User management lets institution administrators control who can access EFI and what they can see. Use this page to invite new team members, adjust their permissions, or remove users who no longer need access.
Inviting a New User
Click Add new to open the invitation form. EFI sends an email to the new user with instructions to set their password and log in.
Choosing a Role
The Role dropdown sets the starting point for the permission cards on the right:
| Role | Behavior |
|---|---|
| Admin | Every permission card is switched on and all counterparty segments are granted. Switching any card off afterwards turns the role into Custom role. |
| Custom role | All cards start off; switch on the ones the user needs. A Read-only access toggle appears below the dropdown. When it is on, the user can view whatever the cards grant but cannot create, edit or delete anything. |
Setting Permissions
Three cards control what the user can reach:
- Data: uploading data files to EFI.
- Institution Report: your own institution's risk report.
- Counterparties: the counterparty reports, limited to the segments ticked under Grant access to the selected segments. Switching the card on ticks every segment; untick the ones the user should not see. Unticking all of them switches the card off again.
Access is granted per area, not per risk theme: a user with Institution Report sees the whole report, and there is no way to hide individual themes from this dialog.
At least one card must be on unless Read-only access is enabled; otherwise Save is refused with "No permission selected".
When you edit an existing user, the form opens with their current role and cards. Permissions the user holds that are not shown here (such as the case management permission below) are left untouched. A user who already holds the Admin role keeps it even if you change the dropdown to Custom role; ask Elucidate if an administrator needs to be downgraded.
Case management permissions
Some ticket actions (changing the due date, priority, assignee or progress, whitelisting a screened name, downloading the audit PDF) require a remediation-write permission that this dialog does not offer. Elucidate provisions it on request. Users without it can still open tickets, comment, attach files and close or reopen them, but those fields are read-only for them. Even with it, a user can only edit tickets owned by their own institution or by an institution that is a portfolio member of it.
Managing Existing Users
Each user row shows the person's name, email and their current permissions at a glance: the enabled cards, Segments followed by the segment names a Counterparties user can see, and an amber Read-only badge when read-only access is on. For users other than yourself, a Manage dropdown offers three actions:
- Edit — Reopen the permissions form to change the user's role or access levels
- Change password — Sends a password reset email to the user
- Delete — Permanently removes the user from the institution after confirmation
You cannot manage your own account from this page — this prevents accidentally locking yourself out. Contact another administrator if you need your own permissions changed.