Overview
The Users & Agents section lets you manage user accounts in your Ender Turing organization. From here you can invite new users, assign roles, link users to agents, manage passwords, and control account status.
Each user account has an email, a name, one or more roles, and an optional link to an agent profile. Roles determine what a user can see and do across the platform.
How It Works
Accessing User Management
Open Settings from the main navigation.
Select Users & Agents.
The Manage Users tab opens by default.
The Users & Agents section contains three tabs:
Manage Users — create, edit, and manage user accounts
Agents — manage agent profiles and teams
Manage Roles & Permissions — configure custom roles
To access the Manage Users tab, your role must include the Manage Users permission.
User List
The user list shows all accounts in your organization, including active, disabled, and invited users. Each row displays:
Email
Full Name
Status — Active, Disabled, Invited, or Invitation Expired
Roles — the assigned role names (superusers display as "System User")
Last Activity — how recently the user logged in, or "Never logged in"
You can search by email or name, and filter by status using the toggle buttons at the top: Active, Invited, and Disabled.
User Statuses
Status | Meaning |
Active | Account is enabled and the user can log in |
Disabled | Account is deactivated; the user cannot log in |
Invited | An invitation was sent and is waiting for the user to accept |
Invitation Expired | The invitation acceptance deadline has passed |
Creating a User
On the Manage Users tab, click Invite User.
Fill in the required fields:
Full Name
Email (must be unique across the organization)
Roles (select one or more)
Optionally, link the user to an Agent profile or assign them to one or more Teams.
Choose how to set the password:
Send Invitation Email (default) — the user receives an email with an activation link and sets their own password. Click Save & Invite.
Enter Password Directly — you set the password immediately and the user can log in right away without needing an email. Click Save & Set password.
Optionally, mark the account as a System/Technical User if it is intended for API integrations or automated processes. System users are excluded from business-related selections such as dispute assignment and training plans.
Invitation Workflow
When you choose Send Invitation Email:
The system sends an email with a unique activation link.
The user clicks the link and sets their own password.
Once the password is set, the account status changes from Invited to Active.
If the invitation expires before the user accepts it, the status changes to Invitation Expired. You can resend the invitation from the user's edit page.
Editing a User
Click the pencil icon on any user row to open the edit page.
You can change:
Full Name
Email
Roles
Linked Agent
Teams
Active/Disabled status
System/Technical User flag
From the edit page, you also have access to these actions:
Resend Invite — appears when the user's status is Invited or Invitation Expired. Sends a new activation email.
Logout from All Devices — immediately ends all active sessions for the user, requiring them to log in again.
If the account is connected to a federated identity provider (OIDC) — for example, because the user signed in through your single sign-on provider — an OIDC linked badge appears below the last login row. The badge is informational; the account itself behaves like any other Ender Turing user.
Managing Passwords
To change a user's password, click the key icon on the user row. Two options are available:
Autogenerate — the system generates a random password. You can reveal it, copy it, and share it securely with the user. The password cannot be retrieved later.
Manual — enter a specific password and confirm it.
Password requirements: at least 8 characters, including one lowercase letter, one uppercase letter, and one digit.
Agent and Team Linking
A user can be linked to one Agent profile. When an agent is selected, the user is automatically assigned to the agent's current team.
If no agent is linked, you can manually assign the user to one or more Teams.
Agent and team assignment are mutually exclusive: selecting an agent disables the teams field, and vice versa.
Some roles may require an agent or team link to function correctly. Ensure the appropriate link is set when assigning such roles.
Access and Permissions
Action | Who can do it |
View the Manage Users tab | Users with the Manage Users permission |
Create a new user | Users with the Manage Users permission |
Edit a user | Users with the Manage Users permission |
Create or modify a superuser account | Superusers only |
Grant superuser status to a user | Superusers only |
Send or resend an invitation | Users with the Manage Users permission |
Reset a user's password | Users with the Manage Users permission |
Logout a user from all devices | Users with the Manage Users permission, or the user themselves |
Superuser accounts are a special tier with full system access. Only existing superusers can create new superuser accounts or modify other superuser accounts. Regular administrators cannot grant or revoke superuser status.
Important Notes
Each email address can only be used for one account.
The built-in system user (ID 0) cannot be modified.
Disabled users cannot receive invitations. Reactivate the account first if you need to resend an invite.
When your organization uses single sign-on (OIDC), user creation and invitations may be handled by the identity provider instead of the built-in workflow.
