Skip to content

User Management

This article covers how to create and manage user accounts on the SenseOn platform, including role assignment, account lifecycle operations, and the permissions model.

💡 Who can manage users? Admins can manage every account. Managers can invite users as Managers or Analysts and edit Manager and Analyst accounts, but cannot delete accounts or change Admin accounts.


Accessing User Management

Navigate to Settings > Team to view and manage all user accounts in your organisation.


User Roles

SenseOn uses a role-based access model with three standard roles. Each user is assigned exactly one role.

Role Capabilities
Analyst View and work cases, run Hunt Lab queries, access Experience, Dashboards, and Assets. Cannot manage users or platform settings.
Manager Everything an Analyst can do, plus device configuration and segments. Can invite users as Managers or Analysts and edit Manager and Analyst accounts, but cannot delete accounts.
Admin Full platform access including user management, segment configuration, integration setup, and API token administration.

âš  Active Response is a separate permission. Active Response access is granted independently of the above roles. An Admin who already has Active Response access can grant it to any user, and SenseOn grants it to your first user. See Active Response for details.


Creating a User Account

  1. Go to Settings > Team.
  2. Click Invite User.
  3. Enter the user's email address, full name, and job title.
  4. Select their role (Analyst, Manager, or Admin).
  5. Click Send Invite.

SenseOn will send an invitation email to the address you provided. The user must click the link in the email to set their password and activate their account.

💡 Invitation link expiry: Invitation links expire after 7 days. If the user does not activate in time, you can resend the invitation (see below). To prevent abuse, resending is rate-limited to once every 30 seconds per user.


Resending an Invitation

If a user has not received or has not acted on their invitation:

  1. Go to Settings > Team.
  2. Find the user in the list (they will show a Pending status).
  3. Click the three-dot menu next to their name.
  4. Select Resend Invite.

Updating a User Account

To update a user's name, job title, or email address:

  1. Go to Settings > Team.
  2. Find the user and click the three-dot menu.
  3. Select Edit User.
  4. Make your changes and click Save.

To change a user's role, use the same three-dot menu and select Change Role.


Disabling and Re-enabling a User

Disabling a user prevents them from logging in without deleting their account or its history. This is recommended for temporary access suspension (for example, during a leave of absence).

  1. Go to Settings > Team.
  2. Find the user and click the three-dot menu.
  3. Select Disable User.

The user's account will be marked as inactive. To re-enable the account, follow the same steps and select Enable User.


Deleting a User Account

Deleting a user permanently removes their account. Audit records and case history associated with the user are retained.

  1. Go to Settings > Team.
  2. Find the user and click the three-dot menu.
  3. Select Delete User.
  4. Confirm the deletion in the popup.

âš  This action cannot be undone. If you only need to revoke access temporarily, disable the account instead.


Password Management

Resetting a user's password (Admin)

If a user cannot log in, an Admin can trigger a password reset email:

  1. Go to Settings > Team.
  2. Find the user and click the three-dot menu.
  3. Select Reset Password.

The user will receive an email with a password reset link.

Changing your own password

  1. Click your profile icon in the top-right corner.
  2. Select Change Password.
  3. Enter your current password and your new password.
  4. Click Save.

Multi-Factor Authentication

SenseOn supports time-based one-time password (TOTP) multi-factor authentication. See the Multi-Factor Authentication article for setup instructions.

âš  MFA is mandatory for Active Response users. Any user with Active Response access has MFA enforced, regardless of the organisation-level MFA setting.


Single Sign-On

Single sign-on for customer logins is on the SenseOn roadmap but is not yet generally available. See Single Sign-On for the current position and how to register your interest.