Users, Roles & Teams
Invite people, decide what they can do and which properties they can reach, and organize them into teams.
Overview
Everyone who works in Cardinal belongs to an organization. Two things decide what each person sees: their role (what they're there to do) and their scope (which properties that role applies to). You manage both under Settings → Users, and you can read exactly what each role allows under Settings → Roles & permissions. Open Settings from your avatar in the sidebar.
Who Can Do What
Owners & Admins
- Invite new users and resend or cancel invitations
- Change anyone's role
- Deactivate, reactivate, or remove users
- Reset another user's two-factor authentication
- Create, edit, and delete teams
Property Managers
- Give people access to the properties they manage, or take it away
- See who is in the organization and on each team
Only an Owner can make someone else an Owner. Everyone can see the list of users and the Roles & permissions page.
Inviting Someone
Owners and admins see a New user button at the top of Settings → Users. The invitation dialog asks three questions and shows you what the person will be able to do before you send it.
Sending an Invitation
- Click New user.
- Under Name and email, enter their first name and email address.
- Under What are they here to do?, choose a role. Click Compare all roles to see every role side by side without leaving the dialog — click a role's column heading to pick it.
- Under Which properties?, choose the scope:
- Everything in [your organization]: every property, including ones added later, plus anything attached to the organization rather than a property.
- Choose properties: only the properties you pick. Click a portfolio chip to add all of the properties it has today — properties added to that portfolio later aren't included automatically.
- Check the access preview at the bottom. It lists what this person will and won't be able to do — click Details for the full breakdown.
- Click Send invitation. They'll receive an email with a link to set up their account.
Good to Know
- Owner and Admin always apply to the whole organization, so the property choice is locked for them.
- Property roles with no properties: you can send the invitation before choosing any properties, but the person won't see any property until one is granted.
- Only Owners can invite Owners. Admins don't see the Owner role in the picker.
Members vs. External Users
Members
- Your organization is their home organization
- Can be given any role
- Deactivated and reactivated from their user page
External users
- Already have a Cardinal account in another organization, which stays their home
- Can be given any role except Owner; their access here depends only on what you grant
- Marked External in the users list, and removed rather than deactivated
You don't choose this — when you enter an email address that already belongs to another organization's account, the dialog tells you the person will join as an external user.
Managing Users
The Users List
Settings → Users has two tabs:
Users
- First name, last name, email, role, status, and the date they were added
- Search by name or email
- Filter by Status (Active, Inactive, Removed) and Role
- Select several people to deactivate, reactivate, or remove them together
Pending users
- Invitations that haven't been accepted yet, with the role, access, and date invited
- Use the row menu to Resend invite or Cancel invite
A User's Page
Click anyone in the list to open their page. It shows their User Details (name, email, phone) and an Access section listing their role and every property, portfolio, and mailbox they can reach.
Changing someone's access
- Click Edit access.
- Choose their role and which properties it applies to — the same choices as an invitation.
- Click Save changes. If the change narrows their access (for example, taking away organization-wide access), Cardinal asks you to confirm and explains what they'll lose.
Property Managers can adjust which properties someone reaches; changing a person's role takes an Owner or Admin. You can't change your own role.
User actions
The actions menu on a user's page (Owners and Admins) offers:
- Deactivate user: they're signed out and lose access immediately. Their data and history are kept, and you can reactivate them at any time.
- Reactivate user: restores access for a deactivated user.
- Reset MFA: removes their enrolled two-factor methods and recovery codes and signs them out everywhere. They set up a new method the next time they sign in — use this when someone loses their phone.
- Remove user from organization (external users only): revokes all of their property and mailbox access and removes them from all teams. This can't be undone.
You can't deactivate or remove yourself.
Roles
Cardinal offers four roles. Owner and Admin always apply to the whole organization. Property Manager and Assistant Property Manager apply to the properties or portfolios they're assigned to — or, if assigned at the organization level, to every property including ones added later.
Owner
Full access across the entire organization. The only role that can delete the organization or transfer its ownership. An organization always has at least one Owner.
Admin
Full access across the entire organization, including all properties, issues, and contacts. Admins can do almost everything an Owner can; the Roles & permissions page lists exactly where the two differ.
Property Manager
Manages daily operations for assigned properties — leases, issues, mail, files, and contacts. The highest property-level role, and the one that can give other people access to those properties.
Assistant Property Manager
Handles routine property work — leases, issues, and files — but can't grant or change anyone else's access.
Roles & Permissions Page
Settings → Roles & permissions shows every role against every area of Cardinal — properties, leases, issues, mail, files, contacts, and more — at one of three levels:
- View: see it, but not change it
- Edit: create and update
- Manage: administer it, including deleting and granting access
Manage includes Edit, and Edit includes View. Hover any cell to read what that level means for that area. Select a role's column to open its page, which covers what the role is for, where it applies, what it deliberately leaves out, the rules that come with it, and Who has this role.
The page is read-only. To change what someone can do, edit their access from their user page.
Rules That Always Apply
- You can only grant access you already hold — to make someone a Property Manager of a property, you need full management access to it yourself.
- The last Owner can't be removed or step down; transfer the organization to someone else first.
Teams
Teams group people in your organization — for example, a leasing team or an accounting team. Organization teams are listed on the Teams page in Settings (/settings/teams), and the teams you belong to are on My Teams (/settings/my-teams).
Creating & Editing Teams
- On the Teams page, click New team, enter a Team Name, and click Create Team.
- Open the team from the list to edit its name and Team Description.
- Click + Add Members, select people from your organization, choose their team role, and click Add.
Each member has a team role — Admin or User. Use a member's menu to Update Team Role or Remove Team Member. To remove a whole team, choose Delete team from its menu in the Teams list.
Who Can Change Teams
- Organization Owners and Admins create, edit, and delete teams, and manage any team's members.
- Team Admins can add members to their team and manage their roles.
- Everyone can see which teams exist and who is on them.
My Teams
My Teams lists every team you're on, with its members. To leave a team, open its menu and choose Leave Team.
Accepting an Invitation
- New to Cardinal: open the link in your invitation email and create a password to set up your account.
- Already have an account: the link asks for your existing password to confirm it's you, then click Accept Invitation.
- Invited to a team: the email names the team and the organization it belongs to; follow the link to set your password and get started.
- Link expired? Cardinal sends a fresh invitation to your email automatically — use the newest link.
Troubleshooting
- Someone signs in but sees nothing: they have a property role but no properties yet. Open their user page and use Edit access to grant some.
- No New user button: only Owners and Admins can invite people.
- Invitation never arrived: check spam, then use Resend invite on the Pending users tab.
- Lost access to two-factor authentication: ask an Owner or Admin to use Reset MFA on your user page.