The user page
The user page gathers everything about one account: the profile, the link to the person record, the roles, and the permissions.
Roles and grants
Link to this headingThe account has one primary role and can have additional roles. Beyond the roles, individual permissions can be granted directly — scoped to a production or group, with an optional expiry date. The effective permissions panel shows the sum of it all: roles, grants, and inherited rights, with the source per permission.
Account status
Link to this heading- Disable account — stops sign-in with a reason; sessions are revoked. You can’t disable your own.
- Account expiry — a date where the account switches itself off; a blank field means no expiry. Expiries are flagged in the user list ahead of time.
Sign-in and two-factor
Link to this heading- Send link — a one-time link where the user sets a new password themselves. runorder has no password fields for administrators.
- Reset two-factor — clears the authenticator and backup codes via the sign-in service; the user re-enrolls at runorder.app → Settings → Security.