mobieusKnow User Management History #46
Author
Patrick Bass
Submitted
May 26, 2026 10:36pm
Reviewed
May 26, 2026 10:36pm
Summary
Initial version
+ ## User Management
You manage every member from your admin area. Open **Admin > Members**, find the
person, and open their profile. Everything below happens in your admin tools.
There is no separate sign-in portal for you or your members to visit.
+ Manage all community members at `/admin/users`.
## Roles
+ ### User List
Every member has one role. Higher roles include everything below them.
+ Browse all users with search, filter by role, and sort by activity. The list shows username, display name, email, role, join date, and last active time.
- **Registered** is a standard member.
- **Moderator** can reach the admin area and the moderation queue.
- **Admin** can manage members.
- **Super Admin** can change site settings, branding, and broadcasts.
- **Banned** is blocked from everything.
+ ### User Detail Page
You can assign any role up to and including your own. You cannot give someone a
role higher than yours, and you cannot demote yourself.
+ Click any user to see their full admin profile:
## Find and edit a member
+ - **Role management** — change user role (Registered, Moderator, Admin, Super Admin)
+ - **Suspension** — temporarily suspend with a reason and duration
+ - **Ban** — permanently ban from the community
+ - **Shadow ban** — user can post but their content is invisible to others
+ - **Password reset** — force a password change on next login
+ - **Email verification** — manually verify or re-send verification
+ - **Stats exclusion** — exclude from leaderboards and public stats
+ - **Notes** — private admin notes visible only to other admins
+ - **Infractions** — issue formal infractions with point values
Search by name, username, or email on the Members page. Open a profile to edit the
display name, username, email, and role, and to see the member's recent activity.
+ ### Role Hierarchy
## Account actions
+ | Level | Role | Access |
+ |-------|------|--------|
+ | 1 | Banned | Blocked from all functionality |
+ | 2 | Registered | Standard member access |
+ | 3 | Moderator | Moderation tools, admin panel (limited) |
+ | 4 | Administrator | Full user management, content management |
+ | 5 | Super Admin | System configuration, branding, all access |
From a member's profile you can:
+ Users can only assign roles strictly below their own level.
- **Reset password.** Send the member a secure, single-use link to set a new
password. The link expires after a short time. You never see or set the member's
password yourself.
- **Lock account.** Immediately block the member from signing in. Use this to stop
access right away while you look into something.
- **Unlock account.** Restore access to a locked account.
- **Clear lockout.** If a member locked themselves out with too many failed
sign-in attempts, clear it so they can try again.
- **Clear two-factor authentication.** Remove the member's two-factor setup, for
example when they lose their device. They can set it up again next time they sign
in.
- **Sign out everywhere.** End all of the member's active sessions on every device.
Pair this with a password reset if you think an account is compromised.
- **Suspend or ban.** Temporarily suspend a member, or ban them to block all
access. Suspensions can be timed and lift automatically.
+ ### mobieusID Integration
Each action is recorded in your audit log with who did it and when.
+ User accounts are linked to mobieusID (Zitadel). From the admin user page, you can:
## What members manage themselves
+ - **Lock** the user's mobieusID account
+ - **Unlock** a locked account
+ - **Clear MFA** — remove multi-factor authentication if the user is locked out
Members handle their own credentials from **Account settings**. They can:
- **Change their password** at any time.
- **Turn on two-factor authentication** with an authenticator app, and keep backup
codes in case they lose their device.
- **Change their email address.** For security, a change is confirmed with links
sent to both the old and the new address.
## Single sign-on for teams
If your organization uses its own identity provider, members can sign in with it.
When they do, Mobieus matches them to their account by their verified email
address, so their existing profile and history stay intact. Ask your platform
contact to connect your provider.
## Bulk actions
Select several members on the Members page to change roles, suspend, or ban in one
step. Members whose role is higher than yours are skipped automatically.
## Tips
- Reset the password and sign the member out everywhere together if an account may
be compromised.
- Clearing two-factor authentication does not change a password. Send a reset as
well if you are unsure.
- Banning blocks access immediately and stays in place until you lift it.

User Management

Manage all community members at /admin/users.

User List

Browse all users with search, filter by role, and sort by activity. The list shows username, display name, email, role, join date, and last active time.

User Detail Page

Click any user to see their full admin profile:

  • Role management — change user role (Registered, Moderator, Admin, Super Admin)
  • Suspension — temporarily suspend with a reason and duration
  • Ban — permanently ban from the community
  • Shadow ban — user can post but their content is invisible to others
  • Password reset — force a password change on next login
  • Email verification — manually verify or re-send verification
  • Stats exclusion — exclude from leaderboards and public stats
  • Notes — private admin notes visible only to other admins
  • Infractions — issue formal infractions with point values

Role Hierarchy

Level Role Access
1 Banned Blocked from all functionality
2 Registered Standard member access
3 Moderator Moderation tools, admin panel (limited)
4 Administrator Full user management, content management
5 Super Admin System configuration, branding, all access

Users can only assign roles strictly below their own level.

mobieusID Integration

User accounts are linked to mobieusID (Zitadel). From the admin user page, you can:

  • Lock the user's mobieusID account
  • Unlock a locked account
  • Clear MFA — remove multi-factor authentication if the user is locked out
## User Management

Manage all community members at `/admin/users`.

### User List

Browse all users with search, filter by role, and sort by activity. The list shows username, display name, email, role, join date, and last active time.

### User Detail Page

Click any user to see their full admin profile:

- **Role management** — change user role (Registered, Moderator, Admin, Super Admin)
- **Suspension** — temporarily suspend with a reason and duration
- **Ban** — permanently ban from the community
- **Shadow ban** — user can post but their content is invisible to others
- **Password reset** — force a password change on next login
- **Email verification** — manually verify or re-send verification
- **Stats exclusion** — exclude from leaderboards and public stats
- **Notes** — private admin notes visible only to other admins
- **Infractions** — issue formal infractions with point values

### Role Hierarchy

| Level | Role | Access |
|-------|------|--------|
| 1 | Banned | Blocked from all functionality |
| 2 | Registered | Standard member access |
| 3 | Moderator | Moderation tools, admin panel (limited) |
| 4 | Administrator | Full user management, content management |
| 5 | Super Admin | System configuration, branding, all access |

Users can only assign roles strictly below their own level.

### mobieusID Integration

User accounts are linked to mobieusID (Zitadel). From the admin user page, you can:

- **Lock** the user's mobieusID account
- **Unlock** a locked account
- **Clear MFA** — remove multi-factor authentication if the user is locked out