1. Docs
  2. Administrators and roles
  3. Invite and manage administrators

Invite and manage administrators

Invite an administrator into the Admin Workspace, change what a pending invitation grants, grant and revoke roles, and deactivate or remove someone.

Invite an administrator

In the Admin Workspace, Administrators → Users is the roster. Its header offers Invite and Assign Administrator, and its three tabs are Users, Invites, and Assignments. An invitation always names a role, because acceptance grants it immediately.

Application
Admin Workspace
Path
AdministratorsUsers
Opens with
  • administrators.manage Invite an administrator, deactivate one, and remove one. Deciding which role they hold is a separate capability, so this alone lets you manage the roster rather than what the roster can do.
Context
Account-wide, for administrators who govern the Account.
Invite an administrator
Open Administrators → Users from the left nav and click Invite. The Invite an administrator dialog opens with a note that acceptance grants the role at once.Enter the invitee's email, first name, and last name. Send invite stays disabled until a role is chosen.Choose a role. An account-wide role such as Administrator shows a hint that it applies account-wide and asks for no Environment; an Environment role asks which Environment, and optionally which place, it should reach.Click Send invite. An Invitation sent. toast appears and the invitation is listed on the Invites tab as Pending. It lasts seven days.The invitee follows the link in their email to the Accept Your Invitation page, sets a password, and clicks Create Account & Join. Their grant then appears on the Assignments tab.

Change what a pending invitation grants

A pending invitation's role can be changed without invalidating the link already sent.

Change what a pending invitation grants
On the Invites tab, click the pending invitation's row. Its drawer opens and names the role it will grant and how far that reaches.Click Change role. The Change what this invite grants dialog opens, pre-filled with the current role, and warns that the invitation has already been sent.Choose the new role and click Save change. An Invitation updated. toast appears and the drawer names the new role.The same drawer offers Resend invite, which issues a fresh link, and Revoke invite, after which the link stops working.

Grant or revoke a role

The Assignments tab is one row per grant: who holds which role, and how far it reaches. This is the list to read when the question is what someone can actually do.

Grant or revoke a role
Open the Assignments tab and click Assign Administrator. The Assign an administrator dialog opens.Choose the person, then the role. For an account-wide role the Environment and place questions disappear and a note says the grant applies account-wide; for an Environment role, pick the Environment and optionally the place it should reach.Click Assign. An Administrator assigned. toast appears and a new row lists the person, the role, and its reach. Someone holding two roles appears on two rows, one per grant.To take a grant back, click Revoke on its row. The Revoke this administrator? dialog confirms it; click Revoke access. An Administrator revoked. toast appears, that row is gone, and the person's other grants are untouched.

Deactivate, reactivate, or remove someone

Three different actions. Deactivating blocks sign-in to this Account while keeping the person's record and grants, and is reversible. Removing deletes their membership in this Account only; coming back means a fresh invitation. Neither touches your end-user directory.

Deactivate, reactivate, or remove someone
On the Users tab, click the person's row. The User Details drawer opens with an Active badge and, in its footer, Deactivate and Remove from Account.Click Deactivate. The Deactivate user dialog states that they are blocked from signing in immediately, that any active sessions are revoked, and that their membership, roles, and data are preserved. Confirm with Deactivate; a User deactivated toast appears and the badge reads Inactive.To let them back in, open the drawer and click Activate. There is no confirmation; a User activated toast appears and the badge returns to Active.To remove them, click Remove from Account. The Remove user dialog explains that their access to this Account and its Applications is revoked, that their login and any other Accounts are untouched, and that they can be re-invited. Confirm with Remove; a User removed from account toast appears and the row is gone.
If you don't see this

Each control on the Users page exists only for someone who may use it. When something described above is missing, one of these is why:

Administrators is not in the left nav. Your administrator role carries no account-governance capability. Opening Users needs administrators.manage.Your own row offers no Deactivate or Remove from Account. Nobody can act on their own membership; the drawer says so and points to Profile settings.The owner's row offers no actions either. The account owner cannot be deactivated or removed by anyone.Assign Administrator lists a role you cannot grant. A role can only be granted by someone holding admin_governance.manage; the roster and the grants are two different capabilities.Someone accepted but landed in the Developer Console, not here. That is expected for an account-wide role: it carries Console access, and the product switcher in the Console brings them to the Admin Workspace.
Environment
API version
v1.0
On this page Was this page helpful?

Tell us how we can improve this guide.