Skip to main content
Version: 2026.09

User Management

The Users page lists a tenant's people. From it you add people one at a time or from a CSV file, suspend and reactivate them, grant administrator roles, and manage their control tags, classification levels, tool access and keys. Agents are managed on the Agents page.

Navigation:

  • In the Admin Panel, Settings > Admin > Users (/admin/users) shows the people in your tenant. The tenant's name sits under the heading.
  • Platform Admin Console > Users (/console/users) shows every tenant's people, for Platform Administrators. See Platform Admin Console.

A Tenant Administrator manages the people in their tenant. A Platform Administrator manages everyone. A Platform Administrator who belongs to no tenant sees "Your account belongs to no tenant. Manage users from the Platform Admin Console." in the Admin Panel.

This page describes installations with tenant management. If Settings > Admin > Users has an Invited tab instead of Pre-registered, see On installations without tenant management.

The list​

  • In the Platform Admin Console, pick a tenant from the Tenant dropdown, or leave it on All tenants. The dropdown lists active tenants only.
  • Pick a status tab:
    • All (the default)
    • Active: people who can sign in and have done so
    • Pre-registered: people added who have not signed in yet and are not suspended
    • Suspended: people who cannot sign in until reactivated
  • Type in the search field to filter the loaded rows by name or email.

The heading shows Users (N), or Users (N+) when more rows remain; click Load more to fetch the next 100.

ColumnShows
Full NameThe display name
EmailThe email address
TenantPlatform Admin Console only: the tenant's name, or No tenant
StatusActive, Pre-registered or Suspended
AdminA pill for each administrator role the person holds, such as Platform Administrator or Tenant Administrator. A Tenant Administrator pill refers to the person's own tenant
Control TagsAssigned control tags
ClassificationInfosec level; shown only when infosec is enabled
Last Sign InWhen the person last signed in, or Never

Control Tags and Classification show a dash until the person first signs in.

Row actions​

Each row ends with an Edit user pencil, which opens the person's details, and a ⋮ menu:

  • Make tenant admin or Remove tenant admin; see Administrators.
  • In the Platform Admin Console, Make platform admin or Remove platform admin.
  • Below a separator, Suspend, or Reactivate for a suspended person.

Some actions are missing or disabled:

  • Your own row never offers Suspend, Remove tenant admin or Remove platform admin. When nothing else applies, its menu is disabled.
  • Any other row with no action for you has no menu.
  • An action that is blocked for now is disabled, with the reason under its name.

Add a person​

A person can hold one membership at a time, so you cannot add someone who belongs to another tenant.

  1. Click Add user in the top-right.
  2. Choose the tenant:
    • In the Platform Admin Console's Users list, pick it in the dialog's Tenant dropdown, which starts on the default tenant.
    • In the Admin Panel, the person joins your tenant.
    • In a tenant's Members section, they join that tenant.
  3. Enter the person's Email, First Name and Last Name. All three are required.
  4. Click Add user.

What happens next depends on whether Istari already knows the person:

  • If nobody holds that email address yet, the person is created and listed under Pre-registered until they first sign in.
  • If the person already exists and holds no membership, they are granted a membership in the tenant.

Until a person first signs in, you cannot assign their control tags, classification, tool access or keys.

Istari sends no invitation. Tell the person to sign in; When someone cannot sign in describes the account they need.

If the person cannot be added, the dialog says why:

SituationMessage
A Platform Administrator adds someone who belongs to another tenant"This person already holds a membership in another tenant."
A Tenant Administrator adds someone they cannot see, such as someone in another tenant"This email belongs to someone outside this tenant. Ask a platform administrator for help."
The person was created, but granting the membership failedThe dialog says so and offers Retry the grant

Pre-register people from a CSV file​

  1. In the Platform Admin Console, pick a tenant in the Tenant dropdown first. In the Admin Panel, people join your tenant.
  2. Click Add from CSV, next to Add user.
  3. Click Choose CSV file and pick a file.
  4. Check the preview, then click Pre-register N people.
  5. Wait for the run to finish, review the results, and click Close.

File format​

The first non-blank row is the header. Header names ignore case, and spaces, hyphens and underscores count as the same character, so First Name matches first_name.

ColumnHeaderNotes
Emailemail or email_addressRequired
Display namedisplay_nameOptional
First namefirst_nameJoined with the last name when display name is blank
Last namelast_nameJoined with the first name when display name is blank

Other columns are ignored and listed in the preview. Example file:

email,first_name,last_name
ada@example.com,Ada,Lovelace

A file is refused before anything is sent when it:

  • is larger than 1 MB;
  • cannot be read as CSV, for example because of an unclosed quote;
  • is empty, or has no rows below the header;
  • has no email column;
  • names the same column twice, for example both email and email_address;
  • has more than 1,000 rows. Split it and import each part.

Preview and results​

The preview says how many rows were read, how many will be pre-registered and how many will be skipped. A row with an invalid email address, or one that repeats an earlier row's address, is skipped and listed with its reason. Row numbers count every row in the file, blank ones included.

While the run continues, the dialog shows "Processed X of N" and stays open. When it finishes, each row has one outcome:

OutcomeMeaning
Pre-registeredNobody held the address; the person was created in the tenant
AddedThe person already existed and was granted a membership. For a suspended person the detail reads "This person is suspended; activate them from Users."
Already a memberThe person already held a membership in this tenant
RefusedThe row was not completed; the detail gives the reason, such as a person who belongs to another tenant, with the same message as in Add a person

Rows skipped in the preview are listed as Refused too.

Importing the same file again is safe: rows already done come back as Already a member. If a person was created but not added to the tenant, the detail ends with "The person was created but not added; import the file again to finish."

User details​

The Edit user pencil opens the person's details page. Back to Users returns to the list. If you cannot see the person, the page reads "This user is not available to you."

The page has up to three tabs: Details, Tool access (for people you administer) and Access keys.

Details tab​

RowShows
StatusActive, Pre-registered or Suspended
Display nameThe name given when the person was added, or their email address if none was given. After the person's first sign-in, the name from your sign-in provider. You cannot change it here.
EmailEditable until the person first signs in; see below
TenantThe person's tenant, or No tenant
CreatedWhen the person was added
Updated onWhen the person's record last changed
Last signed inWhen the person last signed in, or Never

Below the rows, a Roles section lists roles as checkboxes. A checked box means the person holds the role; clicking a box opens the same confirmation as the row menu, and a box you cannot use shows the reason. See Administrators.

The Control Tags section holds the person's control tags and, when infosec is enabled, their classification. Before the person first signs in, it reads "Available after <person's name> first signs in."

For people you administer, other than yourself, the bottom of the tab shows a Suspend User card, or a Reactivate user card for a suspended person.

Suspend a person​

Suspending stops a person from signing in. Who can suspend whom:

  • A Platform Administrator can suspend anyone but themselves.
  • A Tenant Administrator can suspend people in their tenant, except themselves and Platform Administrators. For a Platform Administrator, Suspend is disabled with "Only a platform administrator can suspend a platform administrator."
  1. Click Suspend on the person's row, or on the Suspend User card of their Details tab.
  2. Read the consequences:
    • The person cannot sign in until reactivated.
    • Their credentials stop working within thirty seconds.
    • Memberships and role grants are kept and return when they are reactivated.
  3. Click the button labelled Suspend <person's name>.

You cannot suspend the last active Platform Administrator; see Refusals.

Reactivate a person​

The administrators who can suspend a person can also reactivate them. Reactivating needs the person to hold a membership in an active tenant.

If the person holds no membership, Reactivate is disabled with "Grant a membership before activating." Grant one first:

  • Platform Administrator:
    1. On the person's Details tab, click Grant membership under the card.
    2. Pick an active tenant. If the tenant of their most recently revoked membership is active, it is selected to start with.
    3. Click Grant membership. Reactivate then becomes available.
  • Tenant Administrator: you can grant the membership again only if the person's revoked membership was in your own tenant. Add the person with Add user. Otherwise, ask a Platform Administrator.

If the person's membership is in a suspended tenant, Reactivate is refused with the same message, "Grant a membership before activating." Reactivate the tenant first.

To reactivate the person, click Reactivate on their row, or on the Reactivate user card of their Details tab. There is no confirmation.

Suspending a tenant revokes its memberships by default; see Suspend a tenant.

Edit an email before first sign-in​

A Platform Administrator, or a Tenant Administrator of the person's tenant, can correct a pre-registered person's email address:

  1. On the Details tab, click Edit email.
  2. Enter the address and click Save, or click Cancel.

An invalid address, or one someone else holds, is refused under the field.

Once the person signs in, the address comes from your sign-in provider and can no longer be edited here. If they sign in while you edit, Save reports "This person has signed in, so their email can no longer be changed here."

Manage tool access for a user​

The Tool access tab controls which tools and functions a person can run. It appears for a Platform Administrator, and for a Tenant Administrator of the person's tenant.

  • Granted tools lists each tool the person holds. Expand a tool to see its functions.
  • To add a tool, search for it with Add tool and pick it. A new tool starts with every function selected.
  • A tool's checkbox selects or clears all its functions. It is checked only when every function is selected.
  • A tool saved with every function selected also covers functions added to it later. A tool saved with some functions selected covers only those.
  • To remove a tool, click the X beside it.
  • Save replaces the person's tool access with the list as shown. Discard drops your changes.

If only part of a save succeeds, a message says so and the list reloads to show what the person holds now; review it and save again.

Before the person first signs in, the tab reads "Available after <person's name> first signs in."

Manage keys for a user​

The Access keys tab lists a person's access keys for programmatic access to the Istari Digital Platform API.

A key cannot be generated until the person has signed in; before then, Generate fails with "An error occurred while generating the key."

To revoke a key, click Revoke key on its row and confirm with Revoke.

To generate a key:

  1. Click Generate Key.
  2. In the New Access Key dialog, optionally fill in Name (optional), and set Expiration: 30 days, 90 days, 180 days, 1 year (maximum) (the default), or Custom date….
  3. Click Generate. The keypair is generated in your browser.
  4. Click Download credentials and share the file with the person securely. The private key is not shown again.

Assign Classification Level to a User​

Availability

The Classification column and row appear only when Infosec Levels are enabled for your deployment (see Infosec Levels).

You can assign a level from the users table Classification column or from the person's details:

  1. In the users table, find the Classification column (or open the person's details).
  2. Click the user's current classification level (or "Set level..." if none is assigned).
  3. A dropdown appears listing all available infosec levels with their color indicators.
  4. Select the desired level.
  5. The assignment is saved immediately with a confirmation toast.

This determines the maximum infosec level the user can view and assign to resources.

Assign Control Tags to a User​

Assigning a tag to a user is what lets that user satisfy the need-to-know check on any Resource that carries the same tag. That includes Resources already on the platform and Resources that arrive through a receiving connection after a transformation rule writes a local tag onto them. See Control Tags.

  1. In the users table, find the Control Tags column (or open the person's details).
  2. Click the tags area for the user (shows existing tags as chips, or a small "add" indicator).
  3. In the Edit Control Tags dialog:
    • Select or deselect tags using the multi-select list.
    • Optionally provide a reason for the change in the text area.
  4. Click Save.

When someone cannot sign in​

A person who signs in to your sign-in provider but cannot use Istari sees You don't have access to Istari yet, with one of these reasons:

MessageWhat to do
"Your sign-in worked, but no account is registered for you here."Add the person to their tenant. If you added them under a different address, correct it.
"Your account is registered but belongs to no tenant yet."A Platform Administrator grants the person a membership; see Reactivate a person.
"Your account has been suspended."Reactivate the person.
"Your tenant has been suspended."A Platform Administrator reactivates the tenant and then each person.
"Your account could not be matched to a registered user."Nothing in the Admin Panel resolves this; refer it to your IT administrator.

Adding a person sends no invitation and creates no account in your sign-in provider. The person signs in with an account there that meets both conditions:

  • It is in the organization linked to their tenant.
  • Its verified email address matches the one you entered.

Otherwise Istari does not match their sign-in to the person you added. If they have no such account, ask your IT administrator to create one.

On installations without tenant management​

If the Users page has an Invited tab, your installation does not use tenant management, and the page works as described in this section.

View users​

  1. Pick an organization from the dropdown at the top of the page (Select organization...).
  2. Use the tabs to filter the user list:
    • All — every user
    • Active — users who have signed in and are active
    • Invited — users who have been added but have not yet signed in
    • Suspended — deactivated users
  3. Each tab shows a count of users in that state.
  4. Use the Search field (placeholder Search by user name...) to filter by name or email.

The page heading is Users (N). The table is paginated, 10 rows per page by default. The footer shows Showing N users when everything fits on one page, or Showing X-Y of N when it does not, plus Items per page: (10, 20, 30, or 50) and Page X of Y.

The users table displays the following columns:

ColumnDescription
Full NameThe user's display name
EmailThe user's email address
Updated onDate the user was last updated
StatusActive (green check), Invited (yellow clock), or Suspended (red X)
AdminGreen check if the user has admin privileges
Control TagsAssigned control tags (colored chips) — click to edit
ClassificationInfosec level assignment (only shown when infosec is enabled) — click to edit
⋯Opens User Details (View user details)

Add a new user​

  1. Pick your own organization in the dropdown; the Add user button appears only there.
  2. Click Add user (+ icon) in the top-right.
  3. In the dialog, enter:
    • Email (required)
    • First Name (required)
    • Last Name (required)
  4. Click Invite.
  5. The user will appear in the Invited tab until they accept and sign in.

User Details dialog​

  1. Find the user in the table.
  2. Click the ⋯ button on their row (View user details).
  3. The User Details dialog shows the user's name, email, status, admin flag, control tags, and classification (when infosec is enabled).

To edit a user's name, click the pencil icon next to Name, update First name and/or Last name, and click the check icon to save, or the X icon to cancel.

The dialog footer provides:

  • Deactivate — deactivate the user (confirm in the Deactivate User dialog). The user's status changes to Suspended and they can no longer sign in. The button is hidden on your own account and on users who are already Suspended.
  • Manage Tool Access — open the tool access controls (the button is hidden unless you are an administrator).
  • Manage Keys — open access key management.
  • Close — close the dialog.
Availability

Manage Keys appears only when the Identity Service is enabled for your deployment.

Manage Tool Access​

  1. Open User Details for the user.
  2. Click Manage Tool Access.
  3. In the Manage Tool Access for {name} dialog:
    • Filter the list with Search tools....
    • Each tool is shown as an expandable accordion section with a checkbox that grants the whole tool. The checkbox is indeterminate when only some of that tool's functions are granted.
    • Within each tool, individual functions are listed as checkboxes.
    • Check or uncheck functions to grant or revoke access.
  4. Click Save.

Manage Keys​

  1. Open User Details for the user.
  2. Click Manage Keys.
  3. In the Access Keys — {name} dialog:
    • Each key is shown as a row in the table.
    • Click Revoke key on the row and confirm to revoke the key.
    • Click Generate Key to register a new key for the user.
      • In the New Access Key dialog, optionally fill in Name (optional) — leave it blank and Istari Digital assigns a name automatically.
      • Set Expiration. The presets are 30 days, 90 days, 180 days, and 1 year (maximum) (the default). Custom date… requires a date; Generate stays disabled until you pick one.
      • Click Generate.
      • On the Access Key Generated screen, copy or download the key immediately — it will only be shown once. The screen shows Expires. Click Copy to copy. Click Download credentials to download it.

Assign classification levels and control tags​

Click a user's Classification or Control Tags cell in the table, or use User Details, and follow Assign Classification Level to a User and Assign Control Tags to a User. Where those steps open the person's details, use the User Details dialog.