This page covers the on-premises administrator in a self-hosted deployment. Organisation admins manage their own members from Manage members.
- Activity: what the user has created and done in Cymph, such as playbooks, assets, reviews and executions.
- Membership: the user’s organisation and role, and the organisation workspaces they belong to, with their role in each. Workspaces of another organisation are marked External.
- ⋯: Enable or Disable User, Reset Password and Delete User. Not shown on your own account.
How to disable a user
Disabling suspends an account without deleting anything. Use it when someone leaves or should lose access for a while.- Go to the Users page
- Click ⋯ on the user’s row and select Disable User
- Confirm by clicking Disable user
- Is signed out of every session straight away and cannot use the API, including with API keys.
- Cannot sign in. After entering the correct password they see “Your account has been disabled. Contact your administrator.” A wrong password gives the usual sign-in error, so the page never reveals that an account exists or is disabled.
- Receives no e-mails from Cymph.
- Keeps their organisation, role, workspaces and everything they created. Nothing is removed, and their licence seat stays in use.
- Is no longer offered when choosing people: RACI, reviewers, step assignees, workspace members, sharing and search. The API also refuses to newly add them to a RACI, a reviewer slot, an execution step or a workspace.
- Is shown as Name (Disabled) wherever they are already assigned. In the RACI matrix and on execution steps, a warning icon explains that they no longer have access.
- Is reported by Risk Signals. On playbooks, a disabled Responsible or Accountable person makes the playbook orphaned. On executions, Executions with steps assigned to disabled users lists every open step that is waiting on them.
- Is skipped when a new execution starts: a step whose agent is disabled is assigned to the person running the execution instead.
How to enable a user
- Go to the Users page
- Click ⋯ on the user’s row and select Enable User
- Confirm by clicking Enable user
The last administrator of an organisation
An organisation with members must always keep an active administrator, so its last one is protected:- Disable User and Delete User are unavailable for them, with a note explaining why.
- An administrator who is alone in their organisation can still be disabled or deleted.
When the on-premises administrator is a member of an organisation, they count as one of its administrators. They hold every organisation permission.
How to delete a user
- Go to the Users page
- Click ⋯ on the user’s row and select Delete User
- Confirm the deletion
Users deleting their own account are still stopped while they have open execution tasks, so their managers can reassign the work first. See Delete account.

