User management, or “Manage Users”, is the administrative module for adding, configuring, and managing user accounts within a Docupath tenant. It governs the invitation workflow, role assignment, and organization-level user scoping - determining who can access the platform, what actions they can perform, and which documents they can see.
Docupath uses role-based access control (RBAC) with five defined roles, and supports organization assignment to further restrict document visibility for document-centric roles.
The Filters button at the top right of the Manage users page narrows the user list by organization and by user role. See Filtering Users by Organization and Role.
How It Works
Adding Users
New users are added by administrators through Main Menu → Manage Users:
Click Add Users
Provide the user's Name, Email, and Role
Optionally assign one or more Organizations (for Reviewer, Validator, Reviewer and Validator, and Custom users)
Select one or more modules allowed to access (for Custom users only)
Save - Docupath sends an email invitation to the user
Until the user accepts the invitation, their status shows as Pending Invite. If the invitation is not received, the admin can resend it or check spam/junk folders.
Editing Users
On the Manage Users page, click the edit (pencil) icon on the user's row in the Actions column. The Edit user dialog opens.
Update the user's Name or Role as needed. The Email field cannot be changed.
Click Save to apply your changes, or Cancel to discard them.
Deleting Users
On the Manage Users page, click the delete (trash) icon on the user's row in the Actions column.
Confirm the deletion when prompted.
You cannot delete your own account. The delete icon is disabled on the row marked YOU.
User Roles in Docupath
Docupath provides five roles, each tailored to specific responsibilities:
Role | Capabilities |
Docupath Admin | Full access to all system settings, documents, user management, and integrations |
Docupath Manager | Broad platform visibility including monitoring workflows and usage insights; no access to Instruction Builds |
Docupath Reviewer | Reviews documents, makes field edits, and decides to approve or reject |
Docupath Validator* | Can edit and validate documents but cannot approve or reject them |
Docupath Reviewer and Validator* | Combines Reviewer and Validator capabilities for full document handling |
Custom* | Customizable role for various organizational and team requirements |
Organization Assignment
For document-centric roles (Reviewer, Validator, Reviewer and Validator, Custom), users can be mapped to specific organizations:
With Self-Service Access enabled: Users see only documents they uploaded or those assigned to their mapped organization
With Self-Service Access disabled: Users follow standard visibility rules based on their role
Unmapped non-admin users: See all non-self-service organizations
Admin users: See everything, including self-service organizations
Least-Privilege Principle
Docupath recommends starting users at the most restrictive appropriate role (Reviewer or Validator) and only escalating to Manager or Admin when the broader access is required.
This minimises security risk and maintains a clear separation of duties.
Supported Configurations and Options
Configuration | Detail |
Roles | Admin, Manager, Reviewer, Validator*,* Reviewer and Validator, Custom |
User fields | Name, Email, Role, Organization Assignment (optional) |
Invitation workflow | Email-based invitation with Pending Invite status tracking |
Self-service interaction | Organization assignment + Self-Service Access = scoped document visibility |
Organization mapping | Optional for document-centric roles; determines document visibility |
Other Technical Specifications
Parameter | Limit |
Invitation delivery | Email-based; pending until accepted |
Self-service enforcement | Applies to Reviewer, Validator, and Reviewer and Validator roles only |
Notes
Users stuck in Pending Invite status may need the invitation resent or delivery confirmed (check spam/junk folders)
Shared accounts should be avoided for audit accountability - each user should have their own credentials
Organization assignment is optional; unassigned non-admin users default to broad visibility across all non-self-service organizations
Role changes take effect immediately but may require the user to refresh their session
There is no bulk user import - users are added individually through the UI
