Users, roles, and access
Manage who can sign in and what they can see and change — administrator and standard roles, and job-scoped access control on higher plans.
Last updated July 17, 2026
#User management overview
Users are managed under Settings → User Management. Each plan includes a number of user accounts, and shared team administration — multiple people managing the same FileAgent — is available on Team plans and above. The Free and Pro plans are single-user. See the pricing page for the per-plan user counts.
#Roles
- Administrators manage everything: jobs, credentials, users, alerts, system configuration, licensing, and updates.
- Standard (read-oriented) users can see job status and logs without changing job definitions, credentials, or system settings.
Give day-to-day operators the minimum role that lets them do their work, and reserve administrator access for the people who own the system. Roles are available on Team plans and above (single-user plans have one administrator).
#Job-scoped access (RBAC)
On Business Premium and Enterprise, role-based access control extends to the job level: you can scope which jobs — and which archive folders — a user can see and act on. This lets multiple departments share one FileAgent installation without seeing each other's workflows; finance sees finance jobs, operations sees operations jobs.
#Directory and single sign-on
On Business Premium and Enterprise, users can sign in with your identity provider or directory instead of separate local passwords, via SAML 2.0 SSO or LDAP. This lets your joiner/mover/leaver process govern FileAgent access.
#Best practices
- One account per person. Never share logins — the audit value of logs depends on knowing who did what.
- Standard role for stakeholders who just need to see status.
- Review the user list when people change roles or leave, and deactivate promptly.
- Prefer SSO or LDAP where available so directory policy enforces sign-in.
- Set a session timeout that matches your data's sensitivity.