Skip to content

As an owner or administrator, you control who can access your Wallet-as-a-Service (Palisade) organization and what they can do. This guide covers the admin perspective on user management — when and why to use each action — and links to the Manage users reference for step-by-step procedures.

To access user management, go to Settings > User management.

Understand user roles

Palisade provides six roles. Assign each user the role with the least privilege needed for their responsibilities. See User roles and permissions for the full permission matrix.

RolePurposeTypical team member
OwnerFull access, including organization-level settingsCTO, Head of Operations
AdministratorFull access except organization-level settingsOperations lead, security lead
ProposerManage wallets, initiate transactionsTreasury analyst, operations team
ApproverReview and approve transactions, addresses, policiesCompliance officer, senior manager
ViewerRead-only accessFinance team, reporting
AuditorRead-only audit accessInternal/external auditors

User lifecycle

The table below summarizes every user management action, when to use it, and where to find the procedure.

ActionWhen to useReversible?Reference
InviteOnboard a new team memberNo (invitation can't be unsent)Invite a new user
Edit profileChange a user's name or roleYesEdit another user's profile
Reset passwordUser loses access or you suspect password compromiseYes (user sets a new password)Reset password
Reset 2FAUser lost access to their authenticator appYes (user re-enrolls)Reset 2FA
BlockRevoke access immediately while preserving the accountYes (unblock restores access)Block user
UnblockRestore a previously blocked user's accessYesBlock user

To invite a user, select Invite a user on the User management page. To manage an existing user, you have two options:

  • From the user list: open the Actions menu (three dots) in their row, which provides: Update, Reset 2FA, Reset password, and Block user.
  • From the user profile: select a user's name to open their profile. The sidebar tabs — Personal details, Roles, Password reset, 2FA, API credentials, Devices, and Control access — provide the same actions plus a Block access button on the Control access tab.
Authentication method is permanent

You can't change a user's authentication method after the invitation is sent. If your organization uses SSO, configure it before inviting users. See Configure single sign-on.

Governance decisions

When to block

Palisade doesn't support deleting active users — use blocking to revoke access while preserving the user's audit trail. You can delete users after approvers reject their invitation or creation approval.

ScenarioActionWhy
Team member leaves the organizationBlockPreserves audit trail and prevents access.
Suspected account compromiseBlock immediatelyStops access while you investigate.
Temporary leave or role changeBlockRestores access easily when the user returns.
You created a user in error (never activated)BlockThe account remains but has no access.

Credential reset security

Before resetting a user's password or 2FA, verify their identity through an out-of-band channel (phone call, in-person confirmation). Resetting credentials based on email requests alone creates a social engineering risk.

Minimum admin redundancy

Always maintain at least 2 owners or administrators. If one admin loses access or leaves, you need another admin to reset credentials or manage the organization.

Access review checklist

Perform this review on a regular cadence (monthly or quarterly):

  • Every user has the minimum role required for their current responsibilities.
  • No inactive users remain with active access (block them).
  • At least 2 owners or administrators are active.
  • Users who changed teams or responsibilities have updated roles.
  • You documented and justified all Owner and Administrator role assignments.
  • You reviewed users whose devices you removed from quorums for continued access.
Approval groups for user invitations

You can require approval before new user invitations are sent. This prevents any single admin from unilaterally adding users to the organization. See Configure approval flows.