Platform Users
Platform Users lists and manages the accounts that have platform-level access to your Ascent instance — the operators who administer Ascent across organizations. This is separate from the technicians and contacts managed inside each organization.
Overview
The Platform Users page lets you:
- View every user that holds a platform role, with their linked organization memberships
- Search by name or email and filter by platform role
- Create new platform users with a temporary password
- Change a user's platform role
- Edit a user's display name
- Reset a user's password or MFA
- View and revoke a user's active sessions, or terminate all of them at once
- Deactivate, reactivate, or permanently delete a platform user
Scope: This page only shows users that have a platform role (Platform Admin, Platform Support, or Platform Billing). Regular organization members and client portal contacts are not listed here — they are managed inside each organization.
Navigate to Platform Users
In the Platform admin area, select Users in the sidebar. The page is only reachable by users with the Platform Admin or Platform Support role; everyone else sees an Access Denied message.
Most management actions (create, edit, role change, password/MFA reset, session termination, deactivate, delete) are restricted to Platform Admin. Platform Support users can view the list, open user details, and view active sessions, but cannot make changes.
Platform roles
| Role | Description |
|---|---|
| Platform Admin | Full access to the platform administration area, including all user-management actions on this page. |
| Platform Support | Read-only access to platform users and their sessions, intended for support and incident triage. |
| Platform Billing | Platform role focused on billing; appears in the list and filters. |
A platform user can also have No Platform Role (when you clear their role), which removes their access to the platform administration area.
The users list
The table shows one row per platform user with these columns:
| Column | Details |
|---|---|
| User | Avatar with initials, display name (or email if no name), email address. An Inactive badge appears for deactivated accounts, and a shield icon indicates the user has MFA enabled. |
| Platform Role | The user's platform role badge, or - if none. |
| Organizations | The organizations the linked org account belongs to, each with its role. Shows the first two, then a "+N more" indicator. |
| Last Login | The user's last login date, or Never. |
| Actions | A menu (⋯) of per-user actions. |
Searching and filtering
- Search by name or email — type in the search box to filter the list.
- Filter by platform role — choose All Platform Roles, Platform Admins, Platform Support, or Platform Billing.
The list is paginated at 20 users per page; use Previous / Next to move between pages.
Creating a platform user
Platform Admins can add a new platform user:
-
Click Create User (top right).
-
Fill in the form:
Field Notes Email Email address for the new user. Must not already belong to a platform user. Name The user's full name. Platform Role One of Platform Admin, Platform Support, or Platform Billing (defaults to Platform Support). Temporary Password At least 8 characters. The user should change it after first login. -
Click Create User.
If an organization user already exists with the same email, the new platform account is automatically linked to it (dual identity).
You can also click Configure SSO from the header to open the platform SSO configuration page.
Per-user actions
Open the actions menu (⋯) on any row. View Details is always available; the remaining actions require the Platform Admin role.
| Action | What it does |
|---|---|
| View Details | Opens the user detail dialog (see below). |
| Edit Name | Updates the user's display name. |
| Change Platform Role | Sets the role to Platform Admin, Platform Support, Platform Billing, or No Platform Role. You cannot remove your own Platform Admin role. |
| Reset Password | Generates a new temporary password and invalidates all of the user's existing sessions. |
| Reset MFA | Disables MFA for the user and invalidates their sessions. Only available when the user has MFA enabled. |
| Terminate Sessions | Logs the user out of every active platform session. Only available when the user has active sessions. |
| Deactivate User / Reactivate User | Deactivating prevents sign-in and ends current sessions (reversible); reactivating restores access. |
| Delete User | Permanently removes the platform user. |
Actions that target your own account are disabled — you cannot reset, terminate, deactivate, or delete yourself from this panel. The platform also blocks deleting the last active Platform Admin so the instance always has at least one administrator. Deleting a platform user does not affect its linked organization account.
Reset Password
When you reset a password, Ascent generates a secure temporary password and displays it once. Copy it with the copy button and share it securely — it will not be shown again. All of the user's existing sessions are invalidated at the same time.
Reset MFA
Resetting MFA disables the user's MFA methods and invalidates their sessions. The user can re-enroll in MFA on their next login if it is required.
User detail dialog
Selecting View Details opens a dialog with:
- Profile — avatar, name, email, and platform role badge.
- Created and Last Login dates.
- Organizations — each linked organization membership with its role.
- Active Sessions — a list of the user's current sessions showing device name, browser (user agent), IP address, and start/expiry timestamps. Sessions that are operating in an org "View As" context are marked with a View As Org badge.
From the detail dialog, Platform Admins can revoke an individual session or use Terminate all to end every session for that user at once.
Tips
- Use Reset Password and Reset MFA for support cases when a platform administrator is locked out.
- Prefer Deactivate User over Delete User when offboarding — deactivation is reversible and immediately ends active sessions.
- Review the Active Sessions list during incident triage; Platform Support can view sessions even though they cannot revoke them.
- All of these actions are recorded in the platform audit log — see Audit for the full history of administrative actions.
For an overview of the platform administration area, see Platform Overview.