Open Users
Select Platform → Users. Admins can create and manage users. Support users can view the user directory but cannot create users or change their roles.
Use Search users to find a teammate, then select their name to open User details.
Add a user
Select New user.
Enter Email, First name and Last name. Use the email address the person will use to sign in.
Choose a Role.
Select their Organizations, or choose Grant access to all organizations when they need account-wide organization scope.
Select Create user. Wait for completion and check the new entry in the directory.
Creating a user provisions their access; they still need to sign in using a method enabled for the account. Share your account URL and ask them to use the exact email address you added. If a welcome email does not arrive, first check whether the user already appears in Users before creating another entry.
Cancel closes the drawer. If you have unsaved edits, confirm Discard changes to abandon them.
Choose a role
Admin manages users, groups, account settings and configuration, as well as documents and assets.
Support creates, edits and archives documents and assets within its permitted scope, and can manage record access. It cannot administer users, create or edit asset types, or manage account authentication, API keys or IP restrictions.
Viewer reads accessible records and cannot create or edit them.
A role defines available actions. It does not make every record visible. Organization scope, group restrictions and record or folder access still matter. Use the least privileged role that supports the person's work.
Set organization access
Choose individual organizations for someone who works with a limited set of clients. Grant access to all organizations provides scope across current and future organizations.
Group membership can also affect access. For ordinary account roles, allowed organization scopes combine with their user scope, while an explicit group denial takes precedence. Blocked asset types can further limit what they can access. Membership does not change their role.
If someone cannot see a record, check their organization scope and groups, then the record's access and its folder or tag grants. Giving someone Admin solely to make a missing record appear is not the right access fix.
See Understand record, folder and tag access for how those access paths combine.
Update an existing user
Open the user's name, edit their information, role or organizations, then select Save changes. Wait for saving to complete and verify the displayed values. Closing the drawer without saving does not apply the edits.
Before changing someone's email, confirm the new address is the one they will use with the account's sign-in method.
Archive a user
Open User details and select Archive user, or use the archive action in the directory.
Read the confirmation carefully: the person loses access to this account and assets they own transfer to you.
Confirm Archive user, wait for completion, and verify the result in the directory.
You cannot archive yourself or the last Admin. If the person owns records, your user must have access to all organizations to receive ownership; resolve an insufficient-scope error before retrying.
Archiving removes that user's direct record and tag grants. Review any affected restricted folders or tags so the remaining team has the intended access. It does not delete their documents and assets.
The interface does not provide an unarchive action. Contact support if you need to restore an archived user, and review their role, groups and record access afterward rather than assuming every previous grant returns.
Troubleshoot sign-in
Check that the user exists in the correct account, their email matches the identity used to sign in, and their chosen authentication method is enabled. Also check account IP restrictions. A successful Google or Microsoft sign-in alone does not establish access to the Lexful account.
Use Support in Lexful, or email [email protected] if you cannot sign in.
