Everyone who works in your Structurell subscription is a user. What each person can see and do depends on your package, whether they are a subscription administrator, and the permissions they hold directly or through groups. This article explains how those pieces fit together and how to manage people from **Account → Access → Users**.

## How access works

Three things decide what a person can do in Structurell.

- **Your package.** A feature only appears if your subscription's package or add-ons include it. If it isn't included, nobody in the subscription can use it, including administrators. See [Package and add-ons](/account-and-access/package-and-add-ons).
- **Subscription administrators.** A user with **Subscription Admin** turned on can administer the subscription: they can use every feature in your package and manage the pages under **Account**, such as **Users**, **Teams**, **Groups**, **Access Review**, **Domains**, **Connections** and **API Tokens**.
- **Permissions.** Everyone else gets access service by service. You can give permissions to a user directly, or to a group the user belongs to. A user's access is everything they hold directly plus everything from all of their groups.

Every subscription must always have at least one enabled subscription administrator. If a change would remove the last one, Structurell stops it with "A subscription must always have at least one enabled admin."

Groups and teams are different things. Groups grant permissions. Teams are named sets of people that other features point to, for example as reviewers, and they don't grant any access. Both are covered in [Teams and groups](/account-and-access/teams-and-groups).

## Understanding the permissions list

Users, groups and API tokens all use the same **Subscription permissions** list. It shows each service your subscription can use, with a **Choose access** list next to it.

- **No access** means this setting gives nothing in that service.
- **View**, **Create**, **Edit**, **Delete** and **Manage** give one level of access across the service. Only the levels that apply to that service are shown.
- **Full access** gives every action in the service. Simple features show **Allowed** instead.
- Select **Advanced** to set a different level for each feature inside the service, and **Hide advanced** to collapse it again. When features in a service have different levels, the service shows **Current access**.

Two rules keep this safe:

- You can only give access that you have yourself. Services and features you can't use don't appear in the list.
- If someone already has access that you aren't allowed to manage, it shows with **(locked)** after it. You can't change it, and Structurell keeps it when you save.

## Before you start

To open **Account → Access → Users** you need to be a subscription administrator, or have been given permission to manage subscription users. Only subscription administrators see the **Subscription Admin** setting and can change which groups someone belongs to.

## Add a user

1. Go to **Account → Access → Users** and select **New**.
2. In **General**, enter the person's **Email Address**.
3. If they should administer the subscription, turn on **Subscription Admin**.
4. In **Subscription permissions**, choose the access they need for each service.
5. In **Groups**, select any **Subscription groups** they should join. Selected groups are highlighted.
6. Select **Save**.

What happens next depends on whether the person already has a Structurell login:

- **They're new to Structurell.** Structurell creates a login for them and emails them "Finish setting up your Structurell account". They select **Finish account setup**, choose a password, and can then sign in. The link works for 14 days. If it has expired, the page it opens offers **Email me a new link**, so they can get a fresh one themselves.
- **They already use Structurell.** They're added to your subscription straight away and can switch to it. See [Creating or switching subscriptions](/getting-started/creating-or-switching-subscriptions).

You can also invite someone by email and let them accept the invitation themselves. See [Invites and access requests](/account-and-access/invites-and-access-requests).

## Change a user's access

1. Go to **Account → Access → Users**.
2. Select **Edit** next to the user.
3. Update **Subscription Admin**, **Subscription permissions** or **Groups**.
4. Select **Save**.

To change only someone's groups, open the menu next to their **Edit** button and select **Groups**. In **Groups for** followed by their name, tick the groups they belong to and select **Save**. You'll see "Groups updated."

Remember that a user also gets everything their groups allow. If someone still has access after you remove a permission, check which groups they belong to, or use [Access review](/account-and-access/access-review).

## Remove a user

1. Go to **Account → Access → Users**.
2. Open the menu next to the user's **Edit** button and select **Remove**.
3. Confirm when asked "Are you sure you want to remove this user from this subscription?"

This removes the person's access to your subscription. To remove several users at once, select them in the list and choose **Delete** under **Deletion** in the bulk actions.

## Troubleshooting

- **A user can't see a feature.** Check that the feature is in your package, then check the user's permissions and their groups.
- **You can't see the Subscription Admin setting or the Groups option.** Only subscription administrators can change these.
- **A service is missing from the permissions list.** You can only grant access you have yourself. Ask a subscription administrator to make the change.
- **You can't remove someone or turn off their admin access.** They may be the last enabled administrator. Make someone else an administrator first.

## Related articles

- [Teams and groups](/account-and-access/teams-and-groups)
- [Invites and access requests](/account-and-access/invites-and-access-requests)
- [Access review](/account-and-access/access-review)