Admin management

Permissions: administrate_access_control_management to assign administrators to products, providers, and operators, deactivate_two_factor_auth to reset an administrator’s two-factor authentication

For what this feature does, see Admin management in Platform.

If this feature is activated, an index of all administrators can be found top level in the product overview.

Here, we find the following information on the admins:

  • ID. Internal ID of the administrator.
  • Name. Concatenation of first and last name.
  • Email. Specified email address.
  • Current sign in at. When was the last sign in into this product.
  • Sign in count. How often has this administrator signed in and opened the product.
  • Roles. Which roles does this administrator possess for the current product.
  • Locked. If the administrator is locked, this is shown here.
  • Confirmed. If the mail address is confirmed, a green check mark is shown here.
  • Uses two-factor authentication. If the administrator has activated the two-factor authentication this is also marked with a green check mark.

Note, that Super Admins do not appear in this list.

In the dropdown menu on the individual administrators, the following actions are possible:

  • Show. Gives an overview on the administrator, including the assigned products, providers and all assigned roles including the induced permissions.
  • Edit. Can be used to edit certain information on the administrator.
  • Lock. This locks the administrator, such that he or she can not log in anymore. This is active by default if the administrator is not confirmed yet.
  • Generate new two-factor authentication. This generates a new authentication secret in the form of a QR code, which can be scanned with a two factor-authentication app of choice. This code can then be verified here and used to activate the administrator account. Before resetting another administrator’s 2FA (for example, when they are locked out), verify that the request genuinely comes from the account holder; see Two-factor authentication.
  • Manage roles. Here, roles can be assigned to the corresponding administrator. This defines the connected permissions, i.e., the access rights.
  • Archive. Anonymizes the information and archives the administrator.

Additionally, new administrators can be defined here. Therefore, click the button Add on the index page.

In the following dialog, the first thing which has to be entered is an email address.

If there is already an administrator with this mail address, the product is assigned to the existing administrator. If not, it’s possible to create the account.

Therefore, the following information has to be specified additionally to the email address:

  • First name and Last name,
  • Language
  • Password and again as Password confirmation
  • Two-factor token card (leave blank if a mobile phone will be used). There are two possibilities to activate two-factor authentication. One is via a mobile phone: in this case, this field should be left blank. In the next step a QR code is generated with the authentication secret and can be confirmed using the mobile app of choice of the administrator.