User Management
The Users page lets workspace administrators invite team members, assign roles, manage vault access tiers, and control user status. Each user occupies a billable seat on your subscription.
URL: /settings/users
Required permission: roles.manage
Accessing User Management
Go to Settings from the sidebar.
Click the Users card (described as "Manage team members, invite users, assign roles").
The Users Table
The main table shows every user in your workspace with the following columns:
| Column | Description |
|---|---|
| User | Name and email address. |
| Role | The user's assigned role (e.g., Admin, Manager, Staff). The workspace owner is marked with an "Owner" label. |
| Vault Tier | The user's vault folder visibility tier. Shows "From role" if no override is set, otherwise shows the override tier (Staff, Management, or Director). |
| MFA | Whether the user has two-factor authentication enabled (On/Off). |
| Status | Whether the user account is Active or Disabled. |
Click any user row to expand the detail panel with inline editing controls.
Inviting Users
To invite a new team member:
Click the Invite user button in the top-right corner.
In the modal that appears:
Enter the user's email address.
Select a role from the dropdown (see Roles & Permissions for details on each role).
Click Send invitation.
The user receives an email with a link to accept the invitation and create their account (or link an existing concorbit account).
Invitation Statuses
| Status | Meaning |
|---|---|
| Pending | The invitation has been sent but not yet accepted. |
| Accepted | The user has accepted and created their account. |
| Expired | The invitation link has expired. Send a new one. |
Managing Invitations
The Invitations section below the user table lists all invitations with their status, who sent them, and when. For pending invitations, you can:
Resend: sends a fresh invitation email (useful if the original was lost or expired).
Revoke: cancels the invitation so the link no longer works.
Editing a User
Click a user row in the table to expand the detail panel. From here you can:
Change a User's Role
In the expanded panel, use the Role dropdown to select a new role.
The change is saved automatically when you select a new value.
The workspace owner's role cannot be changed.
Override Vault Tier
Each role grants a vault folder visibility tier (Staff, Management, or Director). You can override this on a per-user basis:
In the expanded panel, use the Vault Tier Override dropdown.
Select a tier, or choose "From role" to use the tier defined by the user's role.
This is useful when a specific user needs access to higher-tier vault folders without changing their overall role. See Roles & Permissions for details on how vault tiers work.
Disable a User
Disabling a user prevents them from logging in without removing them from the workspace:
Expand the user's row.
Click Disable.
The user's status changes to "Disabled" and they are immediately signed out of all sessions. Their data and history are preserved. Re-enable them at any time by clicking Enable.
Remove a User
To permanently remove a user from the workspace:
Expand the user's row.
Click Remove.
Confirm in the dialog.
Removing a user frees up their seat on your subscription. Their historical data (audit entries, email logs, etc.) is retained but attributed to their name.
User Seats and Billing Impact
Every active user in your workspace occupies one billable seat. Your monthly bill is calculated as:
(number of seats) x (per-seat price for the seat's tier)
Individual seats can be on different subscription tiers (e.g., some users on concorbit, others on concorbit Pro). See Subscription & Billing for details on per-seat tier licensing.
When you invite a new user or re-enable a disabled user, a new seat is added to your subscription. When you remove or disable a user, the seat is freed.
Workspace Owner
Every workspace has exactly one owner. The owner:
Has full access to all settings and features.
Cannot be disabled, removed, or have their role changed by other users.
Is marked with an "Owner" badge in the users table.
Ownership transfer is handled by contacting concorbit support.
MFA Status
The MFA column shows whether each user has enabled two-factor authentication. Administrators cannot enable MFA on behalf of a user, but they can:
Require MFA for a role: in the Roles & Permissions page, enable the "Require MFA for this role" setting. Users with that role must set up MFA within the grace period.
View MFA status: quickly audit which team members have MFA enabled.
User Profile Settings
Each user can edit their own profile at Settings > Profile. Profile settings include:
Personal Information
Name: displayed throughout concorbit and in audit logs.
Email: the login email. Changing it requires entering the current password for security.
Phone: optional contact number.
Avatar: upload a profile picture from the media library, or use the default initials avatar.
Localisation Preferences
Timezone: overrides the workspace timezone for this user's display.
Locale: language preference.
Date format: personal date display preference (e.g., DD/MM/YYYY or MM/DD/YYYY).
Password
Users can change their own password from the profile page. A password strength meter provides real-time feedback.
Two-Factor Authentication
A link to the MFA setup page where users can enable authenticator apps and passkeys.
Booking Availability
If the Calendar/Booking module is active, users can set their availability schedule from their profile.
Active Sessions
Users can view and revoke their own active browser sessions.
Account Deletion
Users can request deletion of their own account from the "Danger zone" section. Workspace owners cannot delete their account (ownership must be transferred first).
Session Management
Each user can view their active sessions at Settings > Active Sessions. This shows:
Browser and operating system.
IP address.
When the session was created.
Whether it is the current session.
Users can revoke any session except their current one, which immediately signs out that device.
Related Documentation
Roles & Permissions, how to create roles and assign granular permissions.
Security & Authentication. MFA setup, password requirements, session management.
Subscription & Billing, how user seats affect your monthly bill.