Users, roles & MFA

Roles

admin - everything: Settings, user management, license, tenant add/remove, plus all of the below.

user - browse objects, export Terraform (per-object and bundles), click Refresh, and manage their own Profile. No Settings access, no user management, no license, no tenant changes.

The last active administrator can never be demoted or disabled - there is always someone who can manage the install.

Finding your way around Settings

Every Settings section (Tenants, Users, Security, Email, License, Audit log) is collapsed when the page opens - click a heading to expand it. The chip beside a heading shows what is inside without opening it: how many tenants and users you have, whether email is configured, and your license tier.

Creating users (Business tier)

Settings > Users. Two ways: Create user with a temporary password you hand them (they should change it in Profile), or Email invite - TFsmith emails a set-your-password link valid for 72 hours (requires email setup, below). Pick the role at creation; change it anytime with Make admin / Make user.

Edit on any row opens the account: first and last name, email, role, and the external and break-glass flags. Your own row is editable too - that is how the first break-glass admin gets flagged on a single-admin install. The one thing you cannot do to yourself is change your own role.

Disable suspends an account without deleting it (their sessions stop working immediately); Enable restores it. Reset password sets a new temporary one. Reset MFA appears only on an account that actually has two-factor on, for someone who has lost their authenticator. The Individual tier includes a single user.

Delete appears only on an account that is already disabled, and asks you to type the username to confirm. It destroys the account along with its sessions and any pending invite or password-reset link, so an emailed link cannot outlive the account it was issued for. The audit log keeps the person's name, so history stays readable after they are gone. Disabling first is deliberate: it keeps removal off the end of a row of routine buttons, and it means the last-administrator check has already run before anything is destroyed.

Every user's Profile

Change password, set their own email address, and enroll two-factor authentication (TOTP): scan the QR code with any authenticator app, confirm a code, done. Login then asks for the 6-digit code. Disabling MFA requires a current code.

Security settings

Require MFA for all users: anyone not yet enrolled is taken straight to enrollment at their next sign-in. Session length: 1-365 days (default 30).

Email (SMTP)

Settings > Email. Your own mail server - host, port, credentials, from address. TFsmith never sends anything anywhere else, and the password is encrypted at rest with the master key. Powers three things: user invites, forgot-password reset links (the link on the sign-in screen; 2-hour expiry; works only for accounts with an email on file), and license expiry warnings to administrators. Use the test-send button after saving.

No email configured? Everything still works - admins hand out temporary passwords and reset them manually.

Audit log

Settings > Audit log: who did what, when (shown in your local time) - logins, tenant changes, refreshes, user management, license events, settings changes.

All docs · These docs also ship inside the app under the Docs button.