# Users

This topic describes how to create and manage users and roles in Rebilly.

To effectively manage your team and the roles within it, [create roles](#create-roles) before you start adding users.

## Add a new user

Use this process to add a new user to your team and to assign permissions to them.

To complete this process, you must have the administrator role, or a role with [User permissions](/docs/settings/user-permissions#users).

1. In the left navigation bar, press **Settings**.
2. In the **Management** section, press **Users**.
3. In the right of the page, press **Add user**.
4. In the **User details** section, enter the user's details.
5. In the **User permissions** section, in the **Permission assignment** dropdown, select from the following:
Use this option to assign permissions to the user based on roles.
Use roles to manage permissions consistently for different user types within your organization.
For example, your organization may have a 'Customer service agent' role.
As new users are added to the customer service team, you assign the 'Customer service agent' role to them. 
When permissions are added or removed from the 'Customer service agent' role, the permissions for all users with that role are updated.
To assign permissions based on roles:
  1. Select **Use roles**.
  2. In the **User roles** dropdown, select one or more roles. 
To create roles, see [Create roles](#create-roles).
  3. Review **Selected permissions**. 
This section displays the combined permissions of the selected roles. 
You cannot edit this section.

Use this option with caution.
This option grants the user full access to create, edit, and delete data in your organization.
To grant administrator permissions to the user, select **Grant full access (Administrator)**.
Use this option to assign custom permissions to the user.
  1. Select **Set custom permissions**.
  2. Select from the following:
    1. Select one of the following presets:
      - **Full access**: Grants full edit and view permissions.
      - **Customer service agent**: Grants permissions for customers, invoices, and transactions.
      - **Settings manager**: Grants permissions for products, plans, gateways, and automations.
      - **Accountant**: Grants permissions for reports, billing data, and financial settings.
      - **KYC agent**: Grants permissions for KYC documents, tags, and custom fields.
    2. In the **Selected permissions** section, review the assigned permissions.
    3. Optionally, to change the assigned permissions: Expand a resource section and select or clear the checkbox beside a resource or permission.

    1. In the **Search permissions** field, enter a resource, action, or operation ID.
    2. Select or clear the checkbox beside a resource or permission.
6. Optionally, to restrict the user's access to your organization based on IP addresses: In the **Allowed IPs** field, enter permitted IP addresses. 
Enter one address per line.
This user also inherits any IP restrictions from the assigned roles. 
If you do not enter IP addresses, no IP restrictions are applied, unless restrictions are inherited from assigned roles.
7. Press **Save user**.


## Create roles

Use this process to create roles for the members in your team.

To complete this process, you must have the administrator role, or a role with [User permissions](/docs/settings/user-permissions#users).

Roles have a defined set of permissions that are used by a specific user group.
If permissions are added or removed from a role, the permissions list for all users with that role are updated.

1. In the left navigation bar, press **Settings**.
2. In the **Management** section, press **Users**.
3. In the right of the page, press **Roles**.
4. In the right of the page, press **Create role**.
5. In the **Name** field, enter a name for the role.
6. In the **Description** field, enter a description of the role.
7. Optionally, to add permissions from other roles: In the **Include roles** dropdown, select one or more roles.
8. In the **Permissions** section, select from the following:
  1. Select one of the following presets:
    - **Full access**: Grants full edit and view permissions.
    - **Customer service agent**: Grants permissions for customers, invoices, and transactions.
    - **Settings manager**: Grants permissions for products, plans, gateways, and automations.
    - **Accountant**: Grants permissions for reports, billing data, and financial settings.
    - **KYC agent**: Grants permissions for KYC documents, tags, and custom fields.
  2. In the **Selected permissions** section, review the assigned permissions.
  3. Optionally, to change the assigned permissions: Expand a resource section and select or clear the checkbox beside a resource or permission.

  1. In the **Search permissions** field, enter a resource, action, or operation ID.
  2. Select or clear the checkbox beside a resource or permission.
9. Optionally, to restrict access to your organization based on IP addresses: In the **Allowed IPs** field, enter permitted IP addresses. 
Enter one address per line.
This role inherits IP restrictions from roles you add in the **Include roles** field. 
If you do not enter IP addresses, no IP restrictions are applied, unless restrictions are inherited from included roles.
10. Press **Save role**.


## Edit user details

Use this process to edit a user's details.

To complete this process, you must have the administrator role, or a role with [User permissions](/docs/settings/user-permissions#users).

1. In the left navigation bar, press **Settings**.
2. In the **Management** section, press **Users**.
3. In the list of users, in the **Name** column, press a user.
4. In the **User details** section, edit the user's details.
5. Press **Save user**.


## Edit user permissions

Use this process to edit a user's permissions.

To complete this process, you must have the administrator role, or a role with [User permissions](/docs/settings/user-permissions#users).

If you change your own permission assignment from **Grant full access (Administrator)** to another option, you no longer have full access.
To restore full access, a user with full access must update the assignment.

1. In the left navigation bar, press **Settings**.
2. In the **Management** section, press **Users**.
3. In the list of users, in the **Name** column, press a user.
4. In the **User permissions** section, review the current selection in the **Permission assignment** dropdown.
5. Select from the following:
  1. If **Use roles** is not selected, select it.
  2. In the **User roles** dropdown, add or remove roles. 
To create roles, see [Create roles](#create-roles).
  3. Review **Selected permissions**. 
This section displays the combined permissions of the selected roles. 
You cannot edit this section.

Use this option with caution.
This option grants the user full access to create, edit, and delete data in your organization.
To replace the current permission assignment with administrator permissions, select **Grant full access (Administrator)**.
  1. If **Set custom permissions** is not selected, select it.
  2. Review **Selected permissions**. 
If the user already has custom permissions, this section displays the current selection.
  3. Optionally, to replace the selected permissions with a preset:
Selecting a preset replaces the currently selected permissions.
Select from the following:
    - **Full access**: Grants full edit and view permissions.
    - **Customer service agent**: Grants permissions for customers, invoices, and transactions.
    - **Settings manager**: Grants permissions for products, plans, gateways, and automations.
    - **Accountant**: Grants permissions for reports, billing data, and financial settings.
    - **KYC agent**: Grants permissions for KYC documents, tags, and custom fields.
  4. Add or remove permissions:
    - To find a permission: In the **Search permissions** field, enter a resource, action, or operation ID.
    - To add or remove a permission: Select or clear the checkbox beside a resource or permission.
6. Press **Save user**.


## Verify user account activation

Use this process to verify that a user activated their account. 
This process also describes how to resend an invitation to a user.

To complete this process, you must have the administrator role, or a role with [User permissions](/docs/settings/user-permissions#users).

1. In the left navigation bar, press **Settings**.
2. In the **Management** section, press **Users**.
3. In the user list, check the **Status** column. 
If the user has not activated their account, the status is `Pending confirmation`. 
To resend the invitation, on the right of the user, press **Resend confirmation email**.


## View users, delete users, or emulate a user's permissions

Use this process to view users, delete a user, or emulate a user's permissions.

To complete this process, you must have the administrator role, or a role with [User permissions](/docs/settings/user-permissions#users).

1. In the left navigation bar, press **Settings**.
2. In the **Management** section, press **Users**.
3. Select from the following:
In the user list, view all users.
To view details for a specific user, in the user list, in the **Name** column, press the user.
To filter the user list, in the top right of the page, press **Filter**, then select a filter.
On the right of the user, press **Delete**.
Use this feature to test a user's permissions, and to see which parts of the Rebilly product are available to them.
On the right of the user, press **Emulate permissions**. 
To stop emulating user permissions, at the top of the page, press **Stop emulation**.


## Export user data

Use this process to export user data to a CSV file.

To complete this process, you must have the administrator role, or a role with [User permissions](/docs/settings/user-permissions#users) and [Data exports permissions](/docs/settings/user-permissions#data-exports).

1. In the left navigation bar, press **Settings**.
2. In the **Management** section, press **Users**.
3.   1. In the top right of the page, press **Edit columns**.
  2. Add or remove columns, then press **Apply**.
4.   1. In the top right of the page, press **Edit columns**.
  2. Drag columns to arrange their order, then press **Apply**.
5. In the top right of the page, press **Export**, then press **Export as CSV**. 
When the report is generated, a notification is displayed in the top right of the page.
6. In the top right corner of the page, press **Alerts**, then press the file to download.


## Configure your user profile

Use this process to reset your password, switch between displaying customer names or customer organization names, change time zone, or to set up multi-factor authentication.

1. In the top right corner of the page, press your initials, then press your name.
2. Select from the following:
In the **Profile summary** section, press **Reset password**, then follow the instructions.
This option is available only for an account that signs in with a password.
An account that signs in with Google has no password.
In the **Theme** section, select **Light**, **Dark**, or **System** to match the theme of your device.
In the **Data tables report limit** section, in the **Results per page** dropdown, select a limit.
In the **Display name** section, select an option in the dropdown.
In the **Currency and time zone** section, press **Detect my time zone**.
Or, in the **Select time zone** dropdown, select a time zone.
In the **Currency and time zone** section, in the **Time format** dropdown, select a format.
In the **Multi Factor Authentication (MFA)** section, select from the following:
  - To set up MFA, press **Set up MFA**, then follow the instructions.
  - To replace your authenticator app, press **Change authenticator**, then follow the instructions.
  - To turn off MFA, press **Deactivate MFA**.

These options are available only for an account that signs in with a password.
An account that signs in with Google manages 2-step verification in the Google account.


## Multi-factor authentication (MFA)

MFA provides additional security during the sign-in process by requiring more than one form of identity verification to authenticate a user.
This involves the use of a smart device, such as a phone or tablet, and an authentication application, such as Google Authenticator, or Duo Security.
The user is required to use a password and an authentication code from the authentication application.
If a password is compromised, a malicious user would need the related authentication device, and access to the authentication application, to sign in.

Warning
If you enable MFA on your account but do not complete the setup using an authentication application, you will be locked out of your account.
If you cannot access your account, [contact Support](/contact/).

The use of MFA is optional in Rebilly, but highly recommended.
To enable MFA, see [Configure your user profile](#configure-your-user-profile).

## Change the theme

Use this process to change the theme of the Rebilly UI for your user account.
This option switches between light and dark mode.

There are two ways to change the theme.
Select from the following:

From any page
1. In the top right corner of the page, press your initials.
2. Press **Switch theme to light mode** or **Switch theme to dark mode**.


From user profile settings
1. In the top right corner of the page, press your initials, then press your name.
2. In the **Theme** section, select **Light**, **Dark**, or **System** to match the theme of your device.


## Related topics

- [User permissions](/docs/settings/user-permissions)
- [User management](/docs/tutorials/user-management)
- [API keys](/docs/dev-docs/api-keys)