Skip to main content

Managed User Accounts

Managed user accounts let Business and Enterprise organizations own global Incido user accounts for their team members. A managed account is tied to one managing organization that controls the user's name, email, lifecycle, and — optionally — whether the user may join other organizations.

Managed accounts are useful when you need centralized control over operator identity — for example, when staff should not change their login email, when departing employees must lose access across all organizations at once, or when SAML just-in-time provisioning should create organization-owned accounts automatically.

For invitations and roles, see Users, roles, and invitations. For SAML provisioning settings, see SAML single sign-on.

Plan availability

Managed user accounts are available on Business and Enterprise plans. The feature must be enabled on your subscription before managed-account controls appear in the Dashboard.

You cannot downgrade or remove the managed users feature while managed accounts still exist. Release management or delete all managed accounts before changing plans.

Account types

The Users → View user page shows an account type for each person:

Account typeMeaning
Free-floatingA standard Incido account not owned by any organization
Managed by your organizationYour organization owns and administers this account
Managed by another organizationAnother organization owns the account; your org has only a membership
DeletedThe account was soft-deleted and may be within the restoration window

The Users list includes a Managed column indicating whether each member is managed by your organization.

How users become managed

There are three paths to managed status:

Invite with management on accept

When sending an invitation from Users → Invitations, enable Manage user on accept. The user becomes a managed account owned by your organization when they accept.

By default, users invited this way cannot join other organizations until an administrator changes their join policy.

Request management for an existing member

For someone already in your organization, open Users → View user and use Request in the Account management section. The user receives an email with a link to accept or decline.

Management requests expire after a configurable number of days (default seven). Only the user themselves can accept or decline — administrators cannot accept on their behalf.

If the user belongs to other organizations when they accept, they can still join additional organizations unless you later restrict join policy.

SAML just-in-time provisioning

When SAML single sign-on is configured, enable Provision new users as managed on the identity provider. Only newly created users provisioned through SAML become managed accounts. Existing users who sign in through SAML are unchanged.

What managed users cannot do

Managed users have restrictions designed to keep identity control with the managing organization:

  • They cannot change their name or email from their profile
  • They cannot delete their own account from the profile page
  • They may be blocked from joining other organizations when join policy is restricted

Managed users can still sign in, switch between organizations they belong to, and perform any actions their role permits in each organization.

What administrators can do

Organization administrators with managed-user access can:

  • Edit profile — Update name, email, organization role, incident responder status, and team memberships (email changes may be blocked for users on verified SAML domains managed by your organization)
  • Edit account management — Change whether the user can join other organizations
  • Request password reset — Send a password reset email to managed users in your organization
  • Release management — Return the account to free-floating status and allow joining other organizations
  • Restore account — Recover a soft-deleted managed account within the restoration window

Join policy

The Can join other organizations setting controls whether a managed user may accept invitations or join additional organizations.

When you disable this setting, the user must first be removed from all other organization memberships. Incido blocks the change while other memberships exist.

Users who cannot join other organizations see a message if they attempt to accept an invitation to a second organization.

Removing users

The Remove action on the user view page behaves differently depending on account type. This distinction is important for compliance and offboarding.

ScenarioActionResult
Free-floating memberRemove from organizationMembership is removed; the Incido account remains and the user can access other organizations
Managed by your organizationRemove user from IncidoAccount is soft-deleted and removed from all organizations; sessions and tokens are revoked; restorable within 30 days by default
Managed by another organizationRemove is disabled; your organization cannot delete an account owned elsewhere
YourselfRemove is always disabled
Last administrator of any organizationBlocked to prevent organizations without admins

For managed accounts owned by your organization, you cannot use "remove from organization" alone — use account deletion or release management first.

Restore

When a managing organization soft-deletes a managed account, administrators in that organization can Restore account within the restoration window (30 days by default).

Restore recovers the user account and creates a new membership in your organization with the role the user had before deletion. Historical membership rows from before deletion are not restored in place.

Platform administrators cannot restore managed accounts — only the managing organization can.

Management request flow

  1. An administrator opens Users → View user for an existing member and clicks Request in Account management.
  2. The user receives an email explaining that your organization wants to manage their account.
  3. The user signs in and opens the acceptance page from the email link.
  4. The page summarizes what management means: administrators can update their name and delete the account; the user cannot change email or name; the user cannot self-delete; administrators may restrict joining other organizations.
  5. The user clicks Accept management or Decline.

If the user declines or the request expires, the account remains free-floating.

Billing and plan changes

Managed user accounts count toward your plan's user limits the same way free-floating members do.

You cannot remove the managed users feature or downgrade to a plan that excludes it while managed accounts still exist. Release or delete all managed accounts first.

What changes on the public frontend

Managed account settings do not change public status page content. They affect who can access the Dashboard and how offboarding works. Deleting a managed account removes the operator from all organizations immediately, which can affect your ability to publish incident updates if the wrong person is removed during an active event.

Operational effects

Align managed-account policy with your on-call and incident workflows. Before restricting join policy, confirm the user does not need access to partner or client organizations. Before deleting a managed account, verify they are not the last administrator or the only person who can publish updates. Coordinate with Users, roles, and invitations and SAML single sign-on when provisioning new team members.

Troubleshooting

Managed account controls do not appear. Confirm your plan includes managed user accounts and that you are an organization administrator.

A user cannot accept a management request. They must be signed in as the user who received the email. Requests expire after the configured number of days — send a new request if needed.

Remove is disabled for a user in my organization. The account may be managed by another organization, or the user may be the last administrator of an organization. Check the account type on the view page.

I cannot disable "Can join other organizations." Remove the user from all other organization memberships first, then change join policy.

A managed user cannot join a second organization. Their join policy may be restricted. An administrator can enable Can join other organizations after confirming no policy conflict.

Plan downgrade is blocked because of managed users. Release management or delete all managed accounts owned by your organization before changing plans.

I need to change a managed user's email but cannot. If the user is on a verified SAML domain managed by your organization, email changes may be restricted. Adjust SAML domain configuration or release management if a different email is required.

Restore is not available. The restoration window may have passed, or you may not be an administrator in the managing organization. Only the organization that deleted the account can restore it.