Skip to content

Getting started

Manage who has access

Add and remove your own people, set each to Admin or Viewer, and see how fast a removal takes effect.

Validated against the setup service on 3 August 2026.

Your admins add and remove their own people. Infralign is not in the loop, and there is no ticket.

Open the People page from the Admin section of the dashboard sidebar, which is visible to admins only. Its address is /setup/admin/users, and that URL is safe to put in an email.

The same controls appear as an optional block on the last step of the setup wizard, so the first admin can add colleagues before the first nightly run lands.

The People page. A tabbed admin surface headed "Who can see your cost data." A panel explains what Viewer and Admin can each change. Below it, a list of two people with their roles, a role menu and a Remove button on the editable row, and a form to add a work email with a role.

Captured from the setup service. The addresses and the account name are test values.

RoleWhat they can change
ViewerNothing. They read the dashboards, the reports and the chatbot.
AdminAll of that, plus the Azure connection, the subscription list, and this page.

Give Admin to whoever would rotate the client secret.

Before the dashboards open, a Viewer sees a status page giving the ingestion window and how far setup has got. Only the admin’s screen shows the Azure identifiers: the Directory (tenant) ID and the Application (client) ID.

Everyone on the account sees the whole account. Per-person dashboard scoping is not built.

An account set up before self-serve access may carry a row labelled Owner. That role is shown read-only. Ask Infralign to change it.

  1. Open the People page.
  2. Enter their work email address.
  3. Choose Viewer or Admin.
  4. Select Add to the account.

Done when the row appears in the list and the count above it goes up by one.

That person can sign in immediately, with their own Microsoft work account, at app.infralign.ai. No email is sent to them. The page states it plainly:

They can sign in now. There is no invite email — tell them to go to app.infralign.ai.

Tell them yourself. Nothing else will.

An admin may add addresses only at a domain Infralign has recorded for the account. The first admin’s own domain seeds the list.

A refusal names both the domain that was typed and the domains that are allowed, so the next step is your own IT rather than Infralign’s support queue.

To add a subsidiary’s domain, or a contractor’s own domain, ask Infralign. Recording a domain is an operator action and it is audited.

If no domains are recorded for your account, the add form does not appear and the page says so. An account whose first admin signed up at a personal-mail address starts in that state. Ask Infralign to record your company’s domain.

Infralign holds no permission to ask Microsoft whether your own Entra tenant issues an address. If nobody at that domain has yet signed in from your tenant, the add succeeds and the row carries a warning.

Watch for it. An address your tenant does not issue fails at Microsoft’s own sign-in, before the request reaches Infralign, with an error nobody on your side can debug.

If your account has Azure connections in two different Entra tenants, an add is refused rather than guessed at. The wrong tenant would either lock the person out permanently or trust an issuer nobody chose. Ask Infralign to enrol them.

  1. Open the role menu on their row.
  2. Choose the other role.
  3. Select elsewhere on the page, or press Enter.

Done when the sentence under their address names the new role.

The change applies to their next request, within about a second.

  1. Select Remove on their row.
  2. Read the confirmation, then select Remove access.

Done when their row is gone and the count above the list goes down by one.

Their access ends in about a second, including any session they already have open. Nothing else changes, and you can add them again at any time.

RuleWhat it prevents
You cannot remove or demote yourselfAn admin locking themselves out of their own account
The last admin cannot be removed or demotedAn account with nobody who can rotate the credential

A blocked row explains itself in place rather than showing a greyed-out button. Both rules apply at once for a sole admin looking at their own row. The page then tells you to make someone else an admin first.

Every add, removal and role change is written to the account’s audit trail with the address that made it. Refused adds are recorded too, so repeated attempts at a domain that is not yours are visible.

Read the trail on the connection page. See connect Azure.

SymptomCauseFix
The add form is missingNo email domains are recorded for the accountAsk Infralign to record your company’s domain
The address is refused and the message names your allowed domainsThe address is at a domain that is not recordedAdd an address at a listed domain, or ask Infralign to record the new one
The person you added cannot sign inTheir Entra tenant is not the one connected to this accountCheck the warning on their row, then ask Infralign
Every page returns 403 for a person who is on the listThe address does not match the one their Microsoft account assertsRemove the row and add the exact address Microsoft returns
Remove is missing on a rowThe row is you, or the last admin, or an Owner rowPromote somebody else first, or ask Infralign

Your first day covers what the people you just added will see, and when.