Creating a user
Set up an account when your role allows user management.
This task is for people allowed to manage accounts.
- Open the site's user overview, usually available from the admin navigation.
- Search for the person first. If they already have a person page, check its Username / password panel before creating a duplicate.
- Use Add user for a new person. Enter their name, email address, and the login details requested by the form.
- Complete the creation flow and check the resulting person page.
- Arrange the appropriate user-group membership with the website manager.
- Ask the new user to sign in and confirm that they can do their work.
Creating login details alone does not necessarily grant editorial permissions. Follow the site's account invitation and password procedures; do not put credentials in public page text or editorial notes.
This is a site-administration task. Before granting access, agree which content the person will maintain and whether they may publish, delete, or manage users. Verify with the new account that both the intended work and the expected restrictions apply. A successful administrator test does not check the new user's permissions.
Assign user groups and check access
Access needed: Site administrator with user-management and access-rule permissions.
Start with an existing account and a clear description of its work: which content it maintains, whether it publishes, and whether it manages other people.
- Find the person's page in the user overview and open it.
- In User groups, select the existing group that matches the agreed role. Check inherited memberships and save.
- Use a separate browser profile to sign in as a representative test account with those memberships.
- Check one allowed operation, such as editing a draft in the intended content group.
- Check one restriction, such as editing another team's content or opening user management.
- Record the membership change and the person responsible for approving it.
Do not give an account administrator access merely to fix one missing permission. If no existing role fits, have an access-rule administrator adjust the rules and test them before publication. More than one group can affect the effective permissions.
A person page, login identity, user group, and content group have different purposes. A collection used for navigation is not an access-control boundary.
Remove access when someone leaves
Access needed: Site administrator; identity-provider or integration access may also be needed.
First identify the person, the accounts they use, and which content or responsibilities need transferring.
- Review their user groups, collaboration memberships, API credentials, and any external sign-in method.
- Remove the memberships that grant access and save.
- For a local username/password account, open Set username / password and choose Delete Username. Read the confirmation carefully.
- Disable the account at an external identity provider and revoke separate integration tokens where applicable.
- Arrange invalidation of existing sessions with the site's authentication administrator; removing a password alone is not proof that every existing session is gone.
- Test that the former access methods fail and that the replacement owner can still do the work.
Keep the person resource when it is needed for authorship or records. Unpublishing a person page is not an account-deactivation procedure. Do not delete their content merely to remove a login.
The built-in admin account is configured separately; this username-deletion dialog does not manage it. Handle emergency administrator credential rotation through site configuration.