Skip to content

Managing users

The Users page lists the people who can use RebelCore for your organisation. It is available to the Customer Super Admin and users with Add Users permission.

The Customer Super Admin is marked OWNER. This account is created during provisioning and cannot be edited or deleted from the Users page.

Invite a user

  1. Open Users under Accountability.
  2. Click the + button.
  3. Enter the user’s first name, last name, and email address.
  4. Choose a Role.
  5. Confirm the account status.
  6. Click Create.

RebelCore emails the user a single-use invitation to set their own password. The invitation is valid for 24 hours. The user then completes the sign-in and two-factor authentication flow appropriate to their account.

Edit a user

Select a non-owner user to open the user blade. You can update:

  • First and last name.
  • Email address.
  • Assigned role.
  • Account status.

Save the changes and ask the user to refresh RebelCore if they already have it open. Updated access is applied without requiring a new invitation.

Resend an invitation

Use RESEND INVITE when the original invitation expired, was lost, or should no longer be trusted. RebelCore sends a new invitation and invalidates earlier unused invitation links.

Users who have already completed registration should normally use Forgot password? on the sign-in page. See Signing in for the recovery flow.

Reset two-factor authentication

If a portal user loses both their authenticator and backup codes:

  1. Open the user’s blade.
  2. Choose the two-factor reset action.
  3. Confirm the reset.

The user will enrol an authenticator again at their next portal sign-in. Agent-only users receive a one-time code by email and do not enrol a portal authenticator.

Clear a lockout

Repeated failed sign-in attempts temporarily lock an account. The user blade displays the lockout state and, where permitted, lets the Customer Super Admin clear it immediately. Otherwise, the user can wait for the lockout period to end.

Delete a user

Use Delete on a non-owner account when the person should no longer have access. Deletion is permanent and removes the user’s ability to sign in.

Before deleting an account:

  • Confirm that the user no longer requires access.
  • Reassign any work or project responsibilities.
  • Preserve any activity exports required by your retention policy.

For temporary access changes, set the account to an inactive status instead.

Agent-only users

Assign the RebelCore_AgentUser role when a person should use only RebelCore Agent. Agent-only users:

  • Sign in through the normal RebelCore sign-in page.
  • Verify with a code sent to their email.
  • Go directly to Agent after verification.
  • Do not receive portal navigation.

See Login & access workflows for the complete account flow.