Skip to content

Managing Users

Learn how to invite users, assign roles, and manage user permissions.

Viewing Users

User List

  1. Go to Settings > Users
  2. View all users in your organization

The list shows:

  • User name and email
  • Role
  • Status (Active, Pending, Inactive)
  • Last activity

Screenshot Coming Soon

Screenshot of user list will be added here.

Inviting Users

Send an Invitation

  1. Go to Settings > Users
  2. Click Invite User
  3. Enter the user's email address
  4. Select their role
  5. Click Send Invitation
!!! note "Animation Coming Soon" Animated GIF showing user invitation will be added here.

Invitation Process

When you invite a user:

  1. They receive an email with an invitation link
  2. They click the link to accept
  3. They create a password
  4. They're automatically signed in

Invitation Expiration

Invitations expire after 7 days. If an invitation expires:

  1. Go to Settings > Users
  2. Find the pending invitation
  3. Click Resend Invitation

User Roles

Roles are structural and control access to settings and user management. They are mutually exclusive.

Role Descriptions

org_owner

Organization Owner

  • Full access to all organization settings
  • Can manage billing and seat purchasing
  • Can invite and manage all users
  • Can assign and revoke SignatureManager seats
  • Can access all documents and requests
  • Can view complete audit logs

org_admin

Organization Admin

  • Can manage users (invite, edit, deactivate)
  • Can edit organization settings
  • No access to billing
  • Can sign documents assigned to them

user

User

  • Can view documents and signature requests
  • Can sign documents assigned to them
  • Cannot create or send signature requests (requires a SignatureManager seat)
  • Cannot manage users or organization settings

Signature Capability Flags

Independently of role, users can hold a SignatureManager capability that allows creating and sending signature requests. These flags are orthogonal to the structural role.

A SignatureManager (paid or demo) seat is required to upload documents and to create and send signature requests. Users with neither can only view and sign.

Flag Cost Behavior
SignatureManager (paid) $950/seat/year Upload documents, create/send requests; clean unbranded PDFs
SignatureManager (demo) Free & unlimited Same access as paid; signed PDFs watermarked DEMO
Neither Free Can only view and sign

Demo seats are free and unlimited — they do not count against your purchased paid-seat quota. The Billing page shows the number of demo seats in use alongside your paid seats.

Mutual Exclusivity

A user cannot hold both a paid and a demo seat simultaneously.

Assigning Seats

Only Organization Owners can assign seats.

  1. Go to Users
  2. Click on the user
  3. In the SignatureManager Seat section, click Assign Paid Seat or Assign Demo Seat
  4. Click Revoke Seat to remove capability

Seat Availability

Paid seats must be purchased first in Billing before they can be assigned. Demo seats are always available at no cost.

Changing User Roles

  1. Go to Settings > Users
  2. Click on the user
  3. Click Edit
  4. Select the new role
  5. Click Save

Role Changes Take Effect Immediately

When you change a user's role, they gain or lose access immediately. No notification is sent.

Passkeys for Signing

Every signature event in a GxP-enabled organization requires a fresh re-authentication — there is no session caching (EU Annex 11 § 13.3). The fastest method available is a WebAuthn passkey: one biometric tap (Touch ID, Face ID, Windows Hello, Android biometric, or a hardware security key).

What admins need to know

  • Self-service enrollment. Users register their own passkeys at Your profile → Passkeys. No admin action is required to enable passkey signing for a user.
  • Multiple passkeys per user. Encourage users to register at least two (e.g. phone + laptop) so they are not locked out if a single device is lost.
  • Per-organization policy. You can require passkeys at the organization level so that password and SSO step-up are disabled as signing fallbacks. See Require Passkey to Sign.
  • Lost device. A user can revoke a lost passkey themselves from Your profile → Passkeys → Remove. If they have lost access to all their devices, deactivate their account, reset access through their SSO IdP if applicable, or remove credentials via Django admin.

The end-user setup guide is at Passkeys (Touch ID / Face ID / Hello).

GxP User Fields

For organizations with GxP compliance enabled, additional user fields are available.

Available Fields

Field Description
Employee ID Unique organizational identifier
Training Status Current training completion status
Signature Authority Signing authority level (1-5)

Training Status Options

Status Description
Pending Training not started
In Progress Currently being trained
Completed Training finished and verified
Expired Training needs renewal

Editing GxP Fields

  1. Go to Settings > Users
  2. Click on the user
  3. Click Edit
  4. Update the GxP-specific fields
  5. Click Save

Compliance Note

Changes to GxP fields are logged in the audit trail for compliance purposes.

Deactivating Users

When a user leaves your organization:

  1. Go to Settings > Users
  2. Click on the user
  3. Click Deactivate
  4. Confirm deactivation

Deactivated users:

  • Cannot sign in
  • Retain their signature history
  • Can be reactivated later

Delete User

Permanent Action

Deleted users cannot be recovered. Consider deactivating instead.

  1. Go to Settings > Users
  2. Click on the user
  3. Click Delete
  4. Confirm deletion

Bulk Operations

Export User List

  1. Go to Settings > Users
  2. Click Export
  3. Select format (CSV or Excel)
  4. Download the file

Bulk Invite

For inviting many users at once:

  1. Prepare a CSV with email addresses and roles
  2. Go to Settings > Users
  3. Click Bulk Invite
  4. Upload the CSV
  5. Review and confirm

User Activity

Viewing User Activity

  1. Go to Settings > Users
  2. Click on a user
  3. View their Activity tab

Activity includes:

  • Sign-in history
  • Documents signed
  • Requests created
  • Settings changes

Last Active

The user list shows when each user was last active:

  • Today - Active within 24 hours
  • This week - Active within 7 days
  • Date - Shows the actual date for older activity

Best Practices

  1. Least privilege - Assign the minimum role needed
  2. Regular audits - Review user list periodically
  3. Prompt deactivation - Deactivate departed users immediately
  4. Document roles - Keep a record of who has what access
  5. GxP training - Keep training status current for compliance