Administrator
An administrator is an account that can be granted access to one or more products, providers, or operators. Access is never granted directly. Instead, an administrator is assigned one or more roles, and each role carries a set of permissions that are always scoped to a specific product or provider.
An administrator comes to exist in one of two ways: the person self-registers, or a Provider Admin invites them. Either way, the person gains access to a product or provider only once a Provider Admin has assigned them a role.
Two-factor authentication
Two-factor authentication (2FA) adds a one-time password (OTP) from an authenticator app as a second login factor, after the email address and password. It becomes mandatory only when the administrator holds a role that requires it, or is a Super Admin. Being assigned any role doesn’t trigger the requirement on its own.
Managing your own 2FA
Each administrator manages their own 2FA from the security settings in their profile (see Account settings), on the Two-Factor (2FA) Authentication Settings page. The page shows the current state:
- Two-Factor Authentication Active. 2FA is set up and protecting the account.
- Two-Factor Authentication Setup Not Finished. Setup was started but not confirmed.
- Two-Factor Authentication Required. A role requires 2FA, but it isn’t set up yet.
- Two-Factor Authentication Disabled. 2FA isn’t set up and isn’t required.
From this page the administrator can:
- Setup. Scan a QR code with an authenticator app (for example Google Authenticator, Microsoft Authenticator, Duo Mobile, FreeOTP, 1Password, or Aegis) and confirm the generated code to activate 2FA.
- Disable. Turn 2FA off for the account.
- Manage backup codes—Generate new backup codes or Delete backup codes. Backup codes are shown only once, when generated, and must be stored securely. They are used to recover access when the authenticator app is unavailable.
To disable 2FA, the administrator provides the account’s email address and a valid backup code. An administrator who has lost their authenticator device and has no backup code can’t recover the account on their own. In that case, a colleague administrator can deactivate their 2FA for them, as described next.
Deactivating another administrator’s 2FA
When an administrator loses their authenticator device and has no backup code, a colleague can turn off their 2FA so they can set it up again from scratch. This is the recovery path when self-service isn’t possible.
Any administrator who holds the administrate_access_control_management permission on a provider they share with the locked-out administrator can do this. That permission comes with the Provider Admin and Provider KAM roles, so a Provider Admin can free a colleague who works under the same provider.
To deactivate another administrator’s 2FA in Control Center:
- Open the other administrator’s profile page.
- In the Deactivate 2FA card, select Deactivate 2FA.
- Confirm the action.
The system turns off the administrator’s active 2FA and clears the stored authenticator secret. The administrator can then sign in and set up 2FA again from their own security settings. If their role requires 2FA, they must set it up again before they regain full access.
The Deactivate 2FA card appears only to an administrator who can perform the action, and the Deactivate 2FA button appears only while the target administrator currently has 2FA active. If the target administrator has no active 2FA, the card explains that there is nothing to deactivate.
Deactivating another administrator’s 2FA is not gated by an identity check in the system. Before doing so, confirm the request genuinely comes from the account holder—for example, by requiring it to arrive from the email address associated with the account.
Support only needs to step in when no eligible colleague administrator is available—for example, when every administrator who shares the provider has lost access at the same time.
Account self-service
Administrators can change their own account attributes, and delete their own account, under Account settings.
For managing administrators in the UI, see Administrators in Control Center and Administrators in the Management Area.