Everyone in a tenant is listed on the tenant's Members page with the roles they hold. Open a person to change their roles, see their units and subgroups, renew a guest, or remove them from the tenant.
Finding people
Search by part of a name or an email address, and filter by account type: members, guests or integrations (service accounts of installed extensions). A long list is split into pages.
Roles
A role is a set of permissions in this tenant. Tenant roles such as Owner, Administrator or User administrator manage the tenant; app roles such as Boostan user give access to an app and use one of its seats. Choose the small info button next to a role to see what it allows in each app.
To give a role, open the person and choose Give a role. Roles you are not allowed to give are shown but greyed out, with the permission they need. Roles marked with a shield need or recommend two-step sign-in: your organisation may require a second factor for them, and you may then be asked to confirm it's you before the change is made. Where it is optional, the role dialog says so and shows Second factor recommended.
Nobody can change their own roles; ask another administrator.
Roles that can't be combined
Some roles are kept apart on purpose (separation of duties). A guest, for example, can't be an administrator, and a service account never holds an administrative role. When a choice would break such a rule, the page says which roles clash and why, before and after asking. Remove the conflicting role first if the change is really needed, or give the role to someone else.
The last owner
A tenant always keeps at least one owner. The page refuses to remove the owner role from its only holder and explains what to do: give the owner role to someone else first. In the same way, an app the tenant uses is never left without an administrator.
Removing someone from the tenant
Remove from tenant on a person's page ends their membership of this tenant only:
- they leave the tenant and every unit, subgroup and role in it, and lose access to the tenant's apps, including tokens and keys tied to the tenant;
- what they owned in the tenant's apps (boards, meetings, chats) goes to the successor you choose, or else to their manager, or is archived; nothing is deleted before the tenant's retention period;
- their Shokoofa account, their other tenants and their own mail and files are not affected.
The successor must be another member, not a guest. A reason is required and is kept in the audit log. The Removed people page lists every removal.