The Users page enables adding, disabling, or removing users from your project or workspace. You can also reset passwords and change roles.

Context menu actions:

For each user, you can perform the following actions in the context menu:

Disable: When a user is disabled, the user cannot access the .


Users can be set to one of the following statuses:

Edit Users

To modify a user account, please complete the following steps.

NOTE: For security reasons, an administrator is not permitted to edit some settings in the administrator's own account.


  1. Locate the user in the list of users.
  2. In the context menu on the right side of the user's listing, select Edit.
  3. In the Edit User dialog, modify the following properties as needed:

Name: The display name of the user.

Email: The email address is used as the login identifier. This value cannot be modified.

Roles: Select or remove the roles to assign to the user. For more information, see Roles Page.

SSO Principal: If SSO is enabled, set this value to be the SSO principal value associated with this user.

NOTE: Required value for each user if SSO is enabled. See Configure SSO for AD-LDAP.

Hadoop Principal: If secure impersonation is enabled, set this value to be the Hadoop principal value associated with this user.

NOTE: The user principal value should not include the realm.

NOTE: Hadoop principal is a required value if secure impersonation is enabled. See Configure for Secure Impersonation.

NOTE: If Kerberos is enabled, verify that all user principals that use the platform are also members of the group of the keytab user.

Deployment management: When selected, this user is assigned the deployment role in the platform. In a Development environment, this role can be added to a user's account to enable access to the Deployment Manager.

NOTE: Deployment management user accounts are intended for managing production execution of flows. These users have a different and limited user interface in the . There should be a limited number of these accounts.

NOTE: Only platform administrators can assign the Deployment management role. Workspace admins cannot.

Tip: A deployment user should be assigned the flow author role. Lesser flow roles may prevent the deployment user from properly importing and managing flows. See Roles Page.

Platform admin: When selected, the user is granted admin privileges over the platform. These privileges include user administration, ability to modify platform settings, and permissions to use admin-only API endpoints.

NOTE: Avoid providing the Platform admin permission to a large number of users.

To save your changes, click Edit user.