User management

User management

Synchronize employees from your identity provider, control enrollment, manage groups and roles, and review communication settings.

Reviewed Sep 30, 2026 · Product

Overview

elba synchronizes employee and group information from your connected identity provider. Enrollment lets you choose which synchronized employees participate in the member experience and employee-facing security workflows.

Open the Users page for your region:

Before enrolling employees, complete Communication Preferences. elba disables enrollment actions when required communication settings are missing.

Understand the user list

The Users table can show each employee's:

  • Name and email address
  • Admin role, if assigned
  • Groups and manager
  • Notification channel
  • Enrollment status
  • Member-portal activity or join date

Use the search and filters to find employees by name, email, group, enrollment status, member activity, or communication preference.

Enroll or unenroll an employee

To update one employee:

  1. Open Settings → Team → Users.
  2. Find the employee and open the row actions.
  3. Select Enroll user or Unenroll user.
  4. Review the confirmation before applying the change.

To update several employees, select their rows and use the bulk action bar. The same bar can send invitation reminders to eligible employees and set their communication channel.

In elba, the owner and admins cannot be unenrolled, because an unenrolled user can no longer sign in: not from the Users table, a bulk action or a group change. To unenroll an admin, first select Demote to member, then unenroll them. When a bulk selection includes admins, only the other users are unenrolled. Removing someone from your identity provider still removes them from elba, admins included.

Manage enrollment with groups

Group enrollment is useful when participation should follow identity-provider group membership.

  1. Open Settings → Team → Groups.
  2. Find the group and change its status to Enrolled.
  3. Confirm the change.

Enrolling a group enrolls its current members. A synchronized user added to an enrolled group is also enrolled. When a user is removed from an enrolled group, elba keeps them enrolled if they still belong to another enrolled group; otherwise, elba unenrolls them. The owner and admins always stay enrolled.

Review group membership carefully before unenrolling a group because the change can affect many employees. The owner and admins in the group stay enrolled. Identity-provider groups continue to follow their source memberships after synchronization.

You can also open an employee's row actions and select Manage groups. This lets you add or remove the employee from groups available in elba.

Manage admin roles

From an enrolled employee's row actions, authorized admins can:

  • Promote a member to admin
  • Demote an admin to member
  • Transfer organization ownership to an eligible admin

Role changes affect access to administrative capabilities. Confirm the employee's responsibilities and apply your organization's least-privilege process before changing a role.

Manage notification channels

The Notification channel column shows where each employee receives elba messages. An option such as Default (Slack) means the employee follows the organization default channel set in Communication Preferences. Default (not set up) means your organization has not saved a default channel yet: these employees receive no automated messages until it does or until they choose their own channel. Employees can also choose their own channel from the member portal.

  • For one employee, select a channel in their Notification channel column.
  • For several employees, select their rows, choose Set communication channel, pick a channel, and select Apply.
  • To find employees by channel, use the Communication preference filter. Choose the Default option to list employees who follow the organization default.

The choices are the organization default, Email, and each connected Slack, Microsoft Teams, or Google Chat integration. Unavailable or disconnected chat channels cannot be newly selected. When elba cannot reach an employee on their channel, it uses the organization default, then email. See Members and Sam for delivery behavior and reminder settings.

After a user or group change:

  1. Confirm that the expected users show the correct enrollment status.
  2. Check that manager and group information match the identity provider.
  3. Verify the notification channel for users who need employee-facing actions.
  4. Review the Security leaderboard after relevant activity is available.

Troubleshooting

Enrollment controls are disabled

Complete the required Communication Preferences, then return to the Users or Groups page.

A user is missing or has outdated profile data

Check the employee in the connected identity provider and allow the workspace synchronization to complete. Identity-provider profile and group data should be corrected at its source.

A user becomes enrolled again

Check whether they belong to an enrolled group. Membership in an enrolled group causes elba to enroll the user.

A former employee still has application access

Unenrollment controls the elba member experience; it does not guarantee that accounts in connected applications have been revoked. Use your authoritative offboarding process and review Identity and access reviews for supported account-review workflows.

On this page