User Management in Secryn allows administrators to control who can access the system and define what they are allowed to do. Access is governed by project-level roles and optional restricted vault rules.
User Management is available to Admins only.
In Secryn:
To add a new user:
The user receives an email with a secure link.
Upon first login, the user:
Until the invitation is accepted, the user remains in a pending state.
Secryn includes four predefined roles:
Roles define what a user can do within projects and vaults.
Role capabilities are enforced consistently across:
For a full breakdown of permissions, see the RBAC section.
Users must be assigned to projects to access vaults and resources.
Within a project:
If a user is not assigned to a project, they cannot see it.
If a vault is marked as Restricted:
Restricted vaults override default project-level access.
Admins can:
Users can:
Users cannot:
Disabling a user:
Disabling is preferred over deletion to maintain audit integrity.
Users can enable or disable email notifications.
If disabled:
All user actions are:
Access is never implicitly granted.
User management in Secryn follows these principles: