Heimdallone Docs
Administration

Users & roles

How admins manage who can sign in and what they can do — members, roles, and the difference between job roles and access roles.

AdminTenant OwnerSecurity

This page is for owners and admins managing who can sign in and what they can do.

Members

The people who can sign in to an organization are its members. Manage them from App → Users & Access (in the Workspace section of the sidebar — visible to Tenant Owner, Tenant Admin and HR Admin). There you can:

  • See every member, their access role and when they joined.
  • Change a member's role inline.
  • Remove a member (they lose access immediately; their employee record is kept).
  • Invite a new member by email and pick their starting role.
  • See and manage pending invitations.

Only owners/admins change access

Inviting, changing a role, and removing a member are limited to Tenant Owner, Tenant Admin and HR Admin. The server enforces this regardless of the UI — other roles don't see the page.

Invitations

Email delivery is not yet configured, so an invitation does not send an email automatically. Instead:

Open Users & Access → Invite member, enter the email and pick a role.
In the Pending invitations list, use Copy link and share that link with the person directly.
They open the link, sign in with the invited email, and accept. They then appear as a member.

Cancelling

Pending invitations can be cancelled from the same list before they're accepted.

Two kinds of "role"

These are easy to confuse:

  • Access role (what someone can do) — e.g. HR Admin, Payroll Admin, Manager, Employee, Auditor. Managed in Workspace settings. See the full list and permissions on Roles & access.
  • Job role (a title, e.g. "Technician") — managed in App → Settings → Roles. This is descriptive HR data and does not grant any access.

Give someone access

For a brand-new person, add them in App → Employees with a real email, then invite them from Users & Access — see Migrated logins & access.
To change what an existing member can do, open App → Users & Access and set their access role.
Confirm the change by checking which sidebar areas they can now see (access is least-privilege — people only see what their role allows).

What to check

  • Owners are owners, admins are admins — access roles weren't accidentally reduced during migration (use App → Migration status to confirm).
  • Auditors have read-only access; no one has more than they need.

Troubleshooting

SymptomFix
"I can't see a module"Their access role doesn't include it — adjust in Users & Access
"I can't change a role"Only Tenant Owner / Admin / HR Admin can
"New hire has no login"Add a real email and invite — never use a placeholder
"Invite email never arrived"Email isn't wired yet — use Copy link and share it directly
"Can't find Users & Access"It's under Workspace in the sidebar, owner/admin/HR only

On this page