[{"data":1,"prerenderedAt":237},["ShallowReactive",2],{"\u002Fdocs\u002Fguide\u002Fadministration":3},{"id":4,"title":5,"body":6,"description":229,"extension":230,"meta":231,"navigation":232,"path":233,"seo":234,"stem":235,"__hash__":236},"docs\u002Fdocs\u002Fguide\u002Fadministration.md","Administration",{"type":7,"value":8,"toc":214},"minimark",[9,13,25,30,69,73,79,84,116,119,123,126,130,139,143,150,154,157,173,179,183,194,198],[10,11,5],"h1",{"id":12},"administration",[14,15,16,17,21,22,24],"p",{},"Users with the ",[18,19,20],"strong",{},"Admin"," role see an ",[18,23,20],{}," section in the sidebar. This page covers the tools you have there.",[26,27,29],"h2",{"id":28},"roles","Roles",[31,32,33,46],"table",{},[34,35,36],"thead",{},[37,38,39,43],"tr",{},[40,41,42],"th",{},"Role",[40,44,45],{},"Can do",[47,48,49,60],"tbody",{},[37,50,51,57],{},[52,53,54],"td",{},[18,55,56],{},"User",[52,58,59],{},"Use Delivr: connect mail accounts, read and send mail, manage their own settings and API keys.",[37,61,62,66],{},[52,63,64],{},[18,65,20],{},[52,67,68],{},"Everything a user can, plus manage all user accounts on the instance.",[26,70,72],{"id":71},"managing-users","Managing users",[14,74,75,78],{},[18,76,77],{},"Admin → Users"," lists every account on the instance with its role.",[80,81,83],"h3",{"id":82},"create-a-user","Create a user",[85,86,87,91,109],"ol",{},[88,89,90],"li",{},"Choose to create a new user.",[88,92,93,94,97,98,97,101,104,105,108],{},"Enter a ",[18,95,96],{},"username",", ",[18,99,100],{},"display name",[18,102,103],{},"email address",", and an initial ",[18,106,107],{},"password"," (at least 8 characters).",[88,110,111,112,115],{},"Choose the ",[18,113,114],{},"role",".",[14,117,118],{},"Share the credentials through a secure channel and ask the user to change the password after signing in.",[80,120,122],{"id":121},"edit-a-user","Edit a user",[14,124,125],{},"Change a user's username, display name, email address, or role. Role changes take effect immediately, including in sessions that are already signed in.",[80,127,129],{"id":128},"reset-a-password","Reset a password",[14,131,132,133,138],{},"Set a new password for a user who is locked out. This signs the user out of all sessions. Alternatively, if ",[134,135,137],"a",{"href":136},"\u002Fdocs\u002Fconfiguration#system-email-smtp","system email"," is configured, users can reset their password themselves from the sign-in page.",[80,140,142],{"id":141},"delete-a-user","Delete a user",[14,144,145,146,149],{},"Deleting a user signs them out everywhere, revokes their API keys, and removes their Delivr account together with everything stored for it: connected mail accounts and their encrypted credentials, sender identities and signatures, folder mappings, and preferences. ",[18,147,148],{},"Their mail is not affected"," — it stays on their mail servers.",[26,151,153],{"id":152},"what-administrators-can-see","What administrators can see",[14,155,156],{},"Delivr is designed so that even administrators can't read other people's mail through the app:",[158,159,160,167,170],"ul",{},[88,161,162,163,166],{},"Admins manage ",[18,164,165],{},"accounts",", not mailboxes. There's no feature to open another user's inbox.",[88,168,169],{},"Mail-account passwords are stored encrypted and are never shown in the interface or returned by the API.",[88,171,172],{},"Delivr stores no copies of emails, so there's nothing to browse in the database either.",[174,175,176],"note",{},[14,177,178],{},"Whoever operates the server holds the encryption key and has technical access to the database. If several people administer the server, make sure they're people you trust — as with any self-hosted service.",[26,180,182],{"id":181},"sign-ups","Sign-ups",[14,184,185,186,190,191,115],{},"By default, only admins can create accounts. Keep it that way for private instances: leave ",[187,188,189],"code",{},"NUXT_PUBLIC_IS_SIGNUP_ENABLED"," set to ",[187,192,193],{},"false",[26,195,197],{"id":196},"good-practice","Good practice",[158,199,200,203,206],{},[88,201,202],{},"Keep the number of admins small, and use a separate, non-admin account for your everyday mail if you like.",[88,204,205],{},"Remove accounts of people who leave your organization.",[88,207,208,209,213],{},"Review the ",[134,210,212],{"href":211},"\u002Fdocs\u002Fself-hosting\u002Fhardening","Production Hardening"," checklist from time to time.",{"title":215,"searchDepth":216,"depth":216,"links":217},"",2,[218,219,226,227,228],{"id":28,"depth":216,"text":29},{"id":71,"depth":216,"text":72,"children":220},[221,223,224,225],{"id":82,"depth":222,"text":83},3,{"id":121,"depth":222,"text":122},{"id":128,"depth":222,"text":129},{"id":141,"depth":222,"text":142},{"id":152,"depth":216,"text":153},{"id":181,"depth":216,"text":182},{"id":196,"depth":216,"text":197},"Administer a Delivr instance: manage user accounts and roles, reset passwords, and understand what administrators can and cannot see.","md",{},{"title":5},"\u002Fdocs\u002Fguide\u002Fadministration",{"title":5,"description":229},"docs\u002Fguide\u002Fadministration","esliA7OS5LZGdUarW1HbMTeh99TPgfFDBfFdFx_Ob7s",1791069427611]