Where users come from
User profiles arrive from your connected systems or are created as part of an onboarding or access request, so the user list always reflects who actually exists in your organization.- Directory integrations. Most users arrive through your HRIS, an identity provider such as Google Workspace or Microsoft 365, or Slack. AccessOwl syncs with your directories regularly and keeps statuses and attributes such as the manager up to date. The icons next to each user’s name on the Users page show which connected directories the user exists in. A user usually exists in several of them, and the Source Priority ranking decides which one sets the name and email and which ones fill in the remaining attributes.
- Onboarding. Starting a user onboarding via Slack or the Onboard User button on the Users page creates the profile as part of the flow. This also works for someone who has no account in any connected directory, for example when their email domain is not connected through Google Workspace or Microsoft Entra ID.
- External users. For contractors and other people outside your organization, type their full email address in an access request. This creates the user in AccessOwl without adding them to any of your directory workspaces. See Onboarding Contractors and External Users.
Directory users are owned by their directories, not by AccessOwl. On every sync, name and email are taken from the system with the highest priority. An edit made in AccessOwl is accepted at first, then overwritten by the next sync. If a value keeps coming back, change it in that system instead. A user who is inactive in the directory stays inactive in AccessOwl.
User attributes
Beyond name and email, user profiles carry attributes such as job title, department, employment type, and manager. With an HRIS integration, these attributes are imported and kept in sync automatically, and they appear as sortable columns on the Users page.Actions on the Users page
From the page header you can- Sync Directories to trigger a directory sync on demand instead of waiting for the next scheduled one.
- Export the user list as a CSV, for example for audits or reporting.
- Onboard User to start a user onboarding.
Actions on a user profile
Open a user from the Users page to see their profile with their applications, requests, and revocations. From the top of the profile you can- Edit the user’s attributes, for example to overwrite the manager.
- Scan now to run a Shadow IT discovery scan for the user.
- History to review the full history of the user’s access and status changes.
- Reactivate an offboarded user who returns. See how to onboard a previously offboarded employee.
- Show Requests and Show Revocations to jump to the user’s access requests and revocations.
- Merge… to consolidate two profiles that belong to the same person. See Merge Duplicate User Profiles.
- Offboard… to revoke the user’s access. See User Offboarding.
- Depending on the user’s status, situational actions such as Cancel Offboarding for a scheduled offboarding or Retrigger onboarding.
There is no delete action on a user profile. AccessOwl keeps every user’s record for audit purposes. See User Deletion for the reasoning and what to do instead.
FAQ
Where do I see which role a person holds in each application?
Where do I see which role a person holds in each application?
A user profile shows which applications the person has access to and the status of each access. It does not show the permission level they hold inside the application, so the profile alone cannot answer “which apps is this person an admin in?”. Two routes do.
- Accesses report. Go to the Reports tab in the admin interface and export the accesses report to CSV. Each row is one access and carries the permission level plus a flag for elevated access, so you can filter down to admin-level permissions per person or per application. See How do I export a list of applications and who has access to them?
- Ask Claude in Slack. “What does Maria have access to?” returns her applications and roles as a table, and “Who has admin permissions in Datadog?” answers the same question from the application side. See Claude workflows.

