1. Docs
  2. Identities
  3. Add and manage identities

Add and manage identities

Invite, create, or import end users into the Account-wide directory in the Admin Workspace, then manage each person's profile, Environment access, status, and security.

Invite an identity

In the Admin Workspace, Identities → Overview is the hub for adding people to the Account-wide directory: three cards for Invite, Create Identity, and Import CSV. An invitation here carries no role; naming an Environment grants the person access to it on acceptance, and roles are assigned afterwards in the Developer Console.

Application
Admin Workspace
Path
IdentitiesOverview
Opens with
  • identities.manage Create, edit, and deactivate end users anywhere in the account. The account-wide counterpart of administering people in one place.
Context
Account-wide, for administrators who govern the Account.
Invite an identity
Open Identities → Overview from the left nav and click Send invite on the Invite card. The Invite Identity dialog opens. The same dialog opens from Invite Identity in the Directory header.Enter the email, first name, and last name.Leave Grant access to an Environment off for a directory-only invitation, or turn it on and pick an Environment so the person can sign in there as soon as they accept.Send the invitation. An Invitation sent to … toast appears, and on Identities → Directory the Invites tab lists it as Pending with its Environment, or Directory-only.The recipient follows the emailed link, confirms their name, sets a password, and clicks Create Account. The identity becomes active and the invitation flips to Accepted. Invitations expire after 7 days.To manage a pending invitation, click its row on the Invites tab: Resend invite issues a fresh link (once every 5 minutes), and Revoke invite stops the link working. The Environment filter narrows the tab to one Environment or to Directory-only invitations.

Create an identity directly

Creating writes the identity immediately, with no email. Use it to pre-provision people, migrate a directory, or stage identities you will attach to Environments later.

Create an identity directly
On Identities → Overview, click Create identity on the Create Identity card. The Create Identity dialog opens.Enter the email, first name, and last name, and optionally a starting password. Without one the person sets their own through a password reset or an invitation later.Leave Grant access to an Environment off for a directory-only identity, or turn it on and pick an Environment to grant access in the same step.Submit the dialog. A success toast appears and the identity is listed on Identities → Directory, showing which Environments it can access, if any. An identity created this way starts Unverified until its email is confirmed.

Import identities from a CSV

For a whole team at once. The wizard previews the file, maps its columns, validates every row against the Account, then submits in batches; one bad row fails on its own rather than sinking the import.

Import identities from a CSV
On Identities → Overview, click Upload CSV on the Import CSV card. The wizard opens on its upload step; the Account-tier wizard has no mode step.Choose the CSV. Required columns are email, first_name, and last_name; password, external_id, and environment_id are optional. The wizard previews the parsed rows and maps columns to fields, using a built-in alias table for headings like E-Mail or Surname; override any mapping from its dropdown.Advance to validation. Rows are checked against live Account data, and a row whose email already exists is flagged before anything is written.Submit. A results summary shows created against failed counts with a reason per failed row; the rest are committed. View Identities opens the Directory, where the imported identities are listed as directory-only until you grant Environment access.

Manage a person

Identities → Directory lists everyone in the Account, whatever Environment they can reach. Opening a person shows their record and every action that belongs to the Account-wide directory rather than to one place.

Application
Admin Workspace
Path
IdentitiesDirectory
Opens with
  • identities.manage Create, edit, and deactivate end users anywhere in the account. The account-wide counterpart of administering people in one place.
Context
Account-wide, for administrators who govern the Account.
Manage a person
Open Identities → Directory from the left nav and click a person's row. Their drawer opens with their profile, status, and the Environments they can access, and with Profile, Activity, and MFA tabs.Edit profile changes the name; the drawer and the row update on save.Add to Environment grants access to another Environment; Remove from Environment takes it away. Neither assigns a role: what a person may do inside an Environment is granted by role assignments in the Developer Console.Deactivate blocks sign-in everywhere while keeping the record and its Environment access; confirm in the Deactivate identity dialog and an Identity deactivated toast appears. Activate restores access at once.Send password reset emails the person a link to set a new password, and Resend verification email emails an unverified person a fresh link to confirm their address. Completing either also marks the email verified.On the MFA tab, Force-reset MFA deletes every enrolled factor, unredeemed recovery code, and trusted device so the person enrols afresh at their next sign-in; Revoke all sessions signs them out of every device and browser without touching their password. Both are reversible and say so.Erase identity, under More actions, is the one action that is not: it overwrites the person's details and deletes their assignments.
If you don't see this

Each control on these pages exists only for someone who may use it. When something described above is missing, one of these is why:

Identities with an Overview and Directory is not in the left nav. The Account-wide directory needs identities.manage. The other Identities entry, which opens on its own, is the operational view of the people in the places you administer; it is a different page with a different capability, workspace_identity.view.You are looking for roles. Roles are assigned per Environment in the Developer Console under Access Control → Identities, not here. This directory decides who exists and where they may sign in.A person shows no Environment access. They were invited or created directory-only. Use Add to Environment in their drawer.The Import CSV wizard offers no Invite or Create mode. That choice exists only on the Developer Console's Environment-scoped import; the Account-tier wizard always creates directory rows.
Environment
API version
v1.0
On this page Was this page helpful?

Tell us how we can improve this guide.