User Lifecycle management
Last updated
Last updated
This section explains how user accounts are created, managed, and removed throughout their lifecycle within the platform.
User Lifecycle Management ensures that:
Users have the right access at the right time
Access is removed promptly when no longer needed
Identity data remains accurate and secure
This guide applies to:
Personal accounts
Business and enterprise accounts
Users managed manually or via automated provisioning (SCIM)
It covers:
User onboarding
Account updates
Access changes
User offboarding
Before managing user lifecycles, ensure that:
User Lifecycle Management spans the entire journey of a user account, from creation to deactivation.
The platform supports:
Users can be created through:
During creation:
Administrators can manage:
When SCIM is enabled:
Access can be adjusted by:
Changes take effect immediately and are logged for audit purposes.
Throughout the user lifecycle:
Security controls remain consistent across platforms.
When access is no longer required:
Deactivated users:
You have administrative permissions (for business accounts)
Your organization’s identity model is defined
Security policies are configured (roles, MFA, access rules)
Manual user management
Automated lifecycle management through SCIM
Centralized enforcement of security policies
User creation
Profile and role updates
Ongoing access management
User deactivation or removal
Email-based sign-up
Google sign-up (with password creation)
Administrative invitation
SCIM-based automated provisioning
Email verification is required
Default roles and policies are applied
Security settings inherit organization rules
User profile information
Role assignments
Group membership
Organization-level access
The Identity Provider acts as the source of truth
Attribute changes are synced automatically
Updating roles
Modifying group membership
Applying security policies
MFA policies are enforced
Risk-based authentication may be applied
Device, IP, or geo-based rules can restrict access
Users can be deactivated manually
SCIM can automatically disable users from the IdP
Active sessions are revoked
Cannot sign in
Retain historical audit data
Deleted users cannot be recovered
Deactivation preserves audit history
Manual changes may be overridden when SCIM is enabled
All lifecycle events are recorded for compliance
User Lifecycle Management controls access from onboarding to offboarding
Automation reduces errors and administrative overhead
Security policies are enforced consistently
SCIM enables scalable enterprise user management