The Members list
Each row shows a member’s email, roles, and status. Active members can be Deactivated directly from the list — a deactivated user keeps their record but can no longer sign in. Select a member to open their detail page.The Member detail page
The detail page has four parts.Profile
Read-only account fields: Email, Name, Tenant, Status (Active or Disabled), and Last login.Role assignments
A user’s administrative reach is a list of role grants, not a single dropdown value. Each grant is tagged with its tenant, or platform for a platform-wide grant.- Grant role. Open the grant dialog to add a role assignment, scoped to a tenant (or platform-wide).
- Revoke. Remove an individual grant from the list.
member. Granting tenant_admin or super_admin gives administrative reach; only a super_admin can grant super_admin.
Groups
Two separate sections, never merged:- Groups — the member’s native Aperium permission groups. Managed here via Edit groups, which adds or removes the member one group at a time. These are the groups that carry MCP policies.
- IdP groups — a read-only snapshot of the groups your identity provider (Okta, Entra, Google Workspace) most recently reported on the member’s sign-in token, with a “last reported” time. You cannot edit these in Aperium; manage them in the identity provider. They grant roles through Group mappings, not permission-group membership.
Actions
- Impersonate this user. Start an impersonation session as this member (non-admin, active targets only). Gated by the
impersonation.startcapability. See Impersonation. - Reset onboarding. Clears the member’s onboarding-completion flag so they see the welcome flow again on next sign-in. Useful after a major release, or when someone got stuck.
Common workflows
Promote someone to tenant admin
- Open the member’s detail page.
- In Role assignments, Grant role →
tenant_admin, scoped to the tenant. - The reach applies on their next request.
Move a member between teams
- Open the member and Edit groups.
- Uncheck the old team’s permission group; check the new one. Each change is an individual grant/revoke, so a partial failure reports exactly which change didn’t apply.