- Docs
- Users and Access
Sub-users
What a sub-user is, how to add one, what the seat counter means, and why every account starts with a system-managed default user.
Last updated
A sub-user is a proxy identity: a username and password your tools authenticate with, plus a set of products it may use. They exist so that one account can hold several identities without sharing one credential everywhere.
The sub-user list is on /dashboard/subusers, and also on each active product page's Users tab.
Why use them
Three reasons, in order of practical importance.
Isolation. A tool, a colleague or a client gets its own credential. Revoking one does not disturb the others.
Attribution. Usage per sub-user shows which job is consuming traffic.
Allocation. Traffic can be reserved for a specific sub-user so a busy job cannot consume another's share. See Traffic Allocation.
The seat counter
The page shows seats used against seats available, in the form used/total, for example 2/50. The total is the maximum number of sub-users the account may hold. Creating one consumes a seat; deleting one frees it.
The default user
Every account has a sub-user named default. It is created and maintained by the system rather than by you.
- It holds access to every product the account is entitled to.
- It cannot be deleted.
- It counts toward the seat total like any other user.
It exists so that a new account always has a working credential, before you have configured anything. You can use it, but most people create a named sub-user per job so that usage is attributable and revocable.
Adding a sub-user
- Open
/dashboard/subusers, or the Users tab on a product page. - Select Add new.
- Give the sub-user a name.
- Select which services it may access.
- Confirm.
Two notes on step 4.
- On the account-wide page you choose from all the services the account is entitled to.
- On a product page, creation is scoped to that product, so the service is pre-selected and cannot be added elsewhere.
Newly created sub-users appear immediately and may briefly show as still provisioning, during which they are disabled for endpoint generation.
Where the sub-user appears
Once created, a sub-user can be selected as the Proxy username in the Endpoint Generator, which is what makes its credentials usable in an endpoint.