Skip to content

Users and roles ​

Goal ​

Invite teammates, assign roles, tune invite/session/MFA readiness policies, create roles with the guided wizard, and edit the permission matrix for custom roles.

Who it is for ​

PermissionCapability
member.viewMembers list and role dropdown data
member.manageAdd member, change role, remove
member.adminMembers setup (Options, Advanced catalogs) and the permission catalogue for those forms
role.viewLoad roles / permission catalogue for the matrix
role.manageOpen Members setup, read job/capability catalogs, and create/edit/delete custom roles (wizard or matrix)

Members is a core module (always on).

Preconditions ​

  • Signed in to the correct workspace.
  • At least one role exists to assign on invite (system or custom).
  • Optional modules still require matching permissions after entitlements are granted.

Members list ​

  1. Open Administration → Organization → Members (/members) — Invite teammates and assign roles for this workspace.
  2. Review columns Name, Email, Role.
  3. Add member: enter Name, Email, Role → invite creates the user if new (email with set-password link; expiry follows invite policy) or attaches an existing BlueMatrix user when allowed.
  4. Use Change role or Remove on a row (member.manage).

Members setup ​

  1. Open Members setup (/members/setup) — needs member.admin.
  2. Work the side tabs:

Options ​

  • Invites: Invite link expiry (days, 1–90); Allow inviting users who already have a BlueMatrix account.
  • MFA & SSO readiness: MFA policy (Optional / Required for admins / Required for all members); SSO enforcement (Optional / Preferred / Required); Allow password login when SSO is preferred/required. These store readiness until live MFA/IdP ships — they do not connect an identity provider yet.
  • Sessions: Idle timeout (minutes), Absolute session lifetime (hours), Max concurrent sessions per member.
  • Sensitive actions: Require an audited reason for sensitive tenant setting changes (feeds Tenant settings hard stops).

Create role ​

Guided path for standard admins (role.manage): pick a job, toggle capability packs, name the role, optionally adjust individual permissions. The server composes and validates the final set (POST /members/roles/compose). After create, the permission matrix opens on the new role.

Permission matrix ​

Use guided create, or Add role for a blank custom role. Select a role and toggle permissions. System roles are view-only.

Advanced ​

Curate job templates and capability packs (not day-to-day role creation). Use in Create role opens the wizard with that job selected. Add / edit / deactivate non-system catalog rows. Choose permissions from the searchable catalogue.

Result ​

Membership and RBAC for the workspace reflect invites and matrix changes. Session middleware may force re-sign-in when idle/absolute limits are exceeded.

Hard stops ​

  • Inviting users who already have a BlueMatrix account is disabled for this workspace.
  • This user is already a member of this tenant.
  • System roles cannot be edited or deleted. Clone a template or create a custom role instead.
  • You cannot edit or delete the role assigned to your own membership.
  • This role is assigned to one or more members and cannot be deleted.
  • A role with this name already exists.
  • System role templates cannot be deleted. / System permission packs cannot be deleted.
  • This role template is inactive. / This permission pack is inactive.
  • This role template was not found. / A selected permission pack was not found.
  • Your session has expired. Please sign in again.

BlueMatrix Help — product documentation for tenants