Users

Creating and managing users

This article covers the administration of user accounts: creating them, assigning roles, sending and troubleshooting invitations, resetting passwords, and removing people when they leave. A user cannot log in until they have been invited, which is the step most often missed.

Creating a new user

Adding new team members to Tidal Control happens through a simple process where you can directly assign the appropriate role.

User addition steps

  1. Go to Settings → Users in the left navigation
  2. Click "Add User" button at the top right of the Users page
  3. Fill in user information in the creation form
  4. Select appropriate role for the new user
  5. Click "Create" to add user

Add User dialog

Filling in user information

Name, email, and role are all required to create a user.

Required fields:

FieldExplanation
First NameFirst name
Last nameLast name
EmailBusiness email address
Role
  • Regular User - Default choice for most team members
  • Read Only User - For users who only need access
  • Basic User - For employees who only report incidents and read shared documents
  • Super User - For administrators with full rights
Invite to Tidal Control after creationSend invitation email directly to user
Planning tip

You can create users and assign them to compliance objects before inviting them. This allows you to set up the entire system in preparation for team onboarding.

Assigning and changing roles

After creating users, you can easily adjust roles via the Role dropdown in the user table.

Role change process

  1. Go to the Users overview page
  2. Find the desired user in the table
  3. Click on Role dropdown in the user row
  4. Select new role from available options
  5. Change is saved immediately without confirmation

Role dropdown change

Warning

Security consideration: Granting Super User rights means full system access. Only assign this role to trusted administrators.

Inviting users

If you haven't invited users to Tidal when creating them, you need to do this later before login is possible. The invitation enables account activation and password setup.

Invitation process

  1. Go to Users overview page
  2. Find the new user in the table
  3. Click Manage menu (chevron-down button) in the user row
  4. Select "Send invite" from the dropdown menu
  5. Invitation is sent immediately to user email

Actions menu with Send invite

What happens after invitation?

The invitation email carries the activation link, and it expires after 7 days.

User receives email with:

  • Welcome message with introduction to Tidal Control
  • Password setup link via Keycloak interface
Info

Invitations are valid for 7 days.

If the user hasn't activated their account within this period, a new invitation must be sent.

Invitation troubleshooting

Most missing invitations turn out to be a spam filter or a typo in the email address.

Invitation not received:

  • Check spam folder of user email
  • Verify email address for typos in Users table
  • Resend invitation via Manage menu
  • Contact IT support for email delivery problems

User management tasks

The Manage menu provides various management options for existing users, from password help to account deletion.

Resetting password

Reset a password when the user forgot theirs, it may be compromised, or an activation email never arrived.

When to use:

  • User forgot password
  • Suspected password compromise
  • New user didn't receive activation email

Reset process:

  1. Go to Users overview page
  2. Click Manage menu of relevant user
  3. Select "Reset password" from dropdown
  4. Confirm action in popup dialog
  5. User receives reset email with instructions

What the user receives:

  • Password reset email with secure reset link

Deleting user

Delete a user once they've left the organisation or their access needs to be revoked immediately.

When to use:

  • Employee left organisation
  • Account no longer needed
  • Security reason requires access revocation

Deletion process:

  1. Go to Users overview page
  2. Click Manage menu of relevant user
  3. Select "Delete user" from dropdown
  4. Confirm deletion in warning dialog
  5. User is immediately removed from system

Impact of user deletion:

  • Access blocked - Immediate logout and future login blocked
  • Data preserved - Controls, tasks, evidence remain in system
  • Ownership changed - Assignments show "Unknown user"
  • Audit trail intact - Historical activities remain visible
Warning

Permanent action: User deletion cannot be undone. Consider first changing role to "Read Only User" for temporary access restriction.

Keycloak profile configuration

Users can manage their personal account information via the integrated Keycloak interface accessible from their profile.

Updating personal information

Users manage most of their own profile through Keycloak; only their username stays fixed.

Users can adjust themselves:

  • Email - Contact address for system communication
  • First name / Last name - Names as displayed in interface

Not adjustable:

  • Username - Login identifier (often email address)

Access to Keycloak profile:

  1. Log in to Tidal Control
  2. Click profile icon top right (user avatar)
  3. Select "My preferences" from dropdown menu
  4. Keycloak interface opens in new tab
  5. Adjust desired information and click "Save"

Keycloak personal information

Configuring authentication options

Two-factor authentication is set up from the same Keycloak account security screen.

Setting up two-factor authentication:

  1. Go to Account Security in Keycloak menu
  2. Select "Signing in" section
  3. Click "Set up Authenticator application" link
  4. Scan QR code with authenticator app (Google Authenticator, Authy)
  5. Enter verification code to activate 2FA

Keycloak authentication settings

Available security options:

  • Password management - Change password and strength control
  • Two-factor authentication - Authenticator app configuration
  • Device activity - Overview of active login sessions
  • Applications - Linked services and access rights

Strict mode

Organisations using Tidal Control in Strict Mode have an additional layer of role-based access control per compliance object.

Is Strict Mode on?: You can see if your organisation uses Strict Mode via the green "Strict Mode" indicator at the top right of the interface.

Strict mode indicator

How Strict Mode works

In Strict Mode, a Regular User starts with no access at all until they're explicitly assigned to specific objects.

Additional role assignment required:

  • Regular Users start without access to specific controls or assets
  • Object-level roles must be explicitly assigned per control/asset
  • Owner role - Can create, modify and delete compliance objects (controls, risks, assets).
  • Contributor role - Can contribute to tasks and upload evidence, and also create own tasks and issues.

Impact on user management:

  • More granular control over what users can see
  • Explicit assignment required for each compliance object
  • Increased security but more administrative overhead
  • Suitable for large organisations with strict access control
Turn on Strict Mode?

Send an email to support@tidalcontrol.com and we'll set it up for you. Additional licence costs apply to using Strict Mode.

Bulk user management strategies

When onboarding a team, invite them as a group rather than one at a time.

Group invitations

Onboarding a team goes faster if you create every account first and send all invitations together.

Efficient onboarding for teams:

  1. Create all users with correct roles
  2. Assign responsibilities to controls and assets
  3. Test configuration with one pilot user
  4. Send all invitations simultaneously for consistent process
  5. Organize onboarding session for simultaneous account activation

Practical tips for user management

Three moments deserve a fixed routine: someone joining, someone leaving, and the periodic check that the list still matches reality.

New employee onboarding

Run through this when a new employee needs access.

Efficient onboarding checklist:

  • Create user with correct name and email
  • Assign appropriate role based on function
  • Link responsibilities to controls/assets
  • Send invitation and confirm receipt
  • Guide first login and provide system explanation
  • Support 2FA configuration if required

Employee departure handling

Run through this the moment someone leaves, starting with revoking access immediately.

Safe offboarding procedure:

  • Immediately revoke access via user deletion
  • Transfer responsibilities to other team members
  • Check ongoing tasks and change ownership
  • Perform access audit for related systems
  • Document in HR and compliance administration

Periodic user reviews

A user list stays accurate only if someone checks it on a schedule, not just when something goes wrong.

Monthly/quarterly checks:

  • Identify inactive accounts and evaluate
  • Check role appropriateness for function changes
  • Monitor 2FA adoption and encourage
  • Analyse access patterns for security risks

Next steps

Now that you can create and manage users:

  • Start with pilot group for system configuration and testing
  • Develop onboarding process for new team members
  • Plan role management for future organisational changes
  • Configure authentication policy for optimal security