Platform → People lists every account in the Shokoofa identity service. Search by part of a name or an email address; results come in pages of 20.
Creating an account
Choose Create account and enter the email and, optionally, the name. The person verifies their email and chooses their own password: nobody else sees or sets it. If you leave Email them now on, they receive the link at once (valid 72 hours); otherwise send it later from their page. An address already used by another account is refused.
What an account page shows
- the profile: name, email (verified or not), language, time zone and photo;
- the tenants the person belongs to and their roles there (memberships are managed by each tenant's administrators);
- their platform roles and personal app entitlements;
- the kinds of sign-in method they have (password, authenticator app, security key, passkey), never the secrets;
- the steps the identity service is waiting for them to complete;
- their active sessions.
Changing a profile
Change the name, email, language, time zone or bio and save. Only the fields you changed are sent.
Changing the email marks it unverified. The person must verify the new address before it is trusted: send them a sign-in email with Verify their email. If the person signs in through their organisation's own sign-in system, their name and email are managed there and cannot be changed here.
Sign-in emails
Send sign-in email asks the person, by email, to verify their email, set a new password, set up an authenticator app, register a security key or passkey, or complete their profile. The link works for 1 to 168 hours. This is how you help someone who forgot their password: you never set a password yourself.
Disabling and enabling
Disabling an account signs the person out everywhere at once and stops them signing in to any Shokoofa app until the account is enabled again. Nothing is deleted. Both need a reason, which is kept in the audit log.
Sessions
You can end one of the person's sessions or all of them; they are signed out in those browsers and must sign in again.
Personal apps
Avand storage and Peyk mail belong to the person rather than a tenant. The person's page shows their roles in each app, grouped under Avand and Peyk (mail):
- Entitlements (using the app): with the entitlements permission you switch them on and off.
- Administration roles (administering the whole app, never reading anyone's files or mail): only platform owners give and take them, every platform owner is told when someone is given one, and nobody changes their own.
Roles marked Default for everyone (an Avand store and a Peyk mailbox) are given to every account when it is created and by a daily check. If you switch one off for someone, it stays off for them: the page says Removed by an administrator and the daily check leaves it alone until someone switches it on again. The person's data stays theirs while their access is off.
Platform owners administer Avand through their platform role: the Avand administration row then says Included through platform owner.
Profile photos
You can remove a person's photo, for example an inappropriate image, with a reason. They can upload a new one.
Your own account
Your own account opens read-only here, with a link to My account: the platform refuses any change to your own account made through these pages.