# User management

Managing users and their roles and permissions keeps your Ripple operations secure. The user settings in the Payments Direct UI let administrators assign granular permissions to each user, giving them the appropriate level of access.

## Prerequisites

Prerequisite
You must sign in as an Organization Administrator or a User Administrator to reach **Settings** > **Users** and manage user accounts. Check your role in your user profile.

For information about signing in, including setting your password for the first time, see [Sign in to your Ripple account](/products/payments-direct-2/user-interface/guides/sign-in-to-your-ripple-account).

## Manage user accounts

This section describes how to add, edit, and delete user accounts. For more information about roles and permissions, see [User settings](#user-settings).

### Add a new user account

1. Sign in as an administrator and select the **Settings** gear icon.

2. Select **Team** > **Users** to display the current list of user accounts.

3. Select **New User** in the upper right corner to display the **New User** page.

4. Enter the **First Name**, **Last Name**, and **Email** address for the new user.
The email address cannot be changed once the account is created. It is the permanent username for the account and must stay the same for authentication purposes. Ripple also uses it to contact the user to set up their password.
5. Select a **Role**. For most users this should be **Operator**. For more information, see [Roles](#roles).
6. For the Operator role, choose the permission set that most closely describes what this user will do. This turns on the permissions granted by that set. For more information, see [Permissions](#permissions).
  - To modify a set's permissions, select the checkboxes for permissions you want to turn on or off.
  - To set permissions from scratch instead, select the individual checkboxes you want without choosing a set.
7. Select the environments this user can access. For more information, see [Environments](#environments).

8. Select **Save User** at the bottom of the page. This returns you to the **Users** page, where the new account is listed.


The new user receives an email with the subject line **Welcome to Ripple!** containing a link to the home page, and a second email with the subject line **Set your Ripple Onboarding account password** containing a link for setting a password. The user completes their own account setup from those emails. For the password requirements, see [Sign in to your Ripple account](/products/payments-direct-2/user-interface/guides/sign-in-to-your-ripple-account).

### Edit a user account

1. Sign in as an administrator and go to the **Settings** page.
2. Select **Team** > **Users**.

3. Find the account you want to modify and select the user name link.
4. Edit the account. For information about roles, permissions, and environments, see [Roles](#roles), [Permissions](#permissions), and [Environments](#environments).
You cannot change the email address. It must remain the same for authentication purposes.
5. Select **Save User** to save your changes.


### Delete a user account

1. Sign in as an administrator and go to the **Settings** page.
2. Select **Team** > **Users**.

3. Find the account you want to remove and select **Delete User** to the right.


## User settings

This section describes the roles, permissions, and environments you can set on the **New User** and **Edit User** pages.

### Roles

| Role  | Description |
|  --- | --- |
| **Organization Administrator** | Automatically assigned all available permissions. |
| **User Administrator** | May be assigned permissions by an Organization Administrator. |
| **Operator** | May be assigned permissions by an Organization Administrator or a User Administrator. |


As an Organization Administrator, you can add, edit, and delete user accounts from the **Settings** > **Users** page.

### Permissions

You grant each permission using the **Can Read** and **Can Edit** checkboxes. Selecting **Can Edit** also selects **Can Read**, and clearing **Can Read** also clears **Can Edit**.

The following permissions apply to Payments Direct:

| Permission  | Description |
|  --- | --- |
| **Payments** | Payments in the production and UAT environments. **Can Edit** lets the user create payments. |
| **API credentials** | Credentials for connecting to the API. See [API credentials](/products/payments-direct-2/user-interface/settings/api-credentials). |
| **Identities**
 | Creating and removing payment identities. See [Payment identities](/products/payments-direct-2/introduction/concepts/payment-identities).
This permission offers **Can Edit** only. It has no separate read option.
 |


Note
If your organization holds other Ripple products in addition to Payments Direct, the page lists permissions for those products as well.

Tip
For a user with the **Operator** role, select one of the four permission sets, **Business Growth**, **PM & Integration**, **Payment Operations**, or **Maintenance & Support**, to apply a preselected combination of read and edit permissions. You can modify the selection afterwards.

### Environments

The **Settings** > **Users** page lets you choose which environments a user can access, corresponding to the phases of your implementation.

| Environment  | Description |
|  --- | --- |
| **Test** | An environment developers can use when integrating with Ripple. It has no production consequences. |
| **UAT** | A user acceptance testing environment with simulated transactions. |
| **Production** | The environment where the transfer of actual funds takes place. |


Note
In many cases, only **UAT** and **Production** are available. The **Test** environment is offered for some products only, and can change as integration proceeds.

When a page offers activities that can take place in more than one of the environments you have access to, an environment dropdown appears at the top of the page so you can choose where to work.

Some activities, such as managing users, apply across all environments, so pages offering those activities have no environment picker. These activities have real consequences, but you can usually undo them, for example by deleting a test user.