Users and roles
Route: /administration · Role: admin
Administration is admin-only. The top section manages people and their roles.
The users table
Each row shows the person's name, email, status, and role, with two actions: change role and enable/disable.
Change someone's role
- Open Administration.
- Find the person and pick a new role from the dropdown:
engineer,reviewer,finance, oradmin. - Click Save.
The change is audited (user.role_changed with before/after). Roles are enforced
server-side immediately.
Default people to engineer and add privileges deliberately. Reviewers approve time; finance also runs commercials; admin also administers.
Enable or disable an account
Click Disable on a row to suspend access; the button flips to Enable to restore it. Disabled accounts stay in the data for history. The change is audited.
How roles arrive
Roles can be set two ways:
- From your identity provider — the group claim is mapped to a role at sign-in (configurable per deployment).
- Directly here — for people without a mapped group, or to override.
Identities with no matching group fall back to engineer. The Linked identities panel shows which external accounts map to which user.
Linked identities
The panel lists each user's external provider and id. It is read-only here and helps you confirm that an SSO account is linked to the right person.
Rules
- Only admin can change roles or status.
- You cannot lose access mid-session because of a UI hide — the server re-checks the role on each request.