User Management
The Console surfaces the most common identity management operations directly — no Keycloak admin console required for day-to-day tasks. Platform Admins and Org Admins can create accounts, configure MFA, and provision bot tokens all from one place.
Video: Create and Manage Users
Create a new user account with username, email, and an initial forced-reset password. Update organization membership, toggle active/inactive status, and soft-delete with a 30-day recovery window. All actions are written to the immutable audit trail in Ground Control.
Video: Add User as an Organization Admin
Promote an existing user to Org Admin role within a specific organization. This grants them permission to manage projects and add users within that org, without giving them platform-wide PlatformAdmin access.
Video: MFA Configuration
Walk a new user through enrolling TOTP-based MFA. The Console guides the user through the QR code scan and backup code generation without requiring them to access Keycloak's account portal.
Video: Bot Token Support
Provision service account bot tokens for CI pipelines, automation scripts, and machine-to-machine integrations. Tokens are scoped to a specific organization and expire on a configurable schedule.