Skip to main content

User Management

The Console surfaces the most common identity management operations directly — no Keycloak admin console required for day-to-day tasks. Platform Admins and Org Admins can create accounts, configure MFA, and provision bot tokens all from one place.

Video: Create and Manage Users

Create a new user account with username, email, and an initial forced-reset password. Update organization membership, toggle active/inactive status, and soft-delete with a 30-day recovery window. All actions are written to the immutable audit trail in Ground Control.

Video: Add User as an Organization Admin

Promote an existing user to Org Admin role within a specific organization. This grants them permission to manage projects and add users within that org, without giving them platform-wide PlatformAdmin access.

Video: MFA Configuration

Walk a new user through enrolling TOTP-based MFA. The Console guides the user through the QR code scan and backup code generation without requiring them to access Keycloak's account portal.

Video: Bot Token Support

Provision service account bot tokens for CI pipelines, automation scripts, and machine-to-machine integrations. Tokens are scoped to a specific organization and expire on a configurable schedule.