Skip to main content

User Roles and Permissions

An organization's members and the things they are allowed to do are managed from one place in the Gallium Console: open Settings and then Users. Every member of an organization is assigned one of two roles, which determines what they can see and change. This page explains where to find your members, what each role can do, and how to view and remove the people in your organization.

The Users Page

To work with your members, go to Settings and choose Users from the left navigation. The page is titled All Users and lists everyone who belongs to the organization.

Each member appears as a row with the following columns:

  • Name: the member's display name.
  • Email: the email address the member signs in with.
  • Last Login: when the member last signed in to the Console.
  • Role: the member's role, shown as a badge.
  • MFA: whether the member has multi-factor authentication turned on, shown as Enabled or Disabled.

To add someone new, use the Invite User button at the top right of the page.

Roles

There are exactly two roles you can assign to a member. Each one grants a fixed set of capabilities, so picking the right role at invitation time keeps your organization's access tidy.

  • Owner: can manage the organization's members (invite and remove users), in addition to everything a User can do. In service-provider organizations, Owners can also create child organizations.
  • User: can do everything else in the organization, such as managing deployments and virtual machines. A User cannot manage other members. This is the default role for new invitations.

You may also see two status badges in the Role column. These describe the state of an invitation for someone who has not joined yet, and are statuses rather than roles:

  • Pending Invite: the person has been invited but has not yet accepted.
  • Invite Expired: the invitation lapsed before it was accepted.

Viewing a User

To see the full details for a member, click their name in the All Users list. This opens their User Details page, which shows the Name, Email, Role, MFA status, and Last Login for that member.

Removing a User

Removing a member revokes their access to the organization. You can do this from either the list or the member's detail page.

  1. Open Settings and then Users.
  2. Either click the member's name to open their User Details page, or find their row in the list.
  3. Click Remove User on the detail page, or use the remove icon on their row in the list.
  4. Confirm when prompted.

You cannot remove your own account. When you are viewing yourself, the Remove User button is hidden.

note

Organizations that use Single Sign-On manage their members through their identity provider instead. For those organizations the Users page is replaced by a read-only SSO Users list, and roles and membership are controlled in the identity provider.