User management
Manage team → Users lists everyone in your Trialflare team—the same pool of people you can add as trial collaborators. This screen is about organisation membership and team-scoped permissions, not per-trial access (that is configured inside each trial’s settings).
Inviting users
If you have users.create, you can Add a new user and enter a work email address. Trialflare sends an invitation so they can complete account setup.
- If the person already has a Trialflare account on another team, the product can send a cross-team invitation email so they can join yours.
- After someone accepts, they appear in the table with registration and last seen timestamps.
Team permissions per user
Users with users.manage see a gear menu on each row. From there you can toggle the team permissions (create users, delete users, manage users, create trials, manage any trial, team access, team manage). Ticks show which keys are currently held at team scope.
User lifecycle and safety
- Disable account — With
users.manage, choose Disable account from a user's menu (a reason is required and logged). They are signed out everywhere and cannot sign in by any route — password, passkey or single sign-on — until an administrator chooses Re-enable account. Their permissions, roles and history are kept, so they still appear in trial personnel lists and in a study's access history. Prefer this to deleting when someone leaves: a deleted account leaves only its email address in the event log. users.delete— Removes a user from the team (with confirmation). The account can be invited again later if needed.- Invite pending — Shown while an invitation is outstanding.
- Account manager — A special root / account manager badge may appear for the platform account contact; that is separate from normal team permission toggles.
- No permissions — If someone has team membership but no team-level or trial-level grants yet, the UI warns that they have no permissions; they still need trial permissions (or
trials.manage) to do study work. - Login lockouts — Failed attempts may be visible; managers can reset incorrect login counters where policy allows.
- Two-factor authentication — Every account with a password must have a second factor, and is asked to set one up when it next signs in; the list flags accounts that have a password but have not set 2FA up yet. If a user has lost the device they sign in with and has no recovery codes left, a manager with
users.managecan choose Reset two-factor authentication from the account's menu: their authenticator app and passkeys are removed, they are signed out, and they set up a new second factor when they next sign in. Accounts that sign in with Google or Microsoft single sign-on are not flagged — the identity provider handles their second factor.
Pagination and filters
Use filter and sort (name or created date) to work through large rosters. Lists are paged (typically 30 users per page) with previous/next controls.
Trials vs team
In order for a team member to access a trial, they usually must be added as personnel in that trial’s settings. The team user list includes everyone on the team, even if they are not on any trial yet.
Users with manage any trial can access all trials in the team without being added to each trial’s personnel list.
See also Getting started — Part 10 for the wider collaboration story.