Skip to the page
Get started

Docs · Administration

People

Adding colleagues, changing roles, resetting passwords, and the difference between removing and disabling.

Who can reach this workspace, and with what authority.

Reached from the account menu under Tenancy → People. Admins and owners only.

#There is no self-service sign-up

On a self-hosted installation, an account exists only because somebody made one.

Adding an address that already has an account puts that person in this workspace without touching their password.

So adding a colleague who already uses Mosaic elsewhere in your organisation does exactly what you would hope, and costs nothing against the seat limit — only new accounts are counted.

#Adding somebody

Field
Email
NameOptional
Initial passwordUsed only if this creates a new account. At least 12 characters
RoleOnly roles at or below your own

The initial password comes pre-filled with a suggestion — twenty characters, with l, I, O, 0 and 1 left out so it can be read aloud over a phone.

It is shown once:

Give this to them now. It is stored only as a hash, so it cannot be shown again — if it is lost, set a new one.

There is nowhere to look it up afterwards.

#Changing a role

An inline menu on the row, with three rules that will not bend:

  • Never your own. "Ask another admin to change your own role." — in either direction, so you cannot promote yourself and cannot accidentally demote yourself out of the ability to fix it.
  • Never past yourself. An admin cannot demote an owner.
  • A workspace always keeps at least one owner.

#Resetting a password

The key icon.

Set a new password for them? They will be signed out everywhere, and you will have to give them the new one.

Every one of their sessions is revoked, including the browser they may still have open, and you are told how many. The new password is shown once, like an initial one.

Two limits: you cannot reset your own here — use Settings, where the current password is required — and you cannot reset the password of somebody above you.

#Remove versus disable

These are different and the distinction matters.

Remove takes somebody out of this workspace. Their account survives, and so does every other workspace they belong to. Somebody removed from their last workspace is signed out, but the account remains so the audit trail keeps pointing at a real person.

Disable is an owner's, and it is installation-wide:

They are signed out immediately and cannot sign in to Mosaic at all — including any other workspace they belong to. To remove them from this workspace only, use Remove instead.

Disabling drops their sessions, because an account left signed in is an account that is not disabled. It disables rather than deletes, so re-enabling is one click.

For somebody leaving the company, disable. For somebody moving to another team, remove.

#What each role can do

See Workspaces and roles for the full picture. In short: a viewer reads and runs; an editor changes definitions; an admin publishes, holds credentials and manages people; an owner holds the workspace, the licence and accounts.