Docs / Obsidian Suite / For administrators
Users and roles
Manage > Users lists everyone in your organization who can sign in or receive a quarantine: synced mailbox users and your organization administrators.
Roles
| Role | Can do |
|---|---|
| User | Their own quarantine, recent mail, personal allow and block lists and account security, in the user portal. No admin console. |
| Organization administrator | The admin console for your organization. Administrators also have their own quarantine and lists under My mail. |
Platform settings, service health and API tokens are run by Larström Technologies and are not part of your console.
Finding users
Search by address or name, and filter by role. The list shows VIP and disabled badges, the number of aliases, the sign-in method (local, m365, google, ldap, "+ MFA" when two-factor is on) and the last sign-in.
Add user
Mailbox users normally arrive through user sync rather than being added by hand. To add someone yourself, use Add user:
| Field | Meaning |
|---|---|
| Sign-in name and primary address. | |
| Name | Display name. It matters for VIP protection. |
| Role | User - own quarantine or Organization administrator. |
| Password (optional) | At least 12 characters. Leave it blank for people who sign in with Microsoft or Google, with their Windows password (Exchange), or with emailed sign-in links. |
Click Create.
Editing a user
Click a user to open their page. Their messages opens Message trace for their mail.
| Field | Meaning |
|---|---|
| Display name | Shown in the console and used for impersonation checks. |
| Role | You cannot change your own role. |
| Aliases | Other addresses delivered to this mailbox, comma separated. Mail to an alias shows in this user's quarantine and counts for recipient checks. User sync fills these in from your directory. |
| Active | Inactive users cannot sign in and get no digests. You cannot deactivate yourself. |
| VIP (executive impersonation protection) | See VIP users. |
| Send quarantine digests | Whether this person receives quarantine digests. Users can change this themselves too. |
| Set new password | Resets the password. The user's existing sessions end. |
| Reset two-factor (user re-enrolls) | Shown when two-factor is on. Removes their authenticator so they can set it up again, for example after losing a phone. |
Save applies the changes and also clears a lockout after repeated failed sign-ins. Every change is written to the audit log.
The Personal allow & block entries card lists the user's own list entries; Remove deletes one.
VIP users
Mark executives, finance and HR approvers as VIP. Outside mail that uses a VIP's display name gets the rule VIP_DISPLAY_NAME (+6 points) and is always shown to the AI model (unless a policy turns that off). This is the most common business email compromise trick: a stranger's address with your CEO's name.
Two-factor sign-in
Every user can turn on two-factor sign-in with an authenticator app under Account & security; see User portal. We recommend it for every administrator. For people who sign in with Continue with Microsoft or Continue with Google, enforce two-factor in Microsoft Entra ID or Google Workspace.
After several wrong passwords in a row, an account is locked for a few minutes. Saving the user's record unlocks it at once.