# User Management

As a Client Admin, you can add, edit, and manage user accounts and their platform access.

## Key areas of the user profile

- **Overview** - The basic user profile information, such as personal details, location, and ID.
- **Group** - Will display the group that the user has been assigned to. It will be highlighted in blue.
  - **Admin** - Full platform access. Can view and edit all current and future engagements, manage scanners, integrations,
    agents, and credentials, and create or modify users.
  - **Global Read** - Read-only access to all current and future engagements. Cannot create, edit, or delete engagement
    content.
  - **Global Read / Write** - Full access to view and edit all current and future engagements. Does not include user
    management or platform administration.
  - **Custom** - Granular control over existing engagement access. No user management capabilities.
- **Engagements** - Will display the types of engagements that the user has access to and at what level of permission
based on the group assignment.
- **Orchestration** - Will list the scanners, integrations, and agents the user is able to add and modify. The user must
be a member of the Admin group.
- **MFA** - Used to manage a user's multi-factor authentication – either to require use of an MFA or not at each login.
- **API** - Allows users to create and manage API tokens. Use these tokens to synchronize vulnerability and asset data
between the NetSPI Platform and external tools or workflows, eliminating manual exports.

### Open a User Profile

To open a user profile, click **Settings > Admin > User Management > search for the user and click on the user's row**.

!!!
Use Search or Filter to quickly locate a specific user in your organization, or filter by first name, last name, or email.
!!!

### Add a User

To add a new user, follow these steps:

1. Click **Add User**.
2. Enter the **Personal Information** for the user, and then click **Next**.
3. Move the slider for **Multi-Factor Authentication** to require the user to verify their identity with MFA at each login.
4. Select the **Group** that the user should be a member of, and then click **Next**.
   - If **Group: Admin**, **Global Read** or **Global Read/Write** was selected, then you will skip ahead to the Review
   stage after clicking **Next**.
   - If **Group: Custom** was selected, then you will also select the **Engagements** and **Permissions** after clicking
   **Next**.
5. Select the **Engagements** the user should have access to if the Custom group was selected, and then click **Next**.
6. Select the **Engagement Permissions** to grant the user if the Custom group was selected, and then click **Next**.
7. Review the user details, and then click **Create User**.

### Edit a User

To open a user profile, click **Settings > Admin > User Management > search for the user and click on the user's row**.

!!!
Edits save automatically.
!!!

#### Change Group

Use the Group tab to update a user's group assignment. The user's current group is highlighted in blue, so you can quickly
confirm the existing setting before making a change.

1. Select the user whose group assignment you want to update.
2. Click the **Group** tab.
3. Select the new group for the user.
4. Click **Confirm** to save the change.

!!!
Changing a user's group may affect any engagements the user was actively working on when the change is made.
!!!

#### Change Engagements

To make granular changes to engagements, the user must be a member of the Custom group.

1. From the user's profile page, click the **Engagements** tab.
2. You can select to show a user's current **Access**, **No Access**, or **All**. Use **Search** to find a specific
engagement in the list.
3. Changes save automatically.

!!!
Selecting **Write** will automatically select **Read** permissions for an engagement.
!!!
