How Personal Accounts Work
This page explains how Personal Accounts work in Qualytics, from provisioning and authentication to team-based access control.
How Users Are Provisioned
Personal Accounts are created in three ways: an administrator invites the person by email, the person signs in through an identity provider for the first time, or Directory Sync provisions the account ahead of time.
| Method | How It Works |
|---|---|
| Email Invitation | A user with the Admin role invites the person by email. The account is created with the invited role when the person sets a password and activates it. Available when an Email & Password sign-in provider is enabled. |
| Identity Provider (First Sign-In) | The person authenticates through one of your sign-in providers (OIDC or SAML) and Qualytics creates the account at the first sign-in. |
| Directory Sync (SCIM) | Users are pre-provisioned from your identity provider before they log in, allowing team and role pre-assignment. |
Users created at their first identity provider sign-in receive the Member role and join the Public team. Invited users receive the role selected in the invitation. Directory Sync can assign a mapped role; otherwise, provisioned users also receive the Member role. A user with the Admin role can update role and Team assignments after the account is created.
Info
For managed and self-hosted SSO options, see the SSO documentation. For automated provisioning, see Directory Sync.
Self-hosted deployments authenticating through an OIDC or SAML identity provider can also add accounts to Teams based on the groups that provider presents. The groups presented at a person's most recent sign-in are recorded on their account and shown in the Edit User dialog. See Just-in-Time Provisioning and Group Sync.
User Roles
Every user is assigned a role that controls their platform-level permissions: Admin, Manager, or Member.
Info
For detailed capability tables per role, see the User Roles page.
| Role | Access Level |
|---|---|
| Admin | Full platform access to manage users, teams, datastores, connections, and all settings. Not subject to team permissions. |
| Manager | Limited admin access to create datastores and connections and manage tags and notifications. Subject to team permissions for datastore content. |
| Member | Standard access inherited from team membership. Can generate personal tokens and view library/tags. |
Team-Based Access
Access controls in Qualytics are assigned at the datastore level through Teams. A user without the Admin role can have one of the following levels of access to any datastore:
- Editor: Full datastore management, including enrichment, scoring, computed fields, operations, and field status.
- Author: Manage checks, including activation, validation, status, and metadata.
- Drafter: Create and save checks as drafts without activating them.
- Viewer: Read-only access to anomalies with the ability to comment on the Timeline of containers, quality checks, and anomalies.
- Reporter: Read-only access to all report information including dashboards, overviews, and anomalies.
Note
Permissions are assigned to Teams rather than directly to users. Users inherit the permissions of the teams to which they are assigned.
All users are part of the default Public team, which provides access to all Public Datastores. Admins can create and manage additional teams, assigning both users and datastores to them.
Info
For detailed permission matrices per team permission, see How Teams Work.
The Users List
The Users list on the Access page (Settings > Access > Users) shows one row per account, active accounts only by default. Users with the Manager or Admin role can open it; only the Admin role can act on other users from it. The columns run from left to right:
| Column | What it shows |
|---|---|
| Name and email | The user's avatar, name, and email. A small badge on the avatar shows whether the account is Active or Deactivated; hover over it to read the status. When an account has only an email on file, the email stands in for the name. An information icon next to the name opens the Details panel described below. |
| Type | Human for a person who signs in to the platform, or Service for a non-interactive account used by automation. Service users carry a key icon, human users a person icon. See Service Users. |
| Role | The platform-level role: Admin, Manager, or Member. See User Roles. |
| Teams | The teams the user belongs to, as a row of badges. Clicking a badge switches to the Teams tab with the list searched for that team. When more teams exist than fit in the row, the extra ones collapse into a count badge; hover over it to see their names. |
| Last Active | When the user last interacted with the platform, as relative time. Hover over it for the exact date and time in your local timezone. |
Deactivated accounts, when shown, appear in gray across the whole row.
Details Panel
Hovering over the information icon next to a user's name (or focusing it with the keyboard) opens a Details panel with the identifiers and dates that do not fit in the row:
| Field | Description |
|---|---|
| User ID | The numeric identifier of the account, prefixed with #. Use it when calling the Users API or when reporting an issue about a specific account. |
| Name | The user's display name. Shown only when the account has one. |
| The user's email address. Shown only when the account has one. | |
| Created At | When the account was created, as an exact date and time in your local timezone. |
| Deactivated At | When the account was deactivated. Shown in red, and only for deactivated accounts. |
Right-clicking anywhere on a user's row opens a context menu with Copy ID, plus Copy Name and Copy Email when the account has those values.
Last Active Labels
| Label | Meaning |
|---|---|
| Never | The user has never logged in or made an API request. |
| Just now | The user was active within the last 5 minutes. |
| Relative time | Anything older, for example 19 hours ago or 3 days ago. |
All timestamps are stored in UTC and converted to your browser's timezone for display. Accounts showing Never for a long time were provisioned but never used; consider deactivating them. The creation date is not a column of its own: read it in the Details panel, or sort the list by Created Date as described in Sort and Filter Users.