Skip to main content
Settings › Workspace › Members lists the people who already have an account in your tenant, with their roles and account status. Open any member to reach their detail page, where you grant and revoke roles, edit group memberships, and run the per-user admin actions. If a user hasn’t signed in yet, use Preassignments instead.

The Members list

Each row shows a member’s email, roles, and status. Active members can be Deactivated directly from the list — a deactivated user keeps their record but can no longer sign in. Select a member to open their detail page.

The Member detail page

The detail page has four parts.

Profile

Read-only account fields: Email, Name, Tenant, Status (Active or Disabled), and Last login.

Role assignments

A user’s administrative reach is a list of role grants, not a single dropdown value. Each grant is tagged with its tenant, or platform for a platform-wide grant.
  • Grant role. Open the grant dialog to add a role assignment, scoped to a tenant (or platform-wide).
  • Revoke. Remove an individual grant from the list.
A user with no grants is a plain member. Granting tenant_admin or super_admin gives administrative reach; only a super_admin can grant super_admin.

Groups

Two separate sections, never merged:
  • Groups — the member’s native Aperium permission groups. Managed here via Edit groups, which adds or removes the member one group at a time. These are the groups that carry MCP policies.
  • IdP groups — a read-only snapshot of the groups your identity provider (Okta, Entra, Google Workspace) most recently reported on the member’s sign-in token, with a “last reported” time. You cannot edit these in Aperium; manage them in the identity provider. They grant roles through Group mappings, not permission-group membership.

Actions

  • Impersonate this user. Start an impersonation session as this member (non-admin, active targets only). Gated by the impersonation.start capability. See Impersonation.
  • Reset onboarding. Clears the member’s onboarding-completion flag so they see the welcome flow again on next sign-in. Useful after a major release, or when someone got stuck.

Common workflows

Promote someone to tenant admin

  1. Open the member’s detail page.
  2. In Role assignments, Grant roletenant_admin, scoped to the tenant.
  3. The reach applies on their next request.

Move a member between teams

  1. Open the member and Edit groups.
  2. Uncheck the old team’s permission group; check the new one. Each change is an individual grant/revoke, so a partial failure reports exactly which change didn’t apply.
If your identity provider drives role assignment, prefer updating the user’s IdP groups and letting Group mappings apply the role at next sign-in.

Deactivate a departing user

Use Deactivate on the member’s row. Their record is retained; they can no longer sign in, and they are no longer a valid impersonation target.