> ## Documentation Index
> Fetch the complete documentation index at: https://docs.squawkvoice.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Users

> Manage user access, roles, and permissions across your platform

# User Management

Manage user accounts, roles, and permissions across your SquawkVoice platform. Control access, assign responsibilities, and ensure secure collaboration among team members.

## Overview

User management enables you to control who can access your SquawkVoice platform and what they can do. Create user accounts, assign appropriate roles, and manage permissions to ensure secure and efficient platform usage.

<Card title="User Management Benefits" icon="users">
  * **Secure Access Control**: Manage who can access your platform and data
  * **Role-Based Permissions**: Assign appropriate access levels based on responsibilities
  * **Team Collaboration**: Enable multiple users to work together efficiently
  * **Audit Trail**: Track user activities and changes for compliance
  * **Scalable Administration**: Manage users as your organization grows
</Card>

## User Roles and Permissions

### Understanding User Roles

SquawkVoice provides predefined roles with specific permissions and access levels:

<Columns cols={2}>
  <Card title="Administrator" icon="shield">
    Full access to all platform features, settings, and user management. Can create, modify, and delete any resource.
  </Card>

  <Card title="Manager" icon="user-check">
    Can manage AI agents, view analytics, and configure platform settings. Cannot manage other users or billing.
  </Card>

  <Card title="Agent Builder" icon="bot">
    Can create and configure AI agents, manage knowledge bases, and view call history. Limited access to analytics.
  </Card>

  <Card title="Analyst" icon="bar-chart">
    Can view analytics, reports, and call history. Read-only access to agent configurations and platform data.
  </Card>
</Columns>

### Permission Categories

Permissions are organized into logical categories for easy management:

<AccordionGroup>
  <Accordion title="Agent Management">
    * Create and configure AI voice agents
    * Manage agent settings and behaviors
    * Deploy and activate agents
    * Delete and archive agents
  </Accordion>

  <Accordion title="Knowledge Base">
    * Upload and manage documents
    * Create and configure knowledge bases
    * Organize and categorize content
    * Delete and update knowledge base items
  </Accordion>

  <Accordion title="Analytics and Reporting">
    * View analytics dashboards
    * Access call history and transcripts
    * Generate reports and exports
    * Monitor performance metrics
  </Accordion>

  <Accordion title="User Management">
    * Create and manage user accounts
    * Assign roles and permissions
    * Monitor user activity
    * Manage team access
  </Accordion>

  <Accordion title="Platform Settings">
    * Configure platform-wide settings
    * Manage integrations and APIs
    * Control billing and subscriptions
    * Set security and compliance policies
  </Accordion>
</AccordionGroup>

## Creating and Managing Users

### How Users Are Added

Everyone joins by invitation. **There is no public self-service sign-up** — a visitor who reaches the sign-up URL is redirected to the sign-in page — so a new user arrives either through an invitation you send from **Manage → Users**, or by having an account created for them.

### Adding New Users

1. Navigate to **Manage > Users** in the SquawkVoice Studio
2. Click **Add User** to create a new user account
3. Fill in the required information:

<ResponseField name="Full Name" type="string" required>
  Enter the user's complete name for identification and display purposes.
</ResponseField>

<ResponseField name="Email Address" type="email" required>
  Primary email address for account access and notifications.
</ResponseField>

<ResponseField name="Role" type="select" required>
  Select the appropriate role based on the user's responsibilities and access needs.
</ResponseField>

<ResponseField name="Account Access" type="multi-select">
  Specify which accounts the user can access (for multi-account setups).
</ResponseField>

<ResponseField name="Workspace Access" type="multi-select">
  Define which workspaces the user can access within their assigned accounts.
</ResponseField>

### User Invitation Process

1. **Send Invitation**: User receives an email invitation to join the platform
2. **Account Setup**: User creates password and completes profile setup
3. **Access Verification**: User can access assigned features and resources
4. **Onboarding**: User receives welcome materials and training resources

<Note>
  An invitation link is valid for **72 hours**. After that the invitation shows as **Link expired** — but it is still recoverable, without re-inviting: see Pending Invitations below.
</Note>

### Pending Invitations

**Manage → Users** carries a **Pending Invitations** section listing everyone who has been invited but has not activated their account. Each entry is tagged **Invite not activated**, and **Link expired** once it is more than 72 hours old.

Two actions are available on each:

| Action           | What it does                                                                                                                                                                                     |
| ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Set password** | Generates a strong password, activates the account, marks the email verified, and shows you the password once so you can pass it on out of band. Use it when the invitation email never arrives. |
| **Revoke**       | Withdraws the invitation.                                                                                                                                                                        |

The same capability exists for an **existing** user, from a key icon on their row in the user list. It opens **Set password manually**: "This resets the user's password. You will see the new password once — share it securely."

<Warning>
  Setting or resetting a password this way signs the user out of every device, and you are told if those sessions could not be revoked. Their email address is also marked verified as a side effect.
</Warning>

The guardrails are worth knowing before you use it:

* The password is shown **once**, in a modal that wipes it after two minutes, when you switch tabs, or when you navigate away. After that you would have to reset again.
* The affected user is emailed a notice naming the administrator who made the change and the time — never the password. You are told explicitly if that email could not be delivered, since their mailbox is often the thing that is broken.
* The invited user is *advised*, but not forced, to change the password at first sign-in.
* Every set, reset and revoke is recorded in [Audit Logs](/manage/audit-logs) against the target user.
* You cannot reset your own password here — change it in [Profile Settings](#change-your-password) instead.
* Two accounts are refused outright, with the control greyed out and a tooltip explaining why: the seeded system administrator, whose password is managed by the deployment, and the Freshworks machine account, whose password is its integration API key.

<Note>
  **Pending Invitations** and the per-row password reset are available to partner-tier and SquawkVoice administrators. Account-tier administrators do not see them. A partner user needs both a partner and an account selected in the tenant switcher for the list to load.
</Note>

## User Profile Management

### Profile Settings

**Profile Settings** is where you manage your own name and password. To open it, select the round button with your initials at the right of the top bar and choose **Settings**. You can also press **Cmd/Ctrl+K** and type "Profile Settings": the **Ask AI about …** row at the top is highlighted by default, so arrow down to the **Profile Settings** action before you press Enter.

The **Profile** section at the top holds:

| Field         | What it's for                                                                                            |
| ------------- | -------------------------------------------------------------------------------------------------------- |
| **Email**     | The address you sign in with, shown for reference. Your email address cannot be changed.                 |
| **Full Name** | Your name. The initials on the top-bar button come from it, or from your email address while it's blank. |

**Save Changes** saves your name only, then closes the dialog. Your password is changed separately, in its own card below with its own button — see [Change Your Password](#change-your-password).

### Change Your Password

You can change your own password at any time without signing out.

1. Open **Profile Settings**: select your initials at the right of the top bar and choose **Settings**.
2. In the **Change Password** card, enter your **Current Password**.
3. Enter your new password in **New Password**, and again in **Confirm New Password**. The eye icon in each field shows what you've typed.
4. Select **Update Password**.

The new password must meet every rule listed under the fields, and each one ticks green as you meet it:

* **At least 8 characters**
* **Different from your current password**
* **New and confirm match**

**Update Password** stays disabled until every field is filled and every rule is met. The strength meter under **New Password** (weak, fair or strong) is a guide only: any password that meets the rules is accepted.

When the change goes through, you stay signed in on the device you're using, the dialog closes, and you see "Password updated. You are still signed in." If the dialog closes before you select **Update Password** — including when you select **Cancel** or **Save Changes** — whatever you typed in the password fields is discarded. A password you change here isn't recorded in [Audit Logs](/manage/audit-logs).

#### If You Sign In with Google

If you've only ever signed in with Google, the card is headed **Set a Password** instead. There's no current password to confirm, so Google confirms it's you. Once you've set a password you can sign in either with Google or with your email and password.

1. Enter the password in **New Password** and **Confirm New Password**. The rules are the same, except that there's no current password for it to differ from.
2. Select **Set Password**. A Google pop-up asks you to confirm your identity: choose the same Google account you sign in with.
3. When it's done, the dialog closes and you see "Password set. You can now sign in with Google or with your email and password." From then on the card shows **Change Password**, as it does for everyone else.

If your browser blocks the pop-up, you see "Your browser blocked the Google confirmation window. Allow pop-ups for this site and try again." Allow pop-ups for the Studio and select **Set Password** again. If you close the Google window without confirming, no password is set.

<Note>
  **Forgotten your password?** If you joined with an email and password, use **Forgot your password?** on the sign-in page — you can't change it in **Profile Settings** without your current password. If you added a password to a Google sign-in, you can still sign in with Google.
</Note>

### Account Settings

Configure user-specific account settings:

<Columns cols={2}>
  <Card title="Notification Preferences" icon="bell">
    * Email notification settings
    * SMS alert preferences
    * In-app notification controls
    * Alert frequency and timing
  </Card>

  <Card title="Security Settings" icon="lock">
    * Password requirements and policies
    * Multi-factor authentication setup
    * Session timeout preferences
    * Login history and monitoring
  </Card>

  <Card title="Language and Region" icon="globe">
    * Interface language preferences
    * Time zone and date format settings
    * Regional compliance settings
    * Localization preferences
  </Card>

  <Card title="Access Preferences" icon="settings">
    * Default dashboard views
    * Favorite and pinned items
    * Custom workspace layouts
    * Personalization settings
  </Card>
</Columns>

## Role Management

### Custom Roles

Create custom roles for specific business needs:

<ResponseField name="Role Name" type="string" required>
  Choose a descriptive name for the custom role (e.g., "Support Manager", "Sales Analyst").
</ResponseField>

<ResponseField name="Role Description" type="string">
  Provide a clear description of the role's purpose and responsibilities.
</ResponseField>

<ResponseField name="Permissions" type="multi-select" required>
  Select specific permissions that this role should have access to.
</ResponseField>

<ResponseField name="Account Scope" type="multi-select">
  Define which accounts this role can access and manage.
</ResponseField>

### Permission Granularity

Fine-tune permissions for precise access control:

<AccordionGroup>
  <Accordion title="Read Permissions">
    * View agents and configurations
    * Access analytics and reports
    * Read call history and transcripts
    * View user profiles and settings
  </Accordion>

  <Accordion title="Write Permissions">
    * Create and modify agents
    * Update knowledge base content
    * Configure platform settings
    * Manage user accounts
  </Accordion>

  <Accordion title="Delete Permissions">
    * Remove agents and configurations
    * Delete knowledge base items
    * Archive call history
    * Deactivate user accounts
  </Accordion>

  <Accordion title="Admin Permissions">
    * Manage billing and subscriptions
    * Configure security settings
    * Access system logs and audits
    * Override other user permissions
  </Accordion>
</AccordionGroup>

## User Activity Monitoring

### Activity Tracking

Monitor user activities and platform usage:

<ResponseField name="Login History" type="log">
  Track user login times, locations, and device information.
</ResponseField>

<ResponseField name="Action Logs" type="log">
  Record all user actions and changes made to the platform.
</ResponseField>

<ResponseField name="Session Analytics" type="metric">
  Monitor session duration, activity patterns, and feature usage.
</ResponseField>

<ResponseField name="Performance Metrics" type="metric">
  Track user productivity and platform utilization.
</ResponseField>

### Security Monitoring

Ensure platform security through comprehensive monitoring:

<Columns cols={2}>
  <Card title="Access Monitoring" icon="eye">
    * Track login attempts and failures
    * Monitor unusual access patterns
    * Detect potential security threats
    * Alert on suspicious activities
  </Card>

  <Card title="Data Access Logs" icon="database">
    * Record all data access and downloads
    * Track file and document access
    * Monitor API usage and calls
    * Log configuration changes
  </Card>

  <Card title="Permission Changes" icon="key">
    * Track role and permission modifications
    * Monitor user account changes
    * Log administrative actions
    * Audit trail for compliance
  </Card>

  <Card title="System Events" icon="activity">
    * Monitor system health and performance
    * Track integration and API events
    * Log error and warning messages
    * Alert on critical system issues
  </Card>
</Columns>

## Team Collaboration

### Team Organization

Organize users into teams for better collaboration:

<ResponseField name="Team Name" type="string" required>
  Create descriptive team names (e.g., "Customer Support", "Sales Team", "Technical Support").
</ResponseField>

<ResponseField name="Team Members" type="multi-select">
  Add users to teams for shared access and collaboration.
</ResponseField>

<ResponseField name="Team Permissions" type="object">
  Configure permissions that apply to all team members.
</ResponseField>

<ResponseField name="Team Resources" type="multi-select">
  Assign shared resources and workspaces to teams.
</ResponseField>

### Collaboration Features

Enable team collaboration and communication:

<Columns cols={2}>
  <Card title="Shared Workspaces" icon="folder">
    * Collaborative agent development
    * Shared knowledge base management
    * Team analytics and reporting
    * Common resource access
  </Card>

  <Card title="Communication Tools" icon="message-square">
    * Team chat and messaging
    * Notification and alert sharing
    * Comment and feedback systems
    * Collaborative documentation
  </Card>

  <Card title="Workflow Management" icon="workflow">
    * Task assignment and tracking
    * Approval workflows and processes
    * Status updates and progress tracking
    * Deadline management
  </Card>

  <Card title="Knowledge Sharing" icon="share">
    * Best practices documentation
    * Training materials and guides
    * Experience and insights sharing
    * Team learning and development
  </Card>
</Columns>

## Security and Compliance

### Access Control

Implement robust access control measures:

<Columns cols={2}>
  <Card title="Authentication" icon="lock">
    * Multi-factor authentication (MFA)
    * Single sign-on (SSO) integration
    * Password policies and complexity
    * Session management and timeout
  </Card>

  <Card title="Authorization" icon="shield">
    * Role-based access control (RBAC)
    * Permission inheritance and delegation
    * Resource-level access control
    * Dynamic permission assignment
  </Card>

  <Card title="Audit and Monitoring" icon="activity">
    * Comprehensive audit logging
    * Real-time activity monitoring
    * Security event detection
    * Compliance reporting
  </Card>

  <Card title="Data Protection" icon="database">
    * Data encryption and security
    * Privacy and confidentiality controls
    * Data retention and deletion policies
    * Regulatory compliance measures
  </Card>
</Columns>

### Compliance Features

Meet regulatory and industry requirements:

<AccordionGroup>
  <Accordion title="GDPR Compliance">
    * Data protection and privacy controls
    * Right to erasure and data portability
    * Consent management and transparency
    * Data processing agreements
  </Accordion>

  <Accordion title="SOC 2 Compliance">
    * Security, availability, and confidentiality
    * Regular security assessments and audits
    * Incident response and monitoring
    * Risk management and mitigation
  </Accordion>

  <Accordion title="Industry Standards">
    * ISO 27001 for information security
    * PCI DSS for payment processing
    * HIPAA for healthcare data
    * Industry-specific certifications
  </Accordion>

  <Accordion title="Internal Policies">
    * Company-specific security policies
    * Data handling and privacy guidelines
    * User conduct and acceptable use
    * Incident reporting and response
  </Accordion>
</AccordionGroup>

## User Lifecycle Management

### Onboarding Process

Streamline new user onboarding:

<Columns cols={2}>
  <Card title="Account Setup" icon="user-plus">
    * Automated account creation
    * Role assignment and permissions
    * Initial configuration and settings
    * Welcome materials and training
  </Card>

  <Card title="Training and Support" icon="graduation-cap">
    * Platform orientation and training
    * Role-specific skill development
    * Best practices and guidelines
    * Ongoing support and assistance
  </Card>

  <Card title="Access Provisioning" icon="key">
    * Resource and workspace access
    * Integration and API access
    * Tool and system permissions
    * Collaboration and team access
  </Card>

  <Card title="Performance Monitoring" icon="target">
    * Usage tracking and analytics
    * Performance assessment and feedback
    * Skill development and improvement
    * Success metrics and goals
  </Card>
</Columns>

### Offboarding Process

Ensure secure and complete user offboarding:

<ResponseField name="Access Revocation" type="process">
  Remove all platform access and permissions immediately upon departure.
</ResponseField>

<ResponseField name="Data Transfer" type="process">
  Transfer user's work and responsibilities to appropriate team members.
</ResponseField>

<ResponseField name="Account Cleanup" type="process">
  Archive or delete user account and associated data according to policies.
</ResponseField>

<ResponseField name="Compliance Verification" type="process">
  Ensure all compliance requirements are met during offboarding.
</ResponseField>

## Best Practices

### User Management

1. **Clear Role Definitions**: Define roles with specific responsibilities and permissions
2. **Principle of Least Privilege**: Grant only necessary access to users
3. **Regular Reviews**: Periodically review user access and permissions
4. **Documentation**: Maintain clear documentation of roles and responsibilities

### Security

1. **Strong Authentication**: Implement multi-factor authentication for all users
2. **Access Monitoring**: Regularly monitor user activities and access patterns
3. **Security Training**: Provide regular security awareness training
4. **Incident Response**: Have clear procedures for security incidents

### Collaboration

1. **Team Organization**: Organize users into logical teams and groups
2. **Communication**: Establish clear communication channels and protocols
3. **Knowledge Sharing**: Encourage sharing of best practices and insights
4. **Continuous Improvement**: Regularly assess and improve team effectiveness

## Troubleshooting

<AccordionGroup>
  <Accordion title="User access issues">
    * Verify user account status and permissions
    * Check role assignments and access levels
    * Review account settings and configurations
    * Contact support for access assistance
  </Accordion>

  <Accordion title="Permission problems">
    * Review role definitions and permissions
    * Check account and workspace access
    * Verify inheritance and delegation settings
    * Update permissions as needed
  </Accordion>

  <Accordion title="Authentication issues">
    * Check login credentials and password status
    * Verify multi-factor authentication setup
    * Review session timeout and security settings
    * Contact support for authentication assistance
  </Accordion>

  <Accordion title="Can't change your password">
    * **Update Password** stays disabled until every field is filled and every rule under the fields has a green tick
    * "Your current password is incorrect." means the **Current Password** didn't match. If you've forgotten it and joined with an email and password, use **Forgot your password?** on the sign-in page
    * "The new passwords do not match." means **New Password** and **Confirm New Password** differ
    * "Too many attempts. Please try again in a few minutes." means there have been too many tries in a short time. Wait, then try again
    * "Your session expired. Sign in again to change your password." means you need to sign out, sign back in, and try again
    * With **Set a Password**, allow pop-ups for the site if the Google window is blocked, and confirm with the same Google account you sign in with
  </Accordion>

  <Accordion title="Team collaboration problems">
    * Verify team membership and access
    * Check shared resource permissions
    * Review communication and notification settings
    * Ensure proper team organization and structure
  </Accordion>
</AccordionGroup>

## Next Steps

Now that you understand user management, explore these related topics:

<Columns cols={2}>
  <Card title="Account Management" icon="building" href="/manage/accounts">
    Learn how to manage multiple accounts and organizations
  </Card>

  <Card title="Settings Configuration" icon="settings" href="/manage/settings">
    Configure platform-wide settings and preferences
  </Card>

  <Card title="Voice Settings" icon="mic" href="/manage/voice-settings">
    Configure voice-related settings and preferences
  </Card>

  <Card title="Analytics Dashboard" icon="bar-chart" href="/analyze/dashboard">
    Monitor user activity and platform usage analytics
  </Card>
</Columns>
