Users and roles
Create accounts, pick the role, restrict visible modules, disable an account or reset its two-factor authentication.
Accounts are managed in Settings → Users. The tab only appears for administrators.
The roles
| Role | What it can do |
|---|---|
| Viewer | See everything, change nothing |
| Operator | See and handle: acknowledge or resolve alerts and incidents, run a test, set up a maintenance window |
| Administrator | Everything within its organisation: configuration, users, deletions, API tokens, NetDiag settings, AI, connectors |
An account created automatically through SSO gets the Viewer role. The platform's super administrator has a separate sign-in and manages organisations; it does not appear in your list.
Create an account
Click Add, then enter the name, email address, role and a starting password. That password must be at least 12 characters, with an upper-case letter, a lower-case letter, a digit and a special character. Send it through a different channel from the console address, and ask the person to change it at first sign-in.
An email address can only be used by one account across the whole platform.
Restrict a user's modules
In a user's record, Module access lists the modules they will see. If no box is ticked, a non-administrator sees every module in the organisation. The restriction also applies on the server side, to the API and to the AI Assistant: it is not just a hidden menu.
Edit, disable, delete
Changing the role, resetting the password or unticking Active user immediately closes all of that person's sessions.
Prefer disabling to deleting: the history stays readable (audit log, handled incidents). An administrator cannot delete their own account.
Reset two-factor authentication
The Two-factor column shows, for each account, whether it is Enabled or Not set up. This is where to check that everyone has set it up when your organisation requires it.
When someone has lost their phone or security key and has no backup code left, click the crossed-out shield button on their row (tooltip: “Reset two-factor authentication (lost phone or key)”). This erases their authenticator app, backup codes and security keys, and closes their sessions. At their next sign-in they get in with their password alone; if your organisation requires two-factor authentication, they have to set it up again before they can do anything else.
The button does not exist for your own account: use Settings → Security instead. Every reset is recorded in the audit log.
Targeted delegations
Some actions can be handed to a named person who is not an administrator, for example managing firewall devices or DBMonitor check queries. These delegations are set by the platform administrator.
Source: · FirstSI Docs · updated 2026-10-10