2. Prepare your organisation
Manage your users
Learn how to add, update, and remove the people who sign in to LambdaAssetCheck, so everyone keeps the access their job needs and nothing more.
Last updated: August 2026
In this article
What you'll need
| Tier | Any plan. Users are unlimited on every tier. |
| Platform | Web app |
| Permission | The Users platform-management capability. Owner and Administrator have it by default. |
| Where | Administration → Users / Groups / Sites → Users |
User tasks
Everything you can do to a user, and where to do it. Each task starts from Administration → Users / Groups / Sites → Users.
| Task | What it does |
|---|---|
| Add a user | Create the account and send the invite email. |
| Assign roles | Set what the person can do. |
| Assign groups | Put the person on a team, for assignment and template scoping. |
| Assign sites | Give the person access to the locations they work at. |
| Deactivate a user | Remove access without deleting history. |
| Reset MFA | Clear two-step verification when someone is locked out. |
Assign roles
Roles set what a person can do. A user can hold more than one.
- Find the user and open Actions.
- Select Manage roles.
- Check the roles that match their job, then save.
Follow least privilege — grant the minimum access the job needs.
Assign groups
Groups put a person on a team, for work assignment, template scoping, and rounds.
- Find the user and open Actions.
- Select Add to groups.
- Check the groups to add them to, then select Add.
Assign sites
Sites give a person access to the locations they work at.
- Find the user and open Actions.
- Select Manage sites.
- Check the sites to assign, then save.
You can also assign sites while adding the user. What the person actually sees combines this assignment with their role's Site data access. Groups cannot be assigned a site, and group membership does not inherit site access.
For roles limited to assigned sites, give the person at least one site or they will see no operational data.
Deactivate a user
Use this when someone no longer needs access. History is preserved.
- Find the user and open Actions.
- Select Deactivate.
- Confirm with Deactivate.
Their status changes to Inactive, and Deactivate becomes Activate so you can restore access later.
Reset MFA
Use this when someone cannot complete two-step verification — for example they lost the phone holding the authenticator and they have no recovery codes left.
- Find the user and open Actions.
- Select Reset MFA.
- Confirm in the dialog.
LambdaAssetCheck clears that user's authenticator, their remaining recovery codes, and any in-progress verification session.
What the user does next
| Their role / org policy | What they do at next sign-in |
|---|---|
| Owners, Administrators, Admin-designated roles, or org requires MFA for all | Sign in with email and password, then complete Set up authenticator MFA — scan the QR code, confirm a 6-digit code, and save the new recovery codes. See Two-step verification (MFA). |
| Everyone else (MFA not required org-wide) | Sign in with email and password only. MFA is not available to turn on from My account. |
You cannot reset MFA on your own account from this list. Another owner or administrator must do it. SSO sign-in is unaffected — Reset MFA only touches the password path.
Good habits
- Review regularly. Check roles, groups, and site assignments periodically, and update them when people change department or location.
- Document changes. Note why a user holds a role or group. It keeps access auditable.
- Remove access promptly. Deactivate people who have left, so access stays tight.
Related articles
Previous article: Groups
Next article: Inspection loop overview →
Was this page helpful?
