Manage users and groups
User and group management controls access and permissions in Itential Cloud. Use these tools to configure security settings and manage identity for your organization.
Users
To view and manage users, select Administration → Users from the sidebar.

The users table shows all user accounts in your Itential Cloud account. Each user belongs to an identity provider, which handles authentication. All Itential Cloud accounts include a built-in identity provider called Local. If you have SSO configured, additional identity providers appear in the list.
The users table includes the following columns:
- Source: The identity provider that manages the user. Local indicates the built-in identity provider.
- Verified: Applies only to Local identity provider users.
- Unverified: The user received an invitation but hasn’t signed in yet.
- Verified: The user has signed in at least once and verified their identity.
Add a new user
You can only add new users to a Local source. If you are using SSO, manage users through your identity provider.
Edit user account settings
Reset a user’s password
An email containing a password reset link is sent to the address associated with the account.
Password reset for accounts managed by an SSO identity provider must be done through the identity provider.
Remove a user
The impact of removing a user depends on their identity provider:
- Local provider: The user is permanently deleted from your Cloud Hub account and cannot log in.
- SSO provider: The user is removed from your account but still exists in your SSO provider. If you do not configure rules to block them, they can access their account again the next time they log in via SSO.
Groups
Permissions are granted to user accounts and service accounts via membership in groups. A group contains a collection of roles, where each role corresponds to a permission. A user or service account that belongs to a group inherits all permissions granted by the roles assigned to that group.
To view and manage groups, select Administration → Groups from the sidebar.

Default groups
Every Itential Cloud account includes two built-in groups:
You can modify or delete these built-in groups to suit your organization’s security needs.
Create a new group
Newly created groups have no users, service accounts, or roles assigned.
Assign users to a group
Associating service accounts with groups is done through service account configuration.
Assign roles to a group
Delete a group
Deleting a group is permanent and cannot be undone.