Users & Groups FAQ
Adding external users
| Topic | Details |
|---|---|
| What is an external user? | A user who already exists in Xyte under another tenant. |
| External Users & Groups section (settings page) | View-only. It shows which external users/groups are already added to the tenant — they are not created from here. |
| Add an external user directly to a space | Space → Settings → Access → Manage User Access, then add the external user to the relevant space. This is space-level access. |
| Add via a group (alternative) | Settings → Users & Groups → Groups — create a group; when adding members you can choose internal or external users, then assign the group to the space. Use a group with tenant-wide access to grant access to the whole tenant. |
| Still seeing an error? | Share the exact error message or a screenshot so it can be reviewed. |
Conditions for adding an external user to a group
An org admin can add an external user to a group only when the user's email resolves to exactly one eligible, active user.
| Topic | Details |
|---|---|
| Who is eligible? | An active user who already exists in Xyte and is either (a) a partner user, or (b) a member of a Connect+ organization connected to yours. |
| Is a support license required? | No. A support license/seat is not required to add an external user. |
| "User not found" | No active user with that email is eligible (not a partner user, and not a member of a connected Connect+ organization). |
| "Provided email is ambiguous" | The email matches more than one eligible active user (e.g. the person is both a partner user and a member of a connected organization). Consolidate to a single eligible identity, then retry. |
| Deactivated users | Deactivated users are ignored — only active users are considered. |
Group permissions
| Topic | Details |
|---|---|
| Where space access is configured | When the group is added to the space's access settings — not on the group page |
| Available space access levels | View · Edit · Admin |
A user is in a view-only group but can still edit
A user's access is the highest level they hold from anywhere — not the lowest. Belonging to a view-only group does not cap access: if the same user also gets Edit or Admin from another group, from the administrators group, or from a direct grant on the space, the stronger level wins.
| The user belongs to | Effective access on the space |
|---|---|
| The view-only group only | View |
| The view-only group and a group with Edit on the space (or a space above it) | Edit |
The view-only group and the administrators group | Admin |
| Topic | Details |
|---|---|
| Organization administrators | Members of the tenant's administrators group have full access to every space and device in the tenant. This is resolved before any space-level setting, so setting a space or a group to View cannot reduce it. |
| Changing a space's Access tab | The Access tab controls that space's permissions only. It does not change administrators group membership — so removing and re-adding an administrator's access there will not make them view-only. |
The default Device support group | Every tenant is created with two default groups on the root space: Viewers (View) and Device support (Edit). Access on the root space is inherited by every space and device beneath it, so a user left in Device support has Edit everywhere. |
| Direct user grants | A user can also be granted access directly on a space, separately from any group. A direct Edit or Admin grant outranks a view-only group in the same way. |
To confirm a user is genuinely view-only on a space, check that they are in the view-only group and:
- not in the
administratorsgroup - not in the default
Device supportgroup - have no direct user grant of Edit or Admin on that space or any space above it
Test with the account itself. Testing with an administrator's own login will always show edit rights, whatever the space is set to.
Removing someone from a group did not remove their access
Group membership and Space access are two separate things. Removing a user from a group — including the administrators group — removes only the access they held through that group. Any access granted to them directly on a Space is untouched, and they keep it.
So a user who was given Admin on one Space and was also an administrator will, after you remove them from administrators, still hold Admin on that Space — they simply lose the tenant-wide access that came with being an administrator.
To remove it, open that Space → Settings → Access and remove the user there. The Users & Groups page cannot show you direct Space grants, so check the Space's own Access tab when you need someone fully removed.
Why don't all my accounts appear in the tenant switcher?
The account switcher (top-left) groups the accounts that belong to the same platform. All of your Connect+ accounts are grouped there, so you can switch between the ones you have access to.
An account that lives on its own — for example a standalone or brand-specific account that is not part of Connect+ — sits in a separate space. It will not appear alongside your Connect+ accounts in the switcher, even after access is granted to it — this is about the type of account, not your access rights. You can still open that account by logging into its own portal separately; it simply won't be grouped here with your Connect+ accounts.
| Account | Appears in the switcher with your Connect+ accounts? |
|---|---|
| A Connect+ account you have access to | ✅ Yes — grouped and switchable together |
| A standalone / non-Connect+ account | ❌ No — it lives in a separate space |
To have an account appear and switch alongside your Connect+ accounts, it needs to be a Connect+ account. If you need this, contact us and we'll help set it up.
Updated 2 days ago
