Skip to content

User Management

Under Admin → Users you manage all accounts of your organization.

The user list

ColumnMeaning
NameDisplay name
EmailLogin address
RoleAssigned role → Roles
StatusActive or deactivated
2FAWhether two-factor authentication is set up
Last loginTime of the last sign-in
ActionsEdit · Deactivate · Send password link · Delete

Click a column header to sort. The filters at the top narrow by role and status; the search box finds names and email addresses. The Show deleted switch reveals deleted accounts (see below).

Inviting a person

The normal way to add somebody. The person you invite receives an email and chooses their own password — you set no password and never have to pass one on.

  1. Click Invite person.
  2. Enter the email address.
  3. Optionally suggest a name — they can change it while setting up.
  4. Choose the role.
  5. Choose the language of the email (German or English).
  6. Click Send invitation.

They receive an email from noreply@clavis-rallye.de, follow the link, choose their name and password — and are then signed in with exactly the role you gave them. The link is valid for 7 days and works exactly once.

Pending invitations

Above the user list are all invitations that have been sent but not yet redeemed — with address, role, who invited them and how much longer the link lasts.

ActionEffect
ResendSends a new email. The old link stops working immediately and the validity period restarts. The right move when the email never arrived or was deleted.
WithdrawThe link stops working immediately and the invitation disappears from the list. For mistyped addresses or people who turn out not to need access.

An invitation marked Not delivered could not be handed to the mail server. Check email delivery, then resend it.

Creating a user with a password

Only needed when somebody cannot receive email — a shared device account, for example.

  1. Click Create user.
  2. Enter email, display name, a password and the role.
  3. Click Create.

This way you know another person's password and have to transmit it safely. Wherever possible, Invite person is the better route.

First sign-in of admins

If somebody gets the Org Admin role, they are taken through two-factor setup on their first sign-in — it is mandatory and cannot be skipped. See 2FA.

Forgotten passwords

Users help themselves: Forgot password? on the sign-in page, enter the email address, follow the link in the mail, set a new password. The link is valid for one hour and works once.

If somebody is still stuck, the Send password link action in the user list triggers the same email. You never see the new password — by design: a password belongs to nobody but the person themselves.

After every password change the affected person automatically receives a confirmation email. If it was not them, that is their warning.

Editing a user

Edit lets you change the display name and the role. A role change takes effect immediately; the person sees the matching menu entries on their next page load.

Deactivate rather than delete

Deactivate blocks sign-in but leaves all data untouched. This is the right move when somebody leaves or pauses — reversible at any time.

Deleting and restoring

Delete first only removes the account from the list:

  • The account stays restorable for 30 days. Turn on Show deleted and use the Restore action.
  • After those 30 days the account is anonymized automatically: name and email are irreversibly replaced. Its audit-log entries remain (they must be retained) but can no longer be attributed to a person.

After anonymization

From that point there is no way back — not even for the operator. If someone should only temporarily lose access, deactivate them instead of deleting.

Guests

Guests have no account and therefore do not appear in this list. They are created when they join a run and are deleted automatically once the retention period expires.