Users & Impersonation
Only admins can create user accounts. Admins and supervisors can add an existing Customer account to a company.
Browsing users
Open Users (opens in a new tab) to search the entire user pool. Each account has a platform-wide role: Customer, Supervisor, Admin, or Agent.
Customer access is not assigned on the user form. It comes from a separate company membership.
Creating a user
- Search Users for the email address first to avoid a duplicate account.
- Click Invite new user (opens in a new tab).
- Enter the user's Email and Name.
- Leave Active enabled if the user should be able to sign in.
- Choose the platform-wide Role:
- Customer — contractor owners and employees; access is limited by company memberships.
- Supervisor — CIC staff who work across companies and manage memberships and teams.
- Admin — full platform administration.
- Agent — CIC Assistant/call-handling account; it does not browse customer portal data.
- Choose the user's Time zone, or leave it blank for the portal default.
- Click Invite.
The portal creates the account and sends an invitation email. If it does not arrive, open the user's page and click Resend Invite. Creating a user does not add the user to a company.
Adding a Customer to a company
- Open the target Company and click Members.
- Click Add users.
- Find the existing Customer account and click Add.
- The new membership starts as Member. Click Edit role to change it to Owner when appropriate.
Only Customer accounts appear on the Add users page. The company role is separate from the user's platform role:
- Member grants regular access to that company's data.
- Owner additionally enables owner-only billing actions, such as managing the payment method for a billable company or organization, and receives relevant billing notices.
The same Customer can belong to several companies. Removing a membership revokes only that company's access; it does not disable the account. Follow Onboard a Company & User for the complete onboarding flow.
Editing and deactivating users
From a user's page, an admin can:
- Change name and email
- Change the platform role, active status, and time zone
- Resend an invitation that has not been accepted
- Open the companies and organizations available to a Customer
Changing an email triggers the account's confirmation flow. Role changes have broad access implications, so verify the intended role before saving.
Use Discard to deactivate an entire account. The user loses sign-in access, while the record remains available for audit and can be restored with Undiscard. Use Remove under Company → Members when only one company membership should end.
Password reset and 2FA controls for a signed-in user's own account are under Settings. There is no admin-side 2FA reset on the user management page.
Impersonating a user
Impersonation lets an Admin or Supervisor see the portal as an eligible Customer, Supervisor, or Agent account.
- Open the target user's page or row.
- Click Log in as.
- Reproduce the reported issue without making unrelated changes.
- Use Stop impersonating to return to the original session.
Do not use impersonation to bypass an access-control problem or act for a customer without authorization.
Audit trail
Audited records include Users, Companies, Organizations, Company memberships, inbound numbers, recordings, and related administrative changes. Where the UI displays record events, use them to identify who changed a field and when. Playbooks keep their own version history.
For queries not exposed by the UI, engineering can inspect the audit data directly.
Related
- Onboard a Company & User — company, user, and membership in one sequence
- Security — authentication and 2FA
- On-call Playbook — user-access incidents