Users and roles
Site Admin → Users & roles (/organizer/admin/users) is the one place to see and change who can manage ConferenceOS. It lists every site admin, every active event team member, and everyone with MCP access, with one row per person. Only site admins can open it.
What each kind of access allows
There are three separate kinds of access, and one person can hold any mix of them.
| Access | Applies to | What it allows |
|---|---|---|
| Site admin | Every event and the site | Everything: every event workspace, site settings, all Site Admin tools, and this page |
| Event owner | One event | The full organizer workspace for that event: settings, program, CFP review and decisions, reports and exports, and Production Hub tasks |
| Event admin | One event | The same permissions as event owner |
| Event reviewer | One event | CFP review only: the reviewer queue and scoring. No organizer workspace, no CFP decisions, and no reports |
| MCP access | Content tools at /api/mcp | Content-only event-admin tools for an AI agent, used with the person's own sign-in. System tools such as minting API keys stay on machine API keys only |
A few rules follow from this:
- Only site admins can add or remove event team members, on this page or on an event's Team page. An event owner cannot promote themselves or anyone else.
- MCP access is separate from site admin. A site admin without MCP access cannot use the MCP tools as a person, and turning MCP access on does not make anyone a site admin.
- Prefer an event role. Give site admin only to people who run the whole installation.
Find a person
- Type part of an email address or name in Search by email or name.
- Choose Find.
- Each match shows their current site, event, and MCP access, with the same controls as the main list.
Search covers every account, including people who have no access yet.
Add an organizer
- Under Add organizer, enter the person's email address.
- Choose Access: an event and role, such as ATA 2027 · Admin, or Site admin (all events).
- Choose Add.
The row appears under People with access, and every change is written to the audit log.
Add someone who hasn't signed up yet
Event access works before the person has an account. Their row says Invited, hasn't signed in yet until they sign in, and the access applies automatically when they do.
Use the address they will sign in with. It has to be the verified primary email on their account. When this page looks people up or saves their access, it ignores capital letters and spaces around the address, but nothing else, so ada.smith@example.com and ada_smith@example.com are different people here. See Known limits for how sign-in matches addresses.
Make someone a site admin
Site admin needs an existing account. If nobody has signed in with that email yet, the page says: "They need to sign in once with this email before they can be a site admin." Ask them to sign in once, then add them again.
Before anything changes, a confirm step spells out the scope: full access to every event and site settings. If more than one account has verified the same email, search for the person and use Make admin on the right row.
Change or remove access
- Change an event role. Choose Change next to the event, pick the new role, and choose Save role.
- Remove someone from an event. Choose Change, then Remove from event, and confirm. The membership is marked removed rather than deleted, so its history is kept and you can add the person again later.
- Revoke site admin. Choose Revoke in the Site column and confirm. You cannot revoke your own site admin access, and you cannot revoke the last remaining site admin; make someone else a site admin first.
- Turn MCP access on or off. Use the On/Off switch in the MCP column. The change takes effect immediately and does not affect normal sign-in.
If the page shows a warning
Site admin and MCP access are stored on each account, so the page reads every account to find them. It reuses that result for at most five minutes. After that, the page reads every account again before it shows the list. Changes made on this page, and Rescan accounts, start a fresh read right away. The five minutes are checked again at the moment the page is shown, so a list that passes five minutes old while the page loads is marked as possibly out of date instead of current.
- Showing access as of a time, and refreshing the account list failed. The saved list was more than five minutes old, and the identity provider did not answer when the page tried to refresh it. The page shows the older list with the time it was read, so changes since then, such as a site admin granted in the identity provider's dashboard, may be missing. Choose Rescan accounts to try again.
- This account scan took longer than 5 minutes. The identity provider answered slowly, so accounts read at the start of the scan may have changed before it finished. The page shows the list but doesn't treat it as current. Choose Rescan accounts to check again.
- This account list is more than 5 minutes old. The list was current when the page started loading, but it passed five minutes old before the page was shown, for example while the page looked up event team members. The page shows the list but doesn't treat it as current. Choose Rescan accounts to check again.
- Account scan exceeded its time budget. The scan stops after four minutes so the page doesn't wait on a slow identity provider, and the list may be missing site admins or MCP users. Choose Rescan accounts to try again, or search for a specific person.
- The account scan stopped at its safety limit. The installation has more accounts than one scan reads, so the list may be missing site admins or MCP users. The page says so instead of presenting a partial list as complete. Search for a specific person to check them.
- The account scan couldn't confirm it read every account. The identity provider returned a page of accounts the scan couldn't check, so the list may be missing site admins or MCP users. Choose Rescan accounts to try again, or search for a specific person.
- Couldn't read site admins and MCP access. The identity provider did not answer. Event team members still appear; reload to try again.
- Couldn't look up accounts for event team members. Some people may show as not signed in when they have. Reload to try again.
Known limits
- Literal email matching covers this page's lookups and changes only. When someone signs in, event access is still matched to their email with a case-insensitive comparison. Hardening how sign-in resolves event membership is being handled separately.
- Each server keeps its own copy of the account list. Right after a change, another server can still show its earlier list as current while that list is at most five minutes old. The age is checked when the page is shown, not only when the list is read, so an older list is always marked as possibly out of date.
- If two site admins revoke each other at the same moment, both revocations can succeed.