[{"data":1,"prerenderedAt":384},["Reactive",2],{"navigation":3,"/features/users-and-permissions":118,"/features/users-and-permissions-surround":381},[4,14,43,83,99],{"title":5,"_path":6,"children":7},"Welcome","/welcome",[8,11],{"title":9,"_path":10},"Feature List","/welcome/feature-list",{"title":12,"_path":13},"FAQs","/welcome/faqs",{"title":15,"_path":16,"children":17},"Getting Started","/getting-started",[18,19,22,25,28,31,34,37,40],{"title":15,"_path":16},{"title":20,"_path":21},"Pre-requisites","/getting-started/prerequisites",{"title":23,"_path":24},"Installation","/getting-started/installation",{"title":26,"_path":27},"Upgrading","/getting-started/upgrading",{"title":29,"_path":30},"Configuration","/getting-started/configuration",{"title":32,"_path":33},"DNS configuration","/getting-started/dns-configuration",{"title":35,"_path":36},"Upgrading to v3","/getting-started/upgrade-to-v3",{"title":38,"_path":39},"Upgrading to v2","/getting-started/upgrade-to-v2",{"title":41,"_path":42},"The postal command","/getting-started/postal-command",{"title":44,"_path":45,"children":46},"Features","/features",[47,50,53,56,59,62,65,68,71,74,77,80],{"title":48,"_path":49},"Click & Open Tracking","/features/click-and-open-tracking",{"title":51,"_path":52},"Health & Metrics","/features/health-metrics",{"title":54,"_path":55},"IP Pools","/features/ip-pools",{"title":57,"_path":58},"Logging","/features/logging",{"title":60,"_path":61},"Mail Server Settings","/features/mail-server-settings",{"title":63,"_path":64},"OpenID Connect","/features/oidc",{"title":66,"_path":67},"Routing Incoming E-Mail","/features/routing-incoming-email",{"title":69,"_path":70},"Sending Domains","/features/sending-domains",{"title":72,"_path":73},"SMTP Authentication","/features/smtp-authentication",{"title":75,"_path":76},"SMTP TLS","/features/smtp-tls",{"title":78,"_path":79},"Spam & Virus Checking","/features/spam-and-virus-checking",{"title":81,"_path":82},"Users & Permissions","/features/users-and-permissions",{"title":84,"_path":85,"children":86},"Developer","/developer",[87,90,93,96],{"title":88,"_path":89},"Using the API","/developer/api",{"title":91,"_path":92},"Client Libraries","/developer/client-libraries",{"title":94,"_path":95},"Receiving e-mail by HTTP","/developer/http-payloads",{"title":97,"_path":98},"Webhooks","/developer/webhooks",{"title":100,"_path":101,"children":102},"Other Notes","/other",[103,106,109,112,115],{"title":104,"_path":105},"Auto-Responders & Bounces","/other/auto-responders-and-bounces",{"title":107,"_path":108},"Our container image","/other/containers",{"title":110,"_path":111},"Debugging","/other/debugging",{"title":113,"_path":114},"Wildcards & Address Tags","/other/wildcards-and-address-tags",{"title":116,"_path":117},"Workers & Background Tasks","/other/workers-and-background-tasks",{"_path":82,"_dir":119,"_draft":120,"_partial":120,"_locale":121,"title":81,"description":122,"category":44,"body":123,"_type":376,"_id":377,"_source":378,"_file":379,"_extension":380},"features",false,"","Global administrators, organization members and what each can do.",{"type":124,"children":125,"toc":370},"root",[126,134,141,146,219,224,253,258,264,276,288,299,305,346,364],{"type":127,"tag":128,"props":129,"children":130},"element","p",{},[131],{"type":132,"value":133},"text","Postal has a simple permission model with two kinds of user.",{"type":127,"tag":135,"props":136,"children":138},"h2",{"id":137},"global-administrators",[139],{"type":132,"value":140},"Global administrators",{"type":127,"tag":128,"props":142,"children":143},{},[144],{"type":132,"value":145},"Administrators have full access to every organization, server and setting in the installation. They are the only users who can:",{"type":127,"tag":147,"props":148,"children":149},"ul",{},[150,164,169,181,194,214],{"type":127,"tag":151,"props":152,"children":153},"li",{},[154,156,162],{"type":132,"value":155},"See and manage ",{"type":127,"tag":157,"props":158,"children":159},"strong",{},[160],{"type":132,"value":161},"all",{"type":132,"value":163}," organizations (non-admins only see organizations they have been added to).",{"type":127,"tag":151,"props":165,"children":166},{},[167],{"type":132,"value":168},"Create and delete organizations.",{"type":127,"tag":151,"props":170,"children":171},{},[172,174,179],{"type":132,"value":173},"Manage users (",{"type":127,"tag":157,"props":175,"children":176},{},[177],{"type":132,"value":178},"Users",{"type":132,"value":180}," in the top navigation): create users, edit their details, grant or revoke admin status and choose which organizations a non-admin user belongs to. An administrator cannot remove their own admin status or delete their own user.",{"type":127,"tag":151,"props":182,"children":183},{},[184,186,192],{"type":132,"value":185},"Manage ",{"type":127,"tag":187,"props":188,"children":189},"a",{"href":55},[190],{"type":132,"value":191},"IP pools",{"type":132,"value":193},", IP addresses and organization pool assignments.",{"type":127,"tag":151,"props":195,"children":196},{},[197,199,204,206,212],{"type":132,"value":198},"Change a server's ",{"type":127,"tag":157,"props":200,"children":201},{},[202],{"type":132,"value":203},"Advanced Settings",{"type":132,"value":205}," (send limit, allow sender header, privacy mode, SMTP data logging, outbound spam threshold and retention) and suspend or unsuspend servers. See ",{"type":127,"tag":187,"props":207,"children":209},{"href":208},"/features/mail-server-settings#advanced-settings-administrators-only",[210],{"type":132,"value":211},"Mail server settings",{"type":132,"value":213},".",{"type":127,"tag":151,"props":215,"children":216},{},[217],{"type":132,"value":218},"Add domains without verifying them - domains added by an administrator are marked as verified immediately.",{"type":127,"tag":128,"props":220,"children":221},{},[222],{"type":132,"value":223},"The first administrator is created from the command line during installation with:",{"type":127,"tag":225,"props":226,"children":230},"pre",{"className":227,"code":228,"language":229,"meta":121,"style":121},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","postal make-user\n","bash",[231],{"type":127,"tag":232,"props":233,"children":234},"code",{"__ignoreMap":121},[235],{"type":127,"tag":236,"props":237,"children":240},"span",{"class":238,"line":239},"line",1,[241,247],{"type":127,"tag":236,"props":242,"children":244},{"style":243},"--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B",[245],{"type":132,"value":246},"postal",{"type":127,"tag":236,"props":248,"children":250},{"style":249},"--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D",[251],{"type":132,"value":252}," make-user\n",{"type":127,"tag":128,"props":254,"children":255},{},[256],{"type":132,"value":257},"This prompts for an e-mail address, first name, last name and password, and always creates an administrator. Run it again at any time to create additional administrators, for example if you have locked yourself out.",{"type":127,"tag":135,"props":259,"children":261},{"id":260},"organization-users",[262],{"type":132,"value":263},"Organization users",{"type":127,"tag":128,"props":265,"children":266},{},[267,269,274],{"type":132,"value":268},"Everyone else is an ordinary user who belongs to one or more organizations. Within an organization they have full access to ",{"type":127,"tag":270,"props":271,"children":272},"em",{},[273],{"type":132,"value":161},{"type":132,"value":275}," of its mail servers and domains - there is no per-server or read-only access. This includes creating and deleting servers, managing domains, routes, endpoints, credentials, webhooks and the non-admin server settings, and viewing every message.",{"type":127,"tag":128,"props":277,"children":278},{},[279,281,286],{"type":132,"value":280},"Organizations record which user created them as the ",{"type":127,"tag":157,"props":282,"children":283},{},[284],{"type":132,"value":285},"owner",{"type":132,"value":287},", but this does not currently grant any additional permissions.",{"type":127,"tag":128,"props":289,"children":290},{},[291,293,297],{"type":132,"value":292},"Users are added to organizations by an administrator from the ",{"type":127,"tag":157,"props":294,"children":295},{},[296],{"type":132,"value":178},{"type":132,"value":298}," page: edit the user and tick the organizations they should be able to access. Removing the last organization from a non-admin user leaves them able to log in but with nothing to see.",{"type":127,"tag":135,"props":300,"children":302},{"id":301},"accounts-and-passwords",[303],{"type":132,"value":304},"Accounts and passwords",{"type":127,"tag":147,"props":306,"children":307},{},[308,313,334],{"type":127,"tag":151,"props":309,"children":310},{},[311],{"type":132,"value":312},"Users log in with their e-mail address and password. Passwords must be at least 8 characters long.",{"type":127,"tag":151,"props":314,"children":315},{},[316,318,324,326,332],{"type":132,"value":317},"Password resets are available from the login page and are sent using the ",{"type":127,"tag":232,"props":319,"children":321},{"className":320},[],[322],{"type":132,"value":323},"smtp",{"type":132,"value":325}," section of the Postal configuration, so make sure that is set up (you can test it with ",{"type":127,"tag":232,"props":327,"children":329},{"className":328},[],[330],{"type":132,"value":331},"postal test-app-smtp",{"type":132,"value":333},").",{"type":127,"tag":151,"props":335,"children":336},{},[337,339,344],{"type":132,"value":338},"From ",{"type":127,"tag":157,"props":340,"children":341},{},[342],{"type":132,"value":343},"My Settings",{"type":132,"value":345}," a user can change their name, e-mail address, time zone and (after confirming their current password) their password. Times throughout the interface are shown in the user's time zone, which defaults to UTC.",{"type":127,"tag":128,"props":347,"children":348},{},[349,351,355,357,363],{"type":132,"value":350},"If ",{"type":127,"tag":187,"props":352,"children":353},{"href":64},[354],{"type":132,"value":63},{"type":132,"value":356}," is enabled, users can be created without a password and are linked to their identity provider account on first login. Local logins can be disabled entirely with ",{"type":127,"tag":232,"props":358,"children":360},{"className":359},[],[361],{"type":132,"value":362},"oidc.local_authentication_enabled: false",{"type":132,"value":213},{"type":127,"tag":365,"props":366,"children":367},"style",{},[368],{"type":132,"value":369},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":121,"searchDepth":371,"depth":371,"links":372},2,[373,374,375],{"id":137,"depth":371,"text":140},{"id":260,"depth":371,"text":263},{"id":301,"depth":371,"text":304},"markdown","content:3.features:users-and-permissions.md","content","3.features/users-and-permissions.md","md",[382,383],{"_path":79,"title":78,"description":121},{"_path":89,"title":88,"description":121},1789749433810]