Users (admins)
Sign-in works only for addresses listed here. Add people before they try.
The Contact column reads regular → emergency channel; the mobile is in the tooltip.
Adding a user
+ Add user at the top right: email, entity, role, and how broadcasts reach them — an optional mobile, a regular channel and an emergency channel (email, SMS, both, or do not notify). Anyone who signs in also sees broadcasts in the tool; a contact only gets what their channels say. The entity decides what they see (see Entities). No email is sent — tell them to sign in. People change their own details from their name in the rail.
Editing a user
Edit… on a row opens the same facts for one person: name, email, entity, role, mobile, and the regular and emergency channels. Changing the email means they sign in with the new address next time; open sessions carry on. Moving someone to another entity changes what they see at once. A mobile you enter isn't verified until the person verifies it themselves. You can't change your own role. The role can also be changed straight from the row. Every change is an audit event.
Roles
| Role | Can |
|---|---|
| junior operator | Work cases like an operator, but every response they write must be approved by an operator or admin before it sends |
| operator | Work cases, send responses, review others' drafts |
| admin | Everything, plus assignments, users, entities, library approval, broadcasts |
| contact | Nothing in the tool — a person at the entity who receives its broadcasts and never signs in: an on-call engineer, an IT manager |
An admin for a non-OPN entity manages that entity's users only.
Sign-in method and MFA
The Sign-in column shows how the person signs in — Google or a sign-in link — and their second factors (passkeys, authenticator apps), which everyone must have. Reset access removes all of them and their recovery codes, ends their sessions, and clears any sign-in lock or throttle counted against them; the person sets up a new second factor at their next sign-in. For a lost device, a locked second factor, or an address that asked for too many links.
Sessions and tokens
End closes all of a user's sessions now. The tokens column counts their active tokens and links to User tokens, where any user's tokens can be revoked. Deactivate ends sessions, stops tokens, and leaves the user's assigned cases assigned until you reassign them.