Two tools help larger organizations spread the work of managing access without handing out full administrator rights: team managers, who look after the people at their own locations, and the audit log, which records every change so nothing happens unseen.
Team managers
A team manager can invite, adjust, and disable the people at their own locations from the My Team page, described as "Manage the people at your location(s) and their access." They don't need, and don't get, any wider administrator rights.
Who can be a team manager
- Administrators are always team managers.
- Anyone else becomes a team manager when intSignal turns it on for them. It isn't a role, so you can't grant it from Permission Groups. Ask intSignal, and tell them which person.
A team manager works within their locations, so they should be assigned to locations themselves. A manager with company-wide access can manage people at any location.
What a team manager can and can't do
| A team manager can | A team manager can't |
|---|---|
| Invite new people to one of their locations | Invite anyone to a location outside their own |
| Give people any role except Administrator | Assign the Administrator role |
| Change the roles of people at their locations | Manage anyone who holds the Administrator role |
| Disable and re-enable people at their locations | Manage their own account |
| See pending invitations for their locations | Manage people who have company-wide access |
Who appears on My Team
My Team lists the people a manager is allowed to manage: everyone whose assigned locations all fall within the manager's own locations, excluding Administrators and the manager themselves.
People with company-wide access, who haven't been assigned to any locations, don't appear on My Team. Only someone with User Management permissions can manage them, from the Users page.
Invite a team member
Open My Team
Select Admin → My Team, and find Invite a team member.
Enter their details
Enter their email address and Full name.
Choose their location
Pick one Location from the list. Only your own locations are offered. The new person is limited to that location.
Choose their roles
Select one or more Roles. Administrator isn't available here.
Send it
Select Send invite. It appears under Pending invites until they sign in with Microsoft.
Manage your team
The team table shows each person's Name, Location, Roles, and Status.
- Change roles: select Edit roles, adjust the selection, which must keep at least one role, and select Save, or Cancel to discard.
- Disable or enable: select Disable to block the person immediately, or Enable to restore them. There's no confirmation prompt.
Messages you might see
| Message | Why |
|---|---|
| That location is outside your scope | You tried to invite someone to a location that isn't yours. |
| That team member is outside your scope | The person holds the Administrator role, has company-wide access, or has locations outside yours. |
| You cannot manage your own account here | Managers can't change their own roles or status. Ask an administrator. |
| A user with that email already exists | That person already has an account in your organization. |
| An invite for that email already exists | A pending invitation already exists for that address. |
| Select at least one role | Every invitation and account needs at least one role. |
| One or more roles cannot be assigned | A selected role isn't assignable, such as the Administrator role. |
Audit log
The audit log records every change in your organization, whether made by your team or by intSignal. Open it from Admin → Audit Log; it's titled "Audit log — Every change in your organization — by your team and by intSignal. Filter and export." Team managers and Administrators can see it.
Reading the log
Each entry shows:
| Column | What it shows |
|---|---|
| When | Date and time of the change |
| Account | Who made the change |
| Action | What kind of change it was |
| Target | What was changed |
| Details | Additional context for the change |
The number of matching entries is shown next to the filters.
Filtering
Combine any of these to narrow the log:
- Account: type an email address, such as
name@company.com, to see changes made by one person. - Action: choose one kind of change, or All actions.
- From and To: limit it to a date range.
- Newest first ▼ / Oldest first ▲: select to switch the sort order.
- Clear: reset every filter at once. It appears once any filter is set.
Exporting
Select Export CSV to download audit-log.csv. The export uses the filters you've set, so
filter first to get exactly the slice you need, or clear all filters to export everything.
Use it as audit evidence
Auditors routinely ask for proof that access changes are recorded and reviewed. A periodic export, for example the last quarter filtered to role and account changes, alongside your access review, is exactly that evidence. File it in the free compliance evidence workspace against the matching control.
Useful questions the log answers
- Who gave this person access? Filter Action to role or invitation changes, and look for their name under Target.
- What did this account change last week? Filter Account to their email, and set From and To.
- Did intSignal change anything? The log includes intSignal's changes alongside your team's, so the Account column shows who acted.
