Obsidian SuiteDocumentation
Obsidian Mail Server: all chapters

Docs / Obsidian Mail Server / People

Administrators and change history

Anyone with a user mailbox can be made an administrator. They sign in to this admin center at https://mail.example.com/admin with their normal email address and password; what they see and can change depends on their role.

The roles

RoleCan seeCan change
Global administratorEvery organization on the serverEverything, including organizations, domains, outgoing routes and the mail queue
Organization administratorTheir own organizationEverything inside it: users, groups, shared mailboxes, access, phones, administrators, compliance
Helpdesk administratorTheir own organizationOnly passwords and phones (block, erase); everything else is read-only
View-only administratorTheir own organizationNothing; for auditors and people learning the system
Discovery managerTheir own organization, plus anyone's mail through eDiscoveryeDiscovery cases, searches, exports and case holds; nothing else

Global and organization administrators can use eDiscovery too. Give the Discovery manager role to the people who handle legal cases, so reading other people's mail stays a deliberate, recorded act.

On a server with one organization, the difference between global and organization administrator is small: only global administrators can add domains and manage mail flow.

Make someone an administrator

Open Administrators, start typing the person's name, pick them, choose the role and select Grant. Or open the person's page under Users & groups and use Admin rights.

Nobody can grant a role higher than their own, and at least one global administrator must remain. Removing a role takes effect at the person's next click in the admin center.

Change history

Change history records every change made in the admin center or with the oms command: who did it, when, and to what. For example: [email protected] reset the password of [email protected]. The history cannot be edited or deleted from the admin center.

Changes made with the oms command on the server show the Linux account that ran it, for example cli:obsidian.

Recovering access

If every administrator has lost their password, sign in to the server's console or SSH as obsidian and reset one:

sudo oms password set [email protected]
sudo oms role add [email protected] GlobalAdmin

The first command asks for the new password without showing it.