Skip to main content

Manage Users

Organization admins can manage users and their roles from the Admin section of the Tenzo app.
  • Navigate to Admin > Organization & Users > Manage Users.
On this page you can:
  • View all users in your organization, along with their name, email, role, and status.
  • Invite new users to Tenzo.
  • Update user roles to control access levels.
  • Allow specific users to sign in with email and password when the organization uses SSO.
  • Deactivate or reactivate user accounts as needed.
User management page showing organization users, roles, and statuses

Admin > Organization & Users > Manage Users (PII Redacted)

User Roles and Access

Each user is assigned a role which controls what they can see and do in Tenzo. The main roles are:
  • Limited Access User: By default has no access to jobs, but can be added to specific jobs or folders with elevated permissions as needed.
  • Global Viewer: Can view all jobs in the organization, including exporting candidates and using Chat Assistant, but cannot manage candidates, change configurations, or change settings.
  • Global Editor: Can edit all jobs in the organization, including interview configurations and templates, and can manage candidates on every job.
  • Global Admin: Has full access to org-wide settings, integrations, and user management. Only Global Admins can remove (delete) candidates from a job, and the Restart Workflow control is available to Global Admins only.
You can adjust a user’s role from the Manage Users page using the role selector in the user row.

Access Levels Explained

Access to a job is made up of three levels, each one building on the last:
  • View — See the job, its configuration, and its candidates. On the job’s Candidates tab you can export a selection to CSV and use Chat Assistant. This is the baseline level included in every other access level.
  • Manage Candidates — Everything in View, plus the ability to act on the job’s candidates:
    • Add candidates
    • Edit candidate info and AI summaries
    • Use sourcing
    • Give thumbs up / thumbs down feedback on calls
    • Pause and resume candidates
    • Approve or reject candidate-submitted interview re-issue requests
  • Editor — Everything in Manage Candidates, plus the ability to edit the job (or folder) itself, such as its configuration, interview questions, and templates.
Removing (deleting) candidates from a job is restricted to users with the Global Admin role, and the Restart Workflow control is likewise available to Global Admins only. Users with Manage Candidates access can still approve or reject candidate-submitted interview re-issue requests. The Remove and Restart Workflow controls are disabled for non-admin candidate managers and explain that an admin is required. A Viewer has View access only, so Manage Candidates is off and Viewers cannot perform any of the Manage Candidates actions above. An Editor always has Manage Candidates included automatically. Manage Candidates can also be granted on its own, without Editor access, for users who need to work with a job’s candidates but shouldn’t edit the job’s configuration.

Inviting New Users

To invite a new user:
  1. Go to Admin > Organization & Users > Manage Users.
  2. Click Invite User.
  3. Enter the user’s name and email, choose an appropriate role, and send the invitation.
Invite user modal showing role options

Admin > Organization & Users > Invite User

Invited users will receive an email with instructions to set up their account and sign in.

Allowing Email and Password Sign-In

If your organization uses SSO, everyone signs in through your identity provider by default. Use this exception for contractors, partners, or anyone who is not in that identity provider. To allow a user to sign in with email and password:
  1. Go to Admin > Organization & Users > Manage Users.
  2. Open Edit User for that person.
  3. Turn on Allow email and password sign-in.
  4. Save the change.
This control only appears when the organization uses SSO. Organizations that sign in with email and password do not see it — that is already how everyone logs in. You can also turn this on when inviting a user. After it is enabled, they sign in with their email and password instead of SSO. If they do not have a password yet, they can set one with Forgot password on the login page. This is an allowlist: it does not change how anyone else in the organization signs in.

Granting Access to Specific Jobs and Folders

Even if a user only has Limited Access or Viewer permissions at the organization level, you can grant them elevated access on a per-job or per-folder basis.
  • From the Jobs dashboard, open the action menu (...) for a job or folder and choose Share.
  • Select the user and choose the appropriate permission level, then click Share:
    • Viewer — View access only, as described above.
    • Editor — View, edit, and Manage Candidates access, as described above.
Share menu opened from a job or folder

Jobs > Share job or folder

Share job modal for granting viewer or editor access

Jobs > Share job

Note: When you share a folder with a user, that user is granted access to all jobs and subfolders contained within that folder.