Northstar CloudKnowledge Base
Fictional product · Documentation portfolio by Eliza Lenz

Users and Teams

Roles and Permissions

Every user has one organization role. That role applies throughout Northstar Cloud. Team membership does not add permissions or restrict the role’s access.

RoleScope
OwnerManages users, teams, reports, organization settings, and authentication. Can assign or remove the Owner role.
AdministratorManages other Administrators and Members, teams, and reports. Cannot administer Owners or organization authentication.
MemberManages their own profile, security, and notifications and views their own team memberships.

Compare Permissions

CapabilityOwnerAdministratorMember
View own profile and membershipsYesYesYes
Change own name and notificationsYesYesYes
View user directory and all teamsYesYesNo
Invite as Administrator or MemberYesYesNo
Resend or revoke invitationsYesYesNo
Create and Manage TeamsYesYesNo
View roles reference and reports; export CSVYesYesNo
Edit organization settingsYesNoNo
Configure SSO and MFA policyYesNoNo

Permissions for Account Changes

The following actions apply to other users. You cannot change your own role, deactivate yourself, or administratively reset your own multi-factor authentication (MFA).

ActionOwnerAdministrator
Change Member to Administrator or reverseYes, for Active usersYes, for Active users
Assign or remove OwnerYes, for Active usersNo
Deactivate or reactivate an Administrator or MemberYesYes
Deactivate or reactivate another OwnerYes, with Owner safeguardsNo
Reset local MFAOther usersOther Members only

Ownership Safeguards

An organization must always have at least one active Owner. Northstar blocks changes that would remove the last active Owner. Invitations can assign only Administrator or Member; an Owner can promote a user after activation.

Roles cannot be changed for Invited or Deactivated accounts. Role and status changes end the affected user’s sessions. Unauthorized actions are hidden; temporarily unavailable actions are disabled with an explanation.

Personal MFA and Single Sign-On

Owners and Administrators must use local MFA for password sign-in and cannot disable it. Members may disable local MFA only when organization policy allows it. With single sign-on (SSO), MFA is managed by the identity provider.

Even when SSO is required, Owners retain password sign-in with local MFA as a recovery route.

Related guides: Manage Users; Configure SSO; Configure MFA.