Everyone who uses the portal is managed on the Users page: Admin → Users in the sidebar. The page is titled "Users — Invite and manage your team's access."
Who can do what here
Each action needs the matching User Management permission. The built-in Administrator role has all of them. See Roles & permission groups.
| To do this | You need |
|---|---|
| See the Users page | User Management → read |
| Invite people | User Management → create |
| Change roles, disable or enable accounts, assign locations | User Management → update |
| Revoke a pending invitation | User Management → delete |
Team managers can do a limited version of this for their own locations from My Team. See Team managers & audit log.
Invite a user
Invitations are for people who sign in with Microsoft 365. For someone without a Microsoft 365 account, ask intSignal to create an email account instead. See Signing in.
Open Users
In the sidebar, select Admin → Users, and find the Invite a user card.
Enter their details
Type their email address in the email@company.com field, and their Full name. Use the exact address they sign in to Microsoft 365 with, or their sign-in won't match the invitation.
Choose their roles
Under Roles, select one or more roles or permission groups. At least one is required; Send invite stays unavailable until you pick one. If you choose several, they get everything each one grants.
Send the invitation
Select Send invite. The person appears under Pending invites and may receive an invitation email telling them to sign in with Microsoft.
They sign in
When they select Sign in with Microsoft at portal.intsignal.com with that email address,
their account becomes active with the roles you chose. New users can see their whole company
until you assign locations.
Tip
There's no separate step to resend an invitation. The invitation stays pending until the person signs in, so if they didn't get an email, send them the portal address and tell them to use Sign in with Microsoft.
Revoke a pending invitation
Under Pending invites, each invitation shows the person's name and email. Select Revoke to cancel it; that email address can no longer be used to join from that invitation. Revoke invitations sent to the wrong address, or to people who no longer need access.
The users table
Below the invitations, a table lists everyone in your organization:
| Column | What it shows |
|---|---|
| Name | The person's name and email address |
| Roles | Every role and permission group they hold |
| Status | active — can sign in. disabled — blocked from signing in |
| Last login | The date they last signed in, or — if they never have |
Last login is a quick way to spot accounts nobody uses. Review them regularly and disable those that aren't needed.
Change someone's roles
Start editing
Find the person and select Edit roles.
Adjust their roles
Select or clear roles and permission groups. They must keep at least one; Save is unavailable while none is selected.
Save
Select Save to apply, or Cancel to discard. The change takes effect on their next action, without them needing to sign out.
Disable or re-enable an account
Select Disable next to a person to block them immediately. They're signed out at once and can't sign in again, whichever sign-in method they use. To restore access, select Enable.
Disable acts immediately
There's no confirmation prompt, so check you've picked the right person. You can't disable your own account.
People can't be deleted. Disabling is how you remove someone's access, and their name stays in the list.
When someone leaves
Do both of these on their last day:
- Disable them in the portal. This takes effect immediately, including ending any session they have open right now.
- Disable them in Microsoft 365 if they used Microsoft sign-in. This stops them signing in to anything else in your organization.
Disabling only in Microsoft 365 isn't enough on its own. It stops new sign-ins, but a portal session that's already open keeps working until it times out.
Assign locations
If your organization has locations, you can limit people to the tickets for particular locations. By default everyone sees their whole company, and the panel shows that label next to them.
Assigning locations can't be fully undone from the portal
As soon as you assign any location to someone, they're limited to their assigned locations. This stays true even if you later unassign them from every location: they aren't returned to company-wide access. A person with no locations left sees no tickets at all. To give someone company-wide access again, contact intSignal.
Open the Assign locations panel
It's at the top of the Users page, with a Locations list on one side and a Users list on the other.
Pick the locations
Search with Search locations… if the list is long, and select one or more locations. Selecting a location pre-checks the people already assigned to it, highlighted, so you can see current assignments before changing anything.
Pick the people
Select the people to change, using Search users… to find them. Use the assigned only filter to show just the people already assigned to the locations you selected, or all to show everyone.
Assign or unassign
Select Assign ↓ to give the selected people access to the selected locations, or Unassign to remove those locations from them.
What changes for a person limited to locations:
- They see only the tickets for their assigned locations, including when they filter tickets by location.
- Tickets that aren't tied to any location, such as company-level requests, are not visible to them.
- Machine-level limits for Monitoring and Remote Access are separate, and are set on Machine access.
Common questions
A person's name looks wrong. Their name comes from the Full name you typed on the invitation. Microsoft 365 is only used if that was left blank, and changes made in Microsoft 365 later aren't copied over. Names can't be edited in the portal, so ask intSignal to correct it, and double-check the name before selecting Send invite.
Can I change someone from Microsoft sign-in to an email account? Not from the portal. Each account has one sign-in method, set when it's created. Contact intSignal.
Someone can't see a page they should. Check their roles here, then check the role's permissions on Permission Groups. If nobody can see it, the module may not be enabled for your organization. See How access is decided.
