CoreLayer AI Security logoCoreLayer AI Security

Managing users

Organisation admins invite people, assign roles, and remove access. Everything on this page lives under Users in the admin navigation.

Admin only

Only the Organisation Admin role can manage users. If Users is not in your navigation, you do not have the role. Ask your admin.

Inviting someone

  1. Open Users and choose Invite user.
  2. Enter their email address.
  3. Pick a role. See Roles & permissions if you are unsure.
  4. Send. They receive an email invitation.

The person appears immediately with status Invited. Once they accept and sign in, it becomes Active.

If the invitation does not arrive

  • Check spam and quarantine. Invitations come from the platform, not from your domain.
  • Confirm the address is spelled correctly. An invitation to a mistyped address will never be accepted; delete it and re-invite.
  • Repeated bounces to the same address can cause a mail provider to suppress it. Try a different address, or contact support.

Account statuses

StatusMeaningCan they sign in?
InvitedInvitation sent, not yet accepted.Not until they accept.
ActiveAccepted and in use.Yes.
SuspendedAccess paused by an admin. The account and its history remain.No.

Changing a role

Open the user and pick a new role. The change is written to your identity provider first, so the dashboard and the CLI agree. There is no window where the two disagree about what someone can do.

It takes effect at their next sign-in. Someone currently signed in keeps their existing session until it expires or they sign out.

Suspending versus removing

SuspendRemove
Signs inNoNo
Account retainedYesNo
ReversibleYes. Reactivate at any timeNo. You must re-invite
Use it whenSomeone is on leave, or you are investigating.Someone has left the organisation for good.

Suspending

Open the user and choose Suspend. Access stops immediately; their history and attributed findings stay intact. Reactivate whenever you want.

Removing

Choose Remove. This deletes the membership from the organisation and from your identity provider. They lose dashboard and CLI access. Work they produced (scans, findings, reports) stays; the audit trail is not rewritten.

Removal cannot be undone

Bringing someone back means a fresh invitation and a new membership. If there is any chance they are returning, suspend instead.

You cannot remove yourself

An admin cannot remove their own account. This stops an organisation from being locked out with no remaining administrator. To hand over, invite the incoming admin, confirm they are Active, and have them remove you.

Offboarding checklist

Removing the account is not the whole job. CLI tokens are issued separately.

  1. Remove or suspend the user under Users.
  2. Revoke their CLI tokens under CLI access. A token keeps working on its own scope.
  3. Rotate any shared CI token they had access to.
  4. Reassign the models and projects they owned, so findings do not sit unattended. See Models & projects.
  5. Confirm the removal appears in Audit Logs.

Audit

Invitations, role changes, suspensions, and removals are all recorded under Audit Logs, with who did it and when.

Where the first admin comes from

When CoreLayer provisions your organisation, one admin email is created with it. That person invites everyone else. There is no self-service sign-up, so every account traces back to a deliberate invitation, which is why secureai login can rely on the same identity.