User Management
This page covers the full user lifecycle — invitations, role assignment, deactivation, MFA, and SSO.
Inviting users
Admin → Users → Invite:
- Enter email and name (AR + EN).
- Pick job title and reporting manager (optional).
- Assign initial roles — per company, per project.
- Send invitation.
Invite emails are valid for 72 hours. Resend from Admin → Users → [user] → Resend invite.
Bulk invite
For large rollouts:
- Admin → Users → Bulk import.
- Download the Excel template.
- Fill in name, email, role per company, project scope.
- Re-upload.
- ORKSTRA validates and creates invites for each row.
Role assignment
Roles are assigned per (user, company) pair. A user can have multiple roles per company; permissions are the union.
To assign:
- Admin → Users → [user] → Add role.
- Pick company and role.
- Optionally restrict to specific projects.
- Save.
Deactivation vs. deletion
Deactivation — user loses access but the audit log is preserved. Reversible.
Deletion — soft-deletes the user record; audit log preserved. After 90 days, the user record is hard-deleted (except where legal hold applies). Not reversible.
Leaver workflow:
- Reassign their open approvals (Admin → Users → [user] → Reassign approvals).
- Reassign their owned projects/records.
- Deactivate the account.
- Revoke any API tokens they created.