Account Management covers platform users, roles, account status, subscription or balance, security actions.

Entry Point#

Open Accounts in the admin console to manage the user list, profiles, permissions, billing state, and security actions. Sign-in methods, registration policy, email verification, identity providers, and login security have moved to Login & Auth.

Only administrator accounts can access the admin console. High-risk changes such as super administrator protection, last-super-admin protection, and identity provider default roles are guarded by permission checks and safety rules.

User List#

The user list supports searching username, display name, email, and Public ID. It can be filtered by role, status, and subscription status, and sorted by newest ID, last login, last update, or display name.

Rows show account information, role, status, subscription or balance, timezone, and last login time. The billing fields change with billing mode: period billing focuses on subscription plan and expiry, while usage billing focuses on account balance.

Create and Edit Users#

Use Create to add a normal user account with username, display name, password, email, phone, language, timezone, and preferences. Passwords must satisfy the platform policy.

The user editor is organized into profile, access and region, billing, security, and system information. Administrators can adjust role, status, profile fields, language, timezone, preferences, and billing fields available in the current billing mode.

When changing account status, add a reason when possible so later audits are easier. Suspend, deactivate, and delete actions affect sign-in and access, so confirm the business impact first.

Bulk Actions#

The list supports selecting multiple users and applying role, status, timezone, balance, or deletion changes in bulk. Bulk actions show a confirmation dialog and are useful for organization migration, temporary blocks, billing initialization, and cleanup.

Before bulk changes, narrow the list with filters and verify the selected users. Deletion is permanent; prefer suspend or deactivate unless the account data truly should be removed.

Security Actions#

The user details menu includes reset password, reset two-factor authentication, and revoke sessions.

ActionPurpose
Reset passwordSet a new password for the user.
Reset two-factor authenticationClear the user's two-factor setup and revoke active sessions, useful when an authenticator is lost.
Revoke sessionsInvalidate signed-in devices for the user, useful for suspected exposure or offboarding.

These actions affect the user's sign-in state. Confirm the user's identity and request source before acting, then tell the user to sign in again and complete any required security setup.

Practical Tips#

Configure at least two reliable administrator sign-in paths before opening registration or third-party sign-in. Prefer suspend, deactivate, and revoke sessions for routine account control; delete only when retention is no longer needed. After changing auth policy, verify that an administrator can still sign in.