Skip to content

User management

Administrators can invite users to their GENI Workflows tenant, change their roles, and remove their access. See User roles for the permissions granted by each role.

Terminal window
geni user create \
--name 'Jane Analyst' \
--email jane@acme.io \
--role analyst

The available tenant roles are admin, analyst, and viewer. If --role is omitted, the new user is an analyst.

GENI creates the account in a pending state and emails the user an activation link. The activation token expires after seven days. The user follows the link or runs geni auth activate to choose a password and activate the account; see Activation and authentication.

Terminal window
geni user list

The output includes each user’s ID, name, email, role, and account status. Use the ID to inspect one user:

Terminal window
geni user get <user-id>

By default, list returns up to 50 users. Set a different maximum or choose a machine-readable output format when needed:

Terminal window
geni user list --limit 100 --format json
Terminal window
geni user assign-role <user-id> --role viewer

Assign admin, analyst, or viewer. Role changes take effect for subsequent authorized requests.

Terminal window
geni user delete <user-id>

This permanently removes the user’s account and access to the tenant.