Users
Invite, edit, and manage organization members in the Admin Panel: assign roles and regions, reset passwords, resend invites, and activate or deactivate accounts.
The Users page lists every member in your organization scope. From here you can invite people, update their roles and region assignments, and manage account status.
Open Admin Panel > Users to reach the list. Use the row ⋯ menu for actions, or open a user to edit details.
Platform roles vs app roles
Every user has two role layers. They answer different questions:
| Layer | Question it answers | Set from |
|---|---|---|
| Platform role | Where can this person work in the org? | Users (and when inviting) |
| App role | What can they do inside each app? | Security > Assign Roles |
Platform role = org hierarchy scope (one per user).
App role = permissions inside Well Management, RodSim, Calculators, and other installed apps (one role per app).
Platform roles
| Role | Scope | Typical use |
|---|---|---|
| HQ Admin | Entire organization | Billing, divisions, company settings, all regions |
| Division Admin | One division | Manage that division’s regions and users |
| Region Admin | Assigned region(s) | Manage users and operations in those regions |
| Key User | Assigned region(s) | Day-to-day wells and simulations; no user admin |
App roles
App roles are the same set in every app: Admin, Engineer, Advisor, and Guest. A platform role picks a default app role (for example, Key User → Engineer). Override per app on Assign Roles when someone needs more or less access than that default.
Guest is for read-only internal users (managers, reviewers, stakeholders). It does not take a paid license seat-it uses the free guest seat pool. Guests can view wells, simulations, and reports in their region/division scope, but cannot create or edit. See Guest role and Billing & Licenses.
Full matrix and defaults: Roles & Permissions. Deep reference: RBAC.
HQ Admin is required for organization-wide billing and division creation. Division Admin and Region Admin can manage users only within their assigned scope.
Invite or add a user
- Go to Admin Panel > Users
- Click Add User
- Enter First Name, Last Name, and Email Address
- Choose a User Role and confirm the Organization (division or region scope)
- Choose App Access defaults and whether to Send Invitation Email
- Click Add User
The user receives an email invitation when Send Invitation Email is selected. They must accept before their membership is fully active.
Resend an invitation
If someone cannot find their invite, open the user row ⋯ menu and click Resend Invitation. Confirm the email address is correct first. You can also Copy Invitation Link from the same menu when the invite is still pending.
User actions menu
Each row has an actions menu with common admin tasks (Edit User, Send Password Reset, Assign to Region, Change Role, Deactivate, and invitation controls when applicable):
Edit a user
- Open Admin Panel > Users
- Open the user row ⋯ menu and click Edit User
- Update Name, Email, Platform Role, or region assignment
- Click Save
Changes apply immediately for active users.
Change a user's role
Platform role (where they work):
- Open the user in Users
- Use Edit User or Change Role
- Set Platform Role and scope (division or region)
- Save
App roles (what they can do in each app): open Assign Roles and set the dropdown per installed app. Changing platform role does not replace careful per-app overrides you already saved.
Reset a password
- Open Admin Panel > Users
- Open the user row ⋯ menu
- Click Send Password Reset
- Confirm in the dialog
PetroBench sends a password reset link to the user's email. You cannot set their password directly.
Activate or deactivate a user
Deactivating a user blocks sign-in without deleting their history.
- Open the user row ⋯ menu
- Click Deactivate (or Activate if inactive)
- Confirm when prompted
Deactivated users lose access immediately. Wells and simulations they created remain in the organization.
Remove a user
- Open the user row ⋯ menu
- Click Remove from Division (or the remove action shown for your scope)
- Confirm the action
Removing a user ends their membership in that scope. Only administrators with sufficient scope can remove users.
Key Personnel
Designated Key Personnel contacts are managed from Admin Panel > Key Personnel (HQ Admin). See Company Profile.
Common tasks
| Task | Where |
|---|---|
| Invite a new engineer | Users > Add User |
| Move someone to another region | Row menu > Assign to Region |
| Grant read-only app access | Security > Assign Roles |
| Resend a pending invite | Row menu > Resend Invitation |
| Revoke access quickly | Row menu > Deactivate |
Next steps
- Configure app-level permissions: Roles & Permissions
- Assign users to regions: Regions
- Troubleshoot missing data: Organization Access