User Management
From Admin → Users (Users — write permission), an administrator can:
- Create, edit and deactivate accounts — deleting a user deactivates it (
active = no), it never physically removes its data. - Set the username, email, password (reset) and assigned group. The group is the only carrier of rights: there is no longer any role or profile to assign directly to an account.
- Reset the two-factor authentication of an account that lost both its phone and its backup codes.
- A welcome email is sent automatically on creation if an email address is provided and email sending is configured (see Email Configuration).
What this screen doesn't handle
- A user's team is managed from the team management page (Teams — write permission), not from Admin → Users.
- The rights themselves are not set account by account: they come from the group, composed under Groups and Profiles.
- A user's daily token quota exists and is enforced at analysis time, but no interface currently lets you set it — only a direct database change can.
Self-service
Each user manages, from their own Profile page (account menu):
- Their password (except for an account connected via Azure AD SSO, where the password is managed in the organization's Azure AD portal).
- Their interface language (FR/EN).
- Their notification preference for job-completion emails.
- Their two-factor authentication (enabling, backup codes, disabling).
- The light/dark theme of the interface — this is a browser preference, it is not stored on the account and therefore does not follow the user from one device to another.