Docs / Obsidian Mail Server / People
Administrators and change history
Anyone with a user mailbox can be made an administrator. They sign in to this admin center at https://mail.example.com/admin with their normal email address and password; what they see and can change depends on their role.
The roles
| Role | Can see | Can change |
|---|---|---|
| Global administrator | Every organization on the server | Everything, including organizations, domains, outgoing routes and the mail queue |
| Organization administrator | Their own organization | Everything inside it: users, groups, shared mailboxes, access, phones, administrators, compliance |
| Helpdesk administrator | Their own organization | Only passwords and phones (block, erase); everything else is read-only |
| View-only administrator | Their own organization | Nothing; for auditors and people learning the system |
| Discovery manager | Their own organization, plus anyone's mail through eDiscovery | eDiscovery cases, searches, exports and case holds; nothing else |
Global and organization administrators can use eDiscovery too. Give the Discovery manager role to the people who handle legal cases, so reading other people's mail stays a deliberate, recorded act.
On a server with one organization, the difference between global and organization administrator is small: only global administrators can add domains and manage mail flow.
Make someone an administrator
Open Administrators, start typing the person's name, pick them, choose the role and select Grant. Or open the person's page under Users & groups and use Admin rights.
Nobody can grant a role higher than their own, and at least one global administrator must remain. Removing a role takes effect at the person's next click in the admin center.
Change history
Change history records every change made in the admin center or with the oms command: who did it, when, and to what. For example: [email protected] reset the password of [email protected]. The history cannot be edited or deleted from the admin center.
Changes made with the oms command on the server show the Linux account that ran it, for example cli:obsidian.
Recovering access
If every administrator has lost their password, sign in to the server's console or SSH as obsidian and reset one:
sudo oms password set [email protected]
sudo oms role add [email protected] GlobalAdmin
The first command asks for the new password without showing it.