Skip to main content

User management

User management is about getting the right people into the tenant and keeping their access aligned with their role. VaultPAM distinguishes between platform users and organisation users so you can control administration without blurring tenancy boundaries.

Common tasks

Invite a user

Send an invite by email. The recipient follows the invite flow, creates or confirms their identity, and joins the organisation with the role you selected.

Assign roles

Use Member for daily access and Admin for people who configure the tenant. Only grant admin rights when the person needs to manage connectors, policies, or security settings.

Enforce MFA

You can require MFA for organisation members so that password compromise does not translate into privileged access. The enforcement is set by policy, but the actual enrolment happens in the user flow.

Suspend or restore organization access

Suspend access when you need to stop a member from using this organization without removing their account record. This does not change the member's access in other organizations.

When the incident is resolved, select Restore organization access for the same member. Restoring a previously removed membership does not automatically restore suspended access; use the explicit restore action so the change is recorded.

If a member still has active access to another organization, they continue in that organization without a suspension message. If they have no active organization left, VaultPAM shows an access-status page. The page names the organization only when it is the member's sole suspended membership; it never asks the member to choose a suspended organization or exposes another organization name. A platform-wide account lock remains a separate, global condition.

Request a password reset

Use Force password reset in the member detail when you believe the account password may be compromised. The reset applies to the member's shared account password, not only to this organization.

  1. Open Organization → Members and select the member.
  2. Select Force password reset, enter the required reason, and confirm the action.
  3. The member is asked to change their password at their next sign-in. For accounts managed through Keycloak, they receive the provider's password-update email, complete the change in their identity provider, and then finish the return to VaultPAM.

If the dialog says that a Platform Admin is required, contact a Platform Admin. The dialog intentionally does not disclose details about the member's access elsewhere.