-enroll MFA at the next sign-in.
Disable when access should stop without deleting the historical identity record.
Use bulk import when onboarding a prepared list of accounts. Make sure the CSV or pasted rows match the intended account domain so Control Panel-only roles are not imported through a tenant-only view.
- Pick the correct account domain before you create or import users.
- Assign the minimum role needed.
- Use disable before delete when you may need to preserve the account record.
- Check MFA posture before troubleshooting login issues elsewhere.