Overview
User management should combine quick profile actions with safe guardrails for role changes.
The floorplan supports bulk review, per-user detail, and traceability.
Govern the identity lifecycle
Search the roster, inspect user context, change roles, lock access, and send a policy-aware invitation with explicit feedback.
People and access
Manage membership, roles, and access lifecycle with an immutable audit trail.
Anatomy
Use each piece in this order to keep interpretation and automation consistent.
- 1Identity list
Primary roster with search and role pills.
- 2Bulk panel
Mass role or team updates where permitted.
- 3User detail
Identity, permissions, and activity summary.
- 4Audit summary
Recent access changes with operator context.
- 5Invite actions
Create and onboard new users safely.
The ordering here is not visual-only; it reflects interaction priority and expected user cognition. Keep this order unless policy demands a specific domain exception.
When to use
Use this pattern when the user needs guided consistency, state, and reuse at scale.
Recommended
- Organization administration
Use in any workspace with role assignment responsibilities.
- Tenant management
Use for membership and team membership workflows.
- Compliance monitoring
Use when access updates need audit trails.
When not to use
Avoid forcing this pattern where simpler, direct interactions are sufficient.
Avoid
- Single app settings
Use profile screens for personal preferences.
- Public directories
Avoid in purely public-facing contexts.
- Unmanaged directories
Do not duplicate identity management from external IdPs.
Variants
A small number of variants helps teams choose correctly without adding complexity.
Invite-first
Focused onboarding and activation flow.
Role-first
Prioritize role and access assignment actions.
Audit-first
Detailed change summary and event history.
States
States communicate readiness, risk, and expected user behavior.
| State | Trigger | Visual response | Interaction |
|---|---|---|---|
| Invite | New user added | Pending acceptance state and action reminders | Enable reminder and reminder actions. |
| Active | Verified user | Active badge and accessible role state | User can perform allowed actions. |
| Locked | Admin lock | Clear blocked state | Only admin override unlock available. |
Behavior
Behavior should remain predictable across devices, permissions, and async edges.
Least privilege
Expose only roles allowed in current workspace policy.
State reconciliation
Refresh identity state after sync or directory changes.
Change log
Immediate logging of role and status changes.
Accessibility
Keep interaction clarity high and ensure assistive technologies get the same meaning.
| Key | Action |
|---|---|
| N | Focus quick user invite flow. |
| ShiftF | Open advanced filter within roster. |
| Ctrl/CmdR | Refresh user data. |
- Clearly identify destructive actions with explicit text and confirmation.
- Group roster controls with clear labels and table headers.
- Ensure role badges are text-readable and announced as status.
Content guidelines
Consistency is achieved by language standards, not by design only.
User title
Use full name first, then role.
Maya Patel — Admin
Invite wording
Show expected next action clearly.
Invite sent — pending activation
Role language
Use approved role terminology.
Workspace Owner
Examples
Reference implementation style, payloads, and practical behavior.
Production use
- Separate admin and member views to reduce accidental overexposure.
- Use soft-lock states before disabling critical users.
- Keep bulk role changes in guarded confirmation flows.
Props / API
Use these API entries as a baseline contract and validate them against your domain layer.
These names are implementation-oriented and should map to your local contracts.
Props