Users and roles
From Settings → User Management: list people, switch Users/Roles tabs, and change someone’s organizational role on the edit page.
Outcome
You open User Management with the right permission, use ?tab=users or ?tab=roles, edit via /settings/users/edit?id= (relation id), and soft-link invites to Company team.
Who it's for
Team member with User Management permission (Roles tab needs view-roles)
Prerequisites
- Permission SETTINGS manage users (hub card: User Management)
- At least one company user to view in staging
- View-roles permission if you want the Roles tab
Steps
- From the Settings hub, open User Management (`/settings/users`). Use Back to Settings to return to the hub. This page is for access control: who can sign in and what organizational role they hold: not for inviting a brand-new teammate from scratch (soft-link Company team / `md-team` for invites and team size).
- Two tabs sync with the URL: Users (`?tab=users`, default) and Roles (`?tab=roles`). Roles appears only if you may view roles; without that permission you stay on Users. Bookmark or share the tab query when you hand off work.
- On Users: scan the list (card or table view as the product offers). Use search when present. Edit opens `/settings/users/edit?id=…` where `id` is the user–company relation id: not a bare user id. Prefer the Edit control from the list so the id is correct. Deactivate removes access without deleting the person; you can reactivate later when the product offers it.
- On Edit User: pick the new organizational role from the dropdown (labels often show archetype, e.g. Resource). Save ends the current relation (valid_to = today) and starts a new one (valid_from = today) so history stays intact. You return to `/settings/users?tab=users`. If you change someone to Resource or Client without a linked record, a safety dialog may offer Create & Link Resource Now, Cancel, or Change Anyway: prefer create-and-link so they do not land on an empty portal.
- On Roles (when visible): create or edit roles and the permissions each role grants. Keep roles intentional: planners, admins, and field people see very different apps, and finance permissions can stay off for people who only need to plan. Deep permission matrices are per-role; this tutorial is the map, not every checkbox.
- Next in this cluster: appearance and localization. Soft-continue from Company team (`md-team`) already points here for settings depth after invites.
