Manage users and permissions
Penfield uses role-based access control (RBAC). A user's role determines what they can view and manage.
Only a Super Admin can open the user-management page and manage roles.
Roles
| Role | Permissions |
|---|---|
| Super Admin | Manages users and role assignments, system settings, integrations, and all operational and reporting features. |
| Admin | Has broader visibility into all views and reports. An Admin cannot manage users, roles, or system configuration. |
| Analyst | Performs day-to-day analyst work within the user's assigned scope. An Analyst cannot manage users, roles, or system configuration. |
Use the Super Admin role only for users who need to manage operational features. A Super Admin cannot change their own role or delete their own account, and the last Super Admin cannot be demoted or deleted.
Authentication modes
The Users page displays the deployment's authentication mode:
- Local mode: Penfield manages user accounts, profile details, password-setup links, and roles.
- SSO mode: Your identity provider manages user access and profile information. Penfield manages only the user's Penfield role.
Follow the instructions for your deployment's mode.
Open the Users page
- In the left sidebar, select your name at the bottom.
- In the profile menu, select Users.
The Users page displays the deployment's authentication mode and the users you are authorized to manage.
Local mode
View and find users
The Users page lists each user's email, name, role, authentication method, creation date, and available actions.
Use Search by email or name to find a user, or select All roles to filter the list by role. Select the refresh button to reload the list.
Add one user
- Select Add user.
- On the Single invite tab, enter the user's email address.
- Select the user's initial role.
- Optionally enter the user's first and last name.
- Select Create user.
- Select Copy recovery link and send the link to the user through a secure channel.
The user follows the recovery link to set their password and activate the account.
A recovery link is a one-time secret. Anyone with the link can set the user's password. It expires after 7 days, so share it securely and do not open it on the user's behalf.
Add multiple users
- Select Add user, then select the Bulk invite tab.
- Enter email addresses separated by commas or new lines. You can enter more than 10 users; Penfield processes them in batches of up to 10 at a time.
- Select the role to assign to all users in the batch.
- Select Invite users.
- Securely share each generated recovery link with its corresponding user.
If users require different roles, invite them in separate batches or update their roles after creation.
Change a user's role
In the Role column, select a new role from the user's dropdown. The change takes effect immediately and is recorded in the audit log.
Edit a user
- In the Actions column, select Edit.
- Update the email address, first name, or last name.
- Select Save changes.
Create a password setup or recovery link
Use this action when a local user needs to set or reset their password:
- In the Actions column, select Send recovery link.
- Select Copy recovery link.
- Send the one-time link to the user through a secure channel.
Creating a new recovery link invalidates the previous recovery flow for that user.