Documentation

Reference

Explore Govform.com guidance, configuration details and practical steps for reference.

Library user settings

User management controls who can enter a library, design or comment on services, test in QA, view analytics, work with live data, deploy and administer the library. Open the library and select User management.

The list shows each registered email address, name or pending-sign-up status, access level and whether multifactor authentication is enabled.

Choose the narrowest access level

Access level Main capabilities Important limits
Administrator full design, live-data and environment access; library settings; add, remove and change users reserve for a small accountable group
Live data access design, test, analytics and deploy services, including Production live data and audit records cannot change library settings or manage users
Live data access for non-builders Production analytics, user data and audit records no Builder access
Designer + Analytics + QA deployments update designs, test, view analytics and deploy to QA cannot deploy or remove from Production, change library settings or manage users
Designer + Analytics update designs, test and view analytics cannot deploy or remove from QA or Production, change library settings or manage users
Read-only Designer + Analytics view designs, settings and analytics; add comments; test in QA cannot update designs, create or deploy services or change settings
External QA tester open and test QA services no Builder design or analytics access

Choose by task, not seniority. Someone who approves content may need read-only access, while a release engineer may need QA deployment without live-data access.

Add a user

  1. Select Add user.
  2. Enter the person’s full name.
  3. Enter the exact email address they will use to sign in.
  4. Choose whether to send an email invitation.
  5. Select the narrowest access level.
  6. Select Add user.
  7. Confirm the user appears with the intended role and MFA status.

Access becomes available immediately after the user is added; they may need to sign in or refresh their home page. A person awaiting account creation appears as pending in the list.

Verify the request through an approved channel before granting Administrator, Production deployment or live-data access. An email address alone does not prove authorisation.

Copy users from another library

Copy from library can reproduce an existing access set. Use it only when the source library genuinely has the same ownership and data-access model. Review every copied user and role before confirming; do not treat a convenient source library as a permanent access template.

Copying people does not transfer integration ownership, service-specific external permissions or credential access.

Change or remove access

Select a user’s email address to open their record. An administrator can change another user’s role and select Apply, or use the confirmed Remove this user from library action. A user cannot use this screen to alter their own access level.

Before removing someone, transfer ownership of releases, provider accounts, API keys, domains and support procedures. Removing library access does not revoke an external credential they know or an account in another system.

Maintain at least two appropriate administrators where the operating model requires continuity, but do not keep unnecessary administrator accounts merely as backups.

Manage multifactor authentication

The user record shows the MFA status. When a user with enabled MFA has a legitimate recovery problem, an administrator can select Reset MFA for another user. Verify the person’s identity before resetting and tell them that they must complete setup again.

The library-wide security setting can require MFA for Builder users. External QA testers have no Builder access and are not covered by that requirement.

Review access

Review the list regularly and on role change, departure, service transfer or incident. Look specifically for:

  • pending invitations that are no longer required;
  • administrators without a current ownership responsibility;
  • users with live-data access who need only design or QA access;
  • external testers retained after acceptance work ended;
  • accounts that have not completed required MFA setup.

Record who approved privileged access and when it will next be reviewed.

Related guides

Keep exploring

Explore more documentation

View all categories →