How to manage a user's access
Beyond inviting people, the Users tab is where you suspend, restore and retire access. Each action fits a different situation, and picking the wrong one is the usual source of confusion.
Which action to use
| Situation | Action | Effect |
|---|---|---|
| Someone is away, or you suspect their account is compromised | Disable account | Sign-in is refused immediately. Groups and grants are kept. |
| The person is back | Enable account | Access returns exactly as it was. |
| The person left the company or changed roles for good | Archive | The person is retired and stops appearing in the default list. |
| An archived person came back | Unarchive | They return, with their previous access. |
| The invite never arrived | Resend invite | A new invite e-mail is sent. |
| The invite was a mistake, or the person never joined | Delete user | The pending account is removed for good. |
Disabling is the reversible, immediate one. Archiving is the tidy-up. Deleting only exists while the invite is still pending, because after that there is history attached to the account.
Prerequisites
iam:users:updateto disable, enable and archive.iam:users:inviteto resend an invite.iam:users:removeto delete a pending user.
Where the actions are
Some live on the row, some only inside the person's page:
| Action | Row menu | User detail |
|---|---|---|
| Open details | Yes | |
| Archive / Unarchive | Yes | Yes |
| Delete user (pending only) | Yes | Yes |
| Resend invite (pending only) | Yes | |
| Disable / Enable account | Yes | |
| Edit | Yes |
To disable an account or resend an invite, open the person first: Users tab, click the row or choose Open details in the row menu.
Steps
- Open IAM and go to the Users tab.
- Find the person. Use the search box, and the Show filter to include archived people.
- Open the row menu, or open their details for the full set of actions.
- Where a reason is asked, write it, because it goes to the audit log.
- Confirm.
User states
A person is always in one of three states, and may additionally be archived:
- Pending: invited, has not accepted yet. Cannot sign in.
- Active: accepted the invite and can sign in.
- Blocked: sign-in refused, permissions untouched. This is the state left by Disable account.
Notes
- You can only disable an active account. A pending or already disabled one is refused, so invite the person again, or enable first.
- Archiving twice, or unarchiving someone who is not archived, is refused rather than silently ignored.
- Resending only works while the invite is pending. Once accepted, there is nothing to resend.
- Disabling does not remove groups or grants. When you enable the account again, the previous access comes back. If you wanted it gone, remove the assignments too.