Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ To invite users in Zero Trust Email security:

1. Log in to [Cloudflare One](https://one.dash.cloudflare.com/).
2. Go to **Manage Account**.
3. Select **Members** > **Invite** > [Add account members](/fundamentals/manage-members/manage/#add-account-members).
3. Select **Members** > **Invite members** > [Add account members](/fundamentals/manage-members/manage/#add-account-members).

Once you have added new account members, you will have to assign each member an [Email security role](/cloudflare-one/roles-permissions/#email-security-roles).

Expand Down
19 changes: 9 additions & 10 deletions src/content/docs/fundamentals/manage-members/manage.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -11,15 +11,15 @@ products:
- fundamentals
---

import { Stream, Render } from "~/components";
import { Render } from "~/components";

Granting access to others on your account is done with several sets of data principles:

1. Accounts have Account Members.
2. Account Members have policies.
3. Policies are constructed out of actors, roles, and scopes.

When assigning a new user, you can assign a policy to them directly. If multiple policies are needed, they can be added or revoked at a later time.
When inviting a new member, you can assign one or more permission policies to them directly. Policies can also be added or revoked at a later time.

Learn how to add new account members, edit or revoke their access, and resend verification emails.

Expand All @@ -29,13 +29,6 @@ Learn how to add new account members, edit or revoke their access, and resend ve

:::

<Stream
id="492e46e01d4db17c302f8d10278ab3d8"
title="Manage account members"
thumbnail="https://imagedelivery.net/xDOJvHcv1KwTQn6S-BGFIw/57def76d-110a-419e-a7e4-9278829d6800/public"

/>

## View account members

<Render file="account-member-manage-limitation" product="fundamentals" />
Expand All @@ -54,6 +47,12 @@ Learn how to add new account members, edit or revoke their access, and resend ve

<Render file="edit-member-permissions" product="fundamentals" />

## Manage member settings

<Render file="account-member-manage-limitation" product="fundamentals" />

<Render file="manage-member-settings" product="fundamentals" />

## Resend an invitation

<Render file="resend-member-invitation" product="fundamentals" />
Expand All @@ -65,7 +64,7 @@ Learn how to add new account members, edit or revoke their access, and resend ve
<Render file="remove-account-members" product="fundamentals" />

:::note
If you have been invited to an account and want to remove yourself from the account, go to **Manage Account** > **Members**. Under your email address, select **Leave**.
If you have been invited to an account and want to remove yourself from the account, go to the **Members** page. On your own row, select **...** > **Leave account**.
:::

## Super Administrator access
Expand Down
20 changes: 13 additions & 7 deletions src/content/partials/fundamentals/add-account-members.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -12,17 +12,23 @@ To add a member to your account:

<DashButton url="/?to=/:account/members" />

3. Select **Invite**.
3. Select **Invite members**.

4. Fill out the following information:
4. Under **Add email addresses**, enter one or more email addresses. Separate multiple addresses with commas.

- **Invite members**: Enter one or more email addresses (if multiple, separate addresses with commas).
- **Scope**: Use a variety of fields to adjust the [scope](/fundamentals/manage-members/roles/) of your roles.
- **Roles**: Choose one or more [roles](/fundamentals/manage-members/roles/) to assign your members.
5. Under **Add permission policies**, create the first permission policy for these members:

5. Select **Continue to summary**.
a. Choose the policy's [scope](/fundamentals/manage-members/scope/): either the entire account, or specific resources such as individual domains, Workers, or Access applications.

6. Review the information, then select **Invite**.
b. Select one or more [roles](/fundamentals/manage-members/roles/) to include in the policy. Search by role name, or expand a role category (for example, **App Security** or **Cloudflare One / Zero Trust**) and select individual roles. To select every role in a category, select the category's checkbox.

c. Select **Create policy**.

6. (Optional) Repeat the previous step to add more permission policies with different scopes or roles.

7. Select **Invite members**.

Each invitee receives an email invitation and appears on the **Members** page with a **Pending** status until they accept it.

:::note

Expand Down
11 changes: 7 additions & 4 deletions src/content/partials/fundamentals/edit-member-permissions.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -12,10 +12,13 @@ To edit member permissions using the dashboard:

<DashButton url="/?to=/:account/members" />

3. Select a member record, then select **Edit**.
4. Update the scope and roles of their permissions.
5. Select **Continue to summary**.
6. Review the information, then select **Update**.
3. On the member's row, select **...** > **View & Edit permission policies**.

4. On the **Permission policies** tab, make your changes:

- To add a policy, select **Create a policy**, choose the [scope](/fundamentals/manage-members/scope/) and [roles](/fundamentals/manage-members/roles/), then select **Create policy**.
- To change an existing policy, select **...** > **Edit policy** on its row, adjust the scope and roles, then save your changes.
- To remove a policy, select **...** > **Delete policy** on its row.

</TabItem> <TabItem label="API">

Expand Down
20 changes: 20 additions & 0 deletions src/content/partials/fundamentals/manage-member-settings.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
---
{}
---

import { DashButton } from "~/components";

Each member has settings that apply only to them, such as their API access.

To manage a member's settings:

1. In the Cloudflare dashboard, go to the **Members** page.

<DashButton url="/?to=/:account/members" />

2. On the member's row, select **...** > **Manage member settings**.
3. Under **API access for this member**, choose one of the following:

- **Account default**: Follow the account-wide API access setting.
- **Allow access**: Always allow API access, even if the account-wide setting is off.
- **Block access**: Always block API access, even if the account-wide setting is on.
Original file line number Diff line number Diff line change
Expand Up @@ -6,15 +6,15 @@ import { DashButton, TabItem, Tabs } from "~/components";

<Tabs syncKey="dashPlusAPI"> <TabItem label="Dashboard">

To revoke a member's access to your account:
To revoke a member's access to your account, or to cancel a pending invitation:

1. In the Cloudflare dashboard, go to the **Members** page.

<DashButton url="/?to=/:account/members" />

2. Locate an account member and expand their record.
3. Click **Revoke**.
4. Click **Yes, revoke access**.
3. On the member's row, select **...** > **Remove member**.

4. In the confirmation dialog, select **Remove member**.

</TabItem> <TabItem label="API">

Expand Down
11 changes: 7 additions & 4 deletions src/content/partials/fundamentals/resend-member-invitation.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -2,11 +2,14 @@
{}
---

import { DashButton } from "~/components";

If you invited a member to your account but they cannot find the invitation or the invitation expires, you can resend the invitation through the Cloudflare dashboard:

1. Log in to the [Cloudflare dashboard](https://dash.cloudflare.com/login) and select your account[^1].
2. Go to **Manage Account** > **Members**.
3. Select a member record where their **Status** is **Invite Pending**.
4. Select **Resend invite**.
1. In the Cloudflare dashboard, go to the **Members** page.[^1]

<DashButton url="/?to=/:account/members" />

2. On the row of the member whose **Status** is **Pending**, select **...** > **Resend invite**.

[^1]: To manage account members, you must have a role of **Super Administrator** and have a [verified email address](/fundamentals/user-profiles/verify-email-address/).
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ import { DashButton, TabItem, Tabs } from "~/components";

To view members using the dashboard:

In the [Cloudflare dashboard, go to the **Members** page.
In the Cloudflare dashboard, go to the **Members** page.

<DashButton url="/?to=/:account/members" />

Expand Down
Loading