A user is a person in your organization. People join by creating the organization, by signing in through your organization’s SSO provider, by accepting an invitation, or by being provisioned by your identity provider over SCIM. Each person belongs to one organization at most.
A new user has no access until policies are attached to them, directly or through a group. See Policies.
View users
In the console, open IAM > Users. Select a user to see their Groups, their Permissions (every policy that applies to them, and whether it’s attached directly or through a group) and their API keys.
Users provisioned by SCIM show Managed by SCIM. Users your identity provider suspended show Suspended.
Listing users needs users.list; viewing one needs users.get.
Invite a user
An invitation names an email address and, optionally, the groups the person joins and the policies attached to them when they accept. Invite people with the CLI or the API.
ezgh iam users invite --email ada@example.com --group developers --policy ReadOnlyAccessThe command prints the accept link. --expires-in-days sets the expiry.
curl https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/invitations \
-H "Authorization: Bearer $EZGH_API_KEY" \
-H "Content-Type: application/json" \
-d '{"email": "ada@example.com", "groupIds": ["<group ID>"], "policyIds": ["ReadOnlyAccess"]}'The response’s url is the accept link. See CreateInvitation.
- No email is sent. Share the accept link,
https://login.ezghcloud.com/invitations/<invitation ID>, with the person. - An invitation expires after 7 days unless you set 1 to 30 days.
- Creating an invitation needs
invitations.create. Giving groups also needsgroups.updateMemberson each group, and giving policies needspolicies.attach. - There can be one pending invitation per email address. Inviting someone who is already in the organization returns
409withalready_member; a second pending invitation returns409withinvitation_exists. - In an organization with SCIM turned on, you can’t invite email addresses in your verified SSO domains. Those people come from your identity provider.
Accept an invitation
The invitee opens the accept link, signs in, and selects Accept or Decline. With the CLI, they run ezgh invitations list, then ezgh invitations accept <invitation ID>.
- Invitations match the signed-in person’s verified email address, compared without case. A person whose email address isn’t verified gets
403withemail_not_verified. - Accepting joins the organization with the invitation’s groups and policies. Groups and policies deleted since the invitation was made are skipped.
- Someone who already belongs to another organization gets
409withorganization_exists. They must leave that organization first. - Accepting and declining need a signed-in person. API keys can’t accept or decline invitations.
Manage invitations
Invitations have the status pending, accepted, declined, revoked or expired. You can revoke a pending invitation.
ezgh iam invitations list --status pending
ezgh iam invitations revoke <invitation ID>curl "https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/invitations?status=pending" \
-H "Authorization: Bearer $EZGH_API_KEY"
curl -X DELETE https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/invitations/$INVITATION_ID \
-H "Authorization: Bearer $EZGH_API_KEY"See ListInvitations and RevokeInvitation.
Change a user’s groups
Each group a user joins or leaves needs groups.updateMembers on that group.
- Open IAM > Users and select the user.
- On the Groups tab, select Edit groups.
- Select the groups, then Save.
ezgh iam users update ada@example.com --add-groups developers
ezgh iam users update ada@example.com --remove-groups developers
ezgh iam users update ada@example.com --groups developers,operators--groups replaces all of the user’s groups.
curl -X POST https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/users/$USER_ID/groups/$GROUP_ID \
-H "Authorization: Bearer $EZGH_API_KEY"See AddUserToGroup, RemoveUserFromGroup and SetUserGroups.
To attach policies to a user directly, see Attach a policy.
Remove a user
Removing a user takes them out of the organization. Their group memberships and directly attached policies are removed, and their API keys for the organization are revoked. Removing needs users.delete.
ezgh iam users remove ada@example.comcurl -X DELETE https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/users/$USER_ID \
-H "Authorization: Bearer $EZGH_API_KEY"See RemoveUser.
- You can’t remove the root user. They must make someone else root first.
- A removed user isn’t added back by signing in through your SSO provider. Invite them again to let them back in.
- While SCIM is on, users it provisioned are removed in your identity provider, not here (
409withmanaged_by_scim).
Make another user root
The root user can hand root to another user. Open IAM > Users, select the user, then select Make root. The previous root user keeps the AdministratorAccess policy, attached like any other policy. Only the signed-in root user can do this. See TransferOrganizationRoot.
Reactivate a suspended user
A user your identity provider suspended over SCIM stays suspended after you turn SCIM off. To let them sign in again, open their user page and select Reactivate. They get back the groups and policies they had; API keys revoked when they were suspended don’t come back. Reactivating needs users.reactivate. See SCIM provisioning.