> For the complete documentation index, see [llms.txt](https://docs.expel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.expel.io/workbench-setup/get-started/add-and-manage-users.md).

# Add and Manage Users

{% hint style="info" icon="user-crown" %}
You must be an [Organization Admin user](/workbench-setup/get-started/add-and-manage-users/user-role-rights.md) to add and manage other users in Workbench.
{% endhint %}

## Prerequisites <a href="#h_01jaznwt5ympmw4b504k1s0tcb" id="h_01jaznwt5ympmw4b504k1s0tcb"></a>

1. **All users must install an authenticator application such as Duo or Google Authenticator on their smartphone or other portable device with a built-in camera, or log in via SSO.** Expel requires non-SSO users to set up their Workbench account with multi-factor authentication (MFA) and to use it every time they log in.
2. You must have Organization Admin permissions in Workbench to manage users.

## Add a User Account <a href="#h_01j0vpwav478894tewydxrgcwe" id="h_01j0vpwav478894tewydxrgcwe"></a>

Adding users to Workbench allows other members of your organization to monitor the status of your environment. Before you add a user, make sure you know the level of access the user needs ( organization analyst or organization admin). Administrator rights should not be assigned to everyone. [Learn more about user role rights in Expel Workbench.](/workbench-setup/get-started/add-and-manage-users/user-role-rights.md)

**If your organization uses SSO for logins, you must make sure that every new Workbench user is also assigned the Workbench app in your SSO provider.** To configure SSO in Workbench, go to [Connect Your Single Sign-On Tools](/workbench-setup/get-started/configure-your-sso-provider-with-workbench.md) and follow the instructions for your provider, then return to this setup guide.

To add a user to your organization:

1. [Log in to Workbench](https://workbench.expel.io/auth/login?orig=%2F).
2. Select **Organization Settings > Users**.
3. In the upper right, select **Add User**.
4. The Add User screen appears. Complete the following:
   * **Email/Username** - this must be an email address.
   * **Organization** - select the organization this user should have access to. If you don't have multiple organizations, this list isn't available.
   * **First name** - the user's first name.
   * **Last name** - the user's last name.
   * **Workbench user role** - select Organization Admin or Organization Analyst role for this user. *Keep in mind that Organization Admin gives full administrator rights to your organization's Workbench.*
   * **Organization Contact** - select if you want this user to be the point of contact for your organization if Expel needs to reach out.
   * **Assignable** - select if you want this user to be assigned alerts, actions, or investigations. For example, an analyst needs to see these. An admin may not need to see them.
5. Select **Save**.
6. SSO logins only - you must now also add (or ask someone at your organization to add) the Workbench app to the SSO platform for the user.

The new user account will appear with a "Locked" status until it is [activated](/workbench-setup/get-started/activate-your-workbench-account.md). After the user activates their account, the status will change to "Active" or "Assignable" based on the settings you chose.

## Edit a User Account <a href="#h_01htezy9bpd826jha875bzntt4" id="h_01htezy9bpd826jha875bzntt4"></a>

To edit user information or settings:

1. [Log in to Workbench](https://workbench.expel.io/auth/login?orig=%2F).
2. Select **Organization Settings > Users**.
3. Select the dropdown arrow next to the user whose account you want to edit.
4. Select **View and edit**.
5. Select **Edit User** to make necessary changes.
6. Select **Save**.

{% hint style="info" %}
To edit user **email notifications**, refer to [Manage Email Notifications](/workbench-setup/notifications/manage-email-notifications.md#manage-email-notifications-for-a-user-admins-only).
{% endhint %}

## Lock or Unlock a User Account <a href="#h_01j0y2x7e5p1f0wcpj9dgx87mq" id="h_01j0y2x7e5p1f0wcpj9dgx87mq"></a>

1. [Log in to Workbench](https://workbench.expel.io/auth/login?orig=%2F).
2. Select **Organization Settings > Users**.
3. Select the dropdown arrow next to the user you want to lock or unlock.
4. Select **Lock** or **Unlock**, depending on their current status.
5. The account status changes accordingly. (There is no confirmation message.)

{% hint style="info" %}
If a user's status reads "Locked - Re-enrollment sent" on their page, it means the user needs to check their email for an activation invitation. For instructions, see [Activate Your Workbench account](/workbench-setup/get-started/activate-your-workbench-account.md).
{% endhint %}

<div align="left"><figure><img src="/files/PvhKTVmcsStBpQVcTbrv" alt="Example indicates user John Smith has a status of Locked - Reenrollment sent" width="375"><figcaption></figcaption></figure></div>

## Delete a User Account <a href="#h_01j0y3yj9recxex7es78k0ses4" id="h_01j0y3yj9recxex7es78k0ses4"></a>

{% hint style="warning" %}
If you perform this action, account access is revoked immediately and permanently. The account no longer appears in the list. However, the user's activity history is still available.
{% endhint %}

1. [Log in to Workbench](https://workbench.expel.io/auth/login?orig=%2F).
2. Select **Organization Settings > Users**.
3. Select the dropdown arrow next to the user you intend to delete.
4. Select **Delete user**.
5. Select **Delete**.
6. Workbench confirms the action with a "Successfully deleted user" message in the lower right.

## Resolve First-Time Login Issues <a href="#h_01jaznxhn76ygez3w9q3f38bra" id="h_01jaznxhn76ygez3w9q3f38bra"></a>

### SSO Users <a href="#h_01jaznxwxdf9pzx5j4594jmtf4" id="h_01jaznxwxdf9pzx5j4594jmtf4"></a>

SSO users must have the Workbench app added to their SSO platform by an administrator at your company. Their Workbench account must also use the same email address that is used by that platform.

1. First, verify that the user has the Workbench app in their SSO platform *and* that they have used the app (not a URL) to try to log in.
   * If they do not see the app, contact the appropriate support person at your organization to get it added.
2. If they do have the app but their login is failing, check their account in Workbench.
   * [Log in to Workbench](https://workbench.expel.io/auth/login?orig=%2F).
   * Select **Organization Settings > Users**.
   * Look for the user and verify that their email address matches the email used for their SSO platform.
   * If it does not, use the arrow to select **View and edit** and then select the **Edit User** button to update their email address.

If the user is still unable to log in after following these steps, [contact support](/support/how-to-reach-us.md) for help.

### Non-SSO Users <a href="#h_01j0vq877brxteyrsn4p6ypfe7" id="h_01j0vq877brxteyrsn4p6ypfe7"></a>

Non-SSO users should have received a "Welcome to Expel" email that includes a link to activate their account.

1. First, verify that the user tried to access their account via the link in the Welcome email (not via a Workbench URL).
   * If they cannot find the Welcome email, continue with this process.
   * If the link did not work, [contact support](/support/how-to-reach-us.md) for help.
2. [Log in to Workbench](https://workbench.expel.io/auth/login?orig=%2F).
3. Select **Organization Settings > Users**.
4. Look for the user.
   * Verify with the user that their email address is the one you see listed in Workbench.
   * If you need to update the user's email address, use the arrow to select **View and edit** and then select the **Edit User** button to update their email address, then return to the list of users.
   * Use the arrow to select **Resend enrollment email**.

If the user is still unable to log in after following these steps, [contact support](/support/how-to-reach-us.md) for help.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.expel.io/workbench-setup/get-started/add-and-manage-users.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
