Users and roles

Prev Next

Settings › User permissions is where you see who has access to Quantivly and what each of them can do. It has four tabs: Users, Roles, Permissions, and Activity.

This area is marked beta in the app.

This article covers Users and Roles. See Role capabilities reference for the Permissions matrix, and Activity history for the record of who changed what.

Before you start: what this area does and does not do

Quantivly does not create or delete user accounts. Signing in is handled by your organization's sign-in system, and that is where accounts are added and removed.

What this area controls is which roles an existing account holds, and what each role can do. A person appears in the Users list once they have signed in for the first time — until then there is no record here to show. Accounts your Quantivly team uses to support your deployment may also appear in the list.

Accounts are never deleted from Quantivly. To take away someone's access, disable their account in your organization's sign-in system: they can no longer sign in, and after the next hourly sync the Users list shows them as Keycloak disabled. An account shows as Inactive when it has been deactivated in Quantivly itself, which your Quantivly team can do for you.

Users tab

Every account that has signed in to this deployment, with:

Column

Notes

User

The name the account was registered with. Not editable here. Sortable

Email

Role

The roles assigned to the account; empty if it has none

Status

Active; Inactive — the account has been deactivated in Quantivly; or Keycloak disabled — the account has been disabled in your organization's sign-in system

Last active

Sortable

Use the filter bar (All roles, All statuses) to narrow the list, or the search box to find one person.

Assigning roles

Click the person's row, or open its ... menu and choose Edit user. Tick the roles the person should hold and save. The set you save replaces whatever they had, so clearing every tick removes all of their roles.

People can't be removed from this screen. The ... menu shows a greyed-out Remove user item whose tooltip says user removal is managed in Keycloak — that is, in your organization's sign-in system.

Assigning roles requires the Assign user roles capability.

Editing your own roles

You can change your own roles, including giving yourself fewer. What you cannot do on this tab is give yourself more: a role that would grant you a capability you do not already hold is refused.

Removing your own roles asks you to confirm first, under Remove your own roles. It takes effect as soon as it saves and can change what you are able to see and do — including whether you can still open this screen.

Refusals you may hit

These appear inline under the roles selector.

"At least one user must keep 'Manage roles & permissions'." You are about to remove the last person who can reach the Permissions matrix. If the save went through, nobody could reopen the screen needed to grant it back. Assign a role that grants it to somebody else first.

"At least one user must keep 'Assign user roles' while no one holds 'Manage roles & permissions'." Nobody currently holds Manage roles & permissions, and you are about to remove the last person who can assign roles. Assign a role that grants either capability to somebody else first.

A role that would give you more than you hold. You cannot add to your own account a role granting a capability you do not already have, and you cannot give somebody else Manage roles & permissions unless you hold it yourself. Ordinary roles stay freely assignable to other people.

This guard covers role assignment only. The Permissions matrix has no equivalent check: anyone who holds Manage roles & permissions can tick any capability onto a role they already belong to. Treat that capability as full control over access, and grant it only to people you would trust with every capability.

Roles tab

A role is a named bundle of capabilities. The tab lists each role with its description and how many members hold it.

Action

Notes

Add role

Name and optional description. Names must be unique and non-empty. A new role starts with no capabilities; set them on the Permissions tab once the role exists. The Permissions tab has its own Add role button too

Edit

Change the name, the description, or both

Duplicate

Creates a new role with the same capabilities and description. The name is prefilled as "<name> copy" and you can change it; the copy starts with no members

Delete

Greyed out while anyone holds the role. Remove it from its members on the Users tab first

All four require the Manage roles & permissions capability.

Duplicate is the quickest way to build a role that is a small variation on one you already have: copy it, then adjust the copy's cells in the Permissions tab.

The Administrator role is locked

Every deployment ships with an Administrator role holding the full set of capabilities. It cannot be renamed or deleted, and capabilities cannot be taken away from it — its controls are shown locked. That is what guarantees your deployment always keeps one role able to reach everything, including this screen.

You can add and remove its members in the usual way.

Who can see this area

Tab

Requires

Users, Activity

Assign user roles

Roles, Permissions

Manage roles & permissions

Tabs you cannot open are not shown at all, rather than shown and refused.

If you hold neither capability, User permissions still appears in the settings navigation, greyed out, with a tooltip naming the capabilities you need (Assign user roles or Manage roles & permissions). You can see that the feature exists, but not open it. The Administrator role is assigned by hand when a deployment is set up, so most people will see it this way until somebody grants them a role.

Accounts managed by Quantivly

Your Quantivly team holds a small number of accounts that sit outside the role model and can act regardless of what the Permissions matrix says. Every deployment has at least one, so that support can still reach a site that has locked itself out. They are set up by Quantivly and cannot be created, changed, or removed from this screen — so the Permissions matrix is not quite the complete answer to "who can do what".

The same holds in reverse: a few settings are reserved to Quantivly and cannot be granted to any role. See Role capabilities reference.