---
title: "Users"
description: "Invite people to your organization, change their groups, and remove them."
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.ezghcloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Users

A user is a person in your organization. People join by creating the organization, by signing in through your organization's SSO provider, by accepting an invitation, or by being provisioned by your identity provider over [SCIM](/iam/scim). Each person belongs to one organization at most.

A new user has no access until policies are attached to them, directly or through a group. See [Policies](/iam/policies).

## View users

In the console, open **IAM** > **Users**. Select a user to see their **Groups**, their **Permissions** (every policy that applies to them, and whether it's attached directly or through a group) and their **API keys**.

Users provisioned by SCIM show **Managed by SCIM**. Users your identity provider suspended show **Suspended**.

### CLI

```sh
ezgh iam users list
ezgh iam users get ada@example.com
```
### API

```sh
curl https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/users \
  -H "Authorization: Bearer $EZGH_API_KEY"
```

See [ListUsers](/orgs-api/users/ListUsers/) and [GetUser](/orgs-api/users/GetUser/).

Listing users needs `users.list`; viewing one needs `users.get`.

## Invite a user

An invitation names an email address and, optionally, the groups the person joins and the policies attached to them when they accept. Invite people with the CLI or the API.

### CLI

```sh
ezgh iam users invite --email ada@example.com --group developers --policy ReadOnlyAccess
```

The command prints the accept link. `--expires-in-days` sets the expiry.
### API

```sh
curl https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/invitations \
  -H "Authorization: Bearer $EZGH_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"email": "ada@example.com", "groupIds": ["<group ID>"], "policyIds": ["ReadOnlyAccess"]}'
```

The response's `url` is the accept link. See [CreateInvitation](/orgs-api/invitations/CreateInvitation/).

- No email is sent. Share the accept link, `https://login.ezghcloud.com/invitations/<invitation ID>`, with the person.
- An invitation expires after 7 days unless you set 1 to 30 days.
- Creating an invitation needs `invitations.create`. Giving groups also needs `groups.updateMembers` on each group, and giving policies needs `policies.attach`.
- There can be one pending invitation per email address. Inviting someone who is already in the organization returns `409` with `already_member`; a second pending invitation returns `409` with `invitation_exists`.
- In an organization with SCIM turned on, you can't invite email addresses in your verified SSO domains. Those people come from your identity provider.

### Accept an invitation

The invitee opens the accept link, signs in, and selects **Accept** or **Decline**. With the CLI, they run `ezgh invitations list`, then `ezgh invitations accept <invitation ID>`.

- Invitations match the signed-in person's **verified** email address, compared without case. A person whose email address isn't verified gets `403` with `email_not_verified`.
- Accepting joins the organization with the invitation's groups and policies. Groups and policies deleted since the invitation was made are skipped.
- Someone who already belongs to another organization gets `409` with `organization_exists`. They must leave that organization first.
- Accepting and declining need a signed-in person. API keys can't accept or decline invitations.

### Manage invitations

Invitations have the status `pending`, `accepted`, `declined`, `revoked` or `expired`. You can revoke a pending invitation.

### CLI

```sh
ezgh iam invitations list --status pending
ezgh iam invitations revoke <invitation ID>
```
### API

```sh
curl "https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/invitations?status=pending" \
  -H "Authorization: Bearer $EZGH_API_KEY"

curl -X DELETE https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/invitations/$INVITATION_ID \
  -H "Authorization: Bearer $EZGH_API_KEY"
```

See [ListInvitations](/orgs-api/invitations/ListInvitations/) and [RevokeInvitation](/orgs-api/invitations/RevokeInvitation/).

## Change a user's groups

Each group a user joins or leaves needs `groups.updateMembers` on that group.

### Console

1. Open **IAM** > **Users** and select the user.
2. On the **Groups** tab, select **Edit groups**.
3. Select the groups, then **Save**.
### CLI

```sh
ezgh iam users update ada@example.com --add-groups developers
ezgh iam users update ada@example.com --remove-groups developers
ezgh iam users update ada@example.com --groups developers,operators
```

`--groups` replaces all of the user's groups.
### API

```sh
curl -X POST https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/users/$USER_ID/groups/$GROUP_ID \
  -H "Authorization: Bearer $EZGH_API_KEY"
```

See [AddUserToGroup](/orgs-api/users/AddUserToGroup/), [RemoveUserFromGroup](/orgs-api/users/RemoveUserFromGroup/) and [SetUserGroups](/orgs-api/users/SetUserGroups/).

To attach policies to a user directly, see [Attach a policy](/iam/policies#attach-a-policy).

## Remove a user

Removing a user takes them out of the organization. Their group memberships and directly attached policies are removed, and their API keys for the organization are revoked. Removing needs `users.delete`.

### CLI

```sh
ezgh iam users remove ada@example.com
```
### API

```sh
curl -X DELETE https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/users/$USER_ID \
  -H "Authorization: Bearer $EZGH_API_KEY"
```

See [RemoveUser](/orgs-api/users/RemoveUser/).

- You can't remove the root user. They must make someone else root first.
- A removed user isn't added back by signing in through your SSO provider. Invite them again to let them back in.
- While SCIM is on, users it provisioned are removed in your identity provider, not here (`409` with `managed_by_scim`).

## Make another user root

The root user can hand root to another user. Open **IAM** > **Users**, select the user, then select **Make root**. The previous root user keeps the `AdministratorAccess` policy, attached like any other policy. Only the signed-in root user can do this. See [TransferOrganizationRoot](/orgs-api/organizations/TransferOrganizationRoot/).

## Reactivate a suspended user

A user your identity provider suspended over SCIM stays suspended after you turn SCIM off. To let them sign in again, open their user page and select **Reactivate**. They get back the groups and policies they had; API keys revoked when they were suspended don't come back. Reactivating needs `users.reactivate`. See [SCIM provisioning](/iam/scim#turn-scim-off).

Source: https://docs.ezghcloud.com/iam/users/index.mdx
