# How to Add Users

{% embed url="<https://youtu.be/8sMID1iZIJE>" %}

### Purpose

Adding and Managing Users in the Netmaker Platform

### Identity Provider (IDP) Integration

Integrating an external Identity Provider (IDP) is the most efficient method for managing access at scale within Netmaker. By synchronizing with a provider like Google Workspace, you automate user onboarding and group management, ensuring that users have appropriate access levels based on their organizational roles.

#### Configuring Google Workspace Synchronization

To begin the integration, navigate to the **Settings** gear icon in the bottom-left corner of the sidebar and select the **Security & Authentication** tab.

In the **Identity Providers Integration** section, locate the Google option. Netmaker offers two levels of integration: a basic **Setup OAuth only** option for external login and a full **Integrate** option for automated synchronization. To enable full synchronization, click the **Integrate** button.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/3c483309-c4d9-4ec5-ac8e-5b601581b514-screenshot_1_32.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184141Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=94e8a6d23705ef7f37e9c6daaec7afcee1f7100efd3a998155a4b119a72f0a43" alt=""><figcaption></figcaption></figure>

A configuration wizard will guide you through the connection process. Review the **Required Permissions** listed in the modal and click **Get Started**. You will be prompted to follow on-screen instructions for the Google Cloud Console, including creating a project and configuring the OAuth consent screen. Once the Google Cloud project is ready, enter the **OAuth client ID** and **OAuth client secret** into the provided fields in Netmaker to finalize the connection.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/d3fe821e-81ea-40ac-b839-d1e490a9b86e-screenshot_2_46.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184140Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=01d74a443d9ff1c8a31659426f6288a02b6a3001ed6f5d07e5f4831ec7763eea" alt=""><figcaption></figcaption></figure>

#### Authentication Security Policies

Beyond IDP integration, you can manage global platform security via the **Authentication Security** panel. Here, you can toggle **Basic Authentication** to enable or disable manual credential-based logins. For organizations requiring high security, you can toggle the **Enforce Multi-factor Authentication** switch to require MFA for every user on the platform.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/b3c65342-3bc3-475e-a2ad-38b70ee482ce-screenshot_3_66.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184141Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=825a281b7d8a98fb7c157910b325433a7535d240ecde388593616b024b4b32eb" alt=""><figcaption></figcaption></figure>

Additionally, you can manage the **JWT Validity Duration**, which determines how long a user session remains active before a re-authentication is required. The default is set to 720 minutes but can be adjusted to meet your organization's security posture.

### Authentication Security Settings

Beyond external identity provider integration, Netmaker provides a dedicated panel for managing core security protocols, including manual login permissions and session persistence. These settings are critical for defining the baseline security posture of your network management platform.

#### Access and MFA Controls

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/266bd70d-a34c-4e89-886b-03681a3cabe2-screenshot_4_66.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184141Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=6ca24731dccdb680601c6930629e6a05c266f5aa6a029a89c75e708ff4e266a3" alt=""><figcaption></figcaption></figure>

Within the **Authentication Security** panel, administrators can govern how users access the platform. This includes a toggle for **Basic Authentication**, which allows or restricts the use of manual username and password credentials. For environments requiring higher security standards, you can toggle **Enforce Multi-factor Authentication**. When enabled, this requires all platform users to provide a second form of verification before they are granted access.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/9dbf5421-cb4e-4039-998f-bf298490a7eb-screenshot_5_70.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184141Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=d8240df38e9277f20d332a6da91d658ccaed7c0836f5704f79fdb69d2a909bae" alt=""><figcaption></figcaption></figure>

#### Session Management

Session persistence is managed via JSON Web Tokens (JWT). The **JWT Validity Duration** setting determines how long a user remains logged into the dashboard or application before their session expires and they are required to re-authenticate.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/9ff940aa-905a-4d4d-909c-46ba267d68ba-screenshot_6_76.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184141Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=f6f819aa107c95ce95d716ab13356f1472710c1c3a97ef2681d99b0ecfd3f311" alt=""><figcaption></figcaption></figure>

The default session length is set to **720 minutes** (12 hours). To adjust this duration to better suit your organizational security policies, click the **Edit** button next to the value and enter the desired time in minutes. This ensures a balance between user convenience and the risk of unauthorized access via stale sessions.

#### Reviewing Integration Status

Once your security settings are configured, you can verify your active integrations by returning to the **Security & Authentication** tab. This view allows you to see the details of configured providers, such as Google Workspace, including the Client ID and admin contact information, ensuring all security layers are correctly aligned.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/97836bd3-f028-4fd4-8936-3108d74c503a-screenshot_7_94.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184142Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=5a7ba865bfc9bd64fe5beb69e6192dded0c7b1b1d0157e61da378cb09963a110" alt=""><figcaption></figcaption></figure>

### Manual User Creation and Access Levels

While automated Identity Provider (IDP) synchronization is efficient for large organizations, Netmaker provides a robust manual user management system for creating local accounts and defining granular access controls.

#### Creating a New User

To manually add a user, navigate to the **User Management** page from the left-hand sidebar and click the **+ Create User** button in the top-right corner. This opens a modal where you must define the user's primary credentials and permission scope.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/033c1b9b-8b2a-4fbd-80a3-dbdc0543e4f9-screenshot_8_118.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184142Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=262763a26fe7d285c5f7a4f253e58666135ce88457ff45851d1965fcd343e47a" alt=""><figcaption></figcaption></figure>

1. **Identify the User:** Enter a unique identifier in the **Username** field and set a secure password.
2. **Assign Access Level:** Select the appropriate radio button to define the user's global platform permissions.
3. **Finalize:** Once details are entered and roles are assigned, click **Create User**. A confirmation toast will appear in the top-right corner.

#### Understanding Platform Access Levels

Netmaker utilizes three distinct access levels to ensure the principle of least privilege is maintained across the network infrastructure.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/55c00a86-a38c-4b2a-889b-8bfc19891e79-screenshot_9_124.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184141Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=c44227296d84d60902156ce410f64f953cd290b7eb2bc8bd724030481d6cf3ee" alt=""><figcaption></figcaption></figure>

**1. Admin**

Admins hold full system-wide permissions. They can manage all users, add or remove devices, configure global settings, and oversee every network within the platform. This level is intended for primary infrastructure maintainers.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/31150c12-d5a7-49c9-933c-47e887cbf4ca-screenshot_10_130.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184142Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=ba4ddf978999ba0796de8b04508bd9cf2ee05ef8f29234184be7bf581f822c4e" alt=""><figcaption></figcaption></figure>

**2. Platform User**

Platform Users are granted dashboard access but are restricted to specific network administration duties. Their access is dictated by group membership. For example, assigning a Platform User to a 'cloud-overlay Admin Group' allows them to act as an administrator only for that specific network environment.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/4219d13a-ab39-4fe9-8aba-72c6b4f2a63a-screenshot_11_136.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184142Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=38ec74d0c8e2fd7459b7c931376ea760b93964dc71db21dda447b1d52e62ae9d" alt=""><figcaption></figcaption></figure>

**3. Service User**

Service Users are restricted accounts designed for standard end-users who do not require dashboard access. These users cannot log into the web UI; instead, they use the Netmaker Desktop application to connect to their assigned networks. Access is managed by adding them to specific user groups, such as an 'Office User Group'.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/10ced52a-bbec-4dea-9f80-484a65832cb9-screenshot_12_142.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184142Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=4c5bd2ff07f21d181ff7ca2942e445ca9018193febb4e0b2ddd53fc2cbf1b7cb" alt=""><figcaption></figcaption></figure>

**4. Auditor**

The Auditor role will gain full **read-only** access to the platform on the specified networks.

#### Post-Creation Management

Once created, users appear in the User Management table. From here, you can monitor their **Status** (Enabled/Disabled) and **Auth Type**. If you need to manage network-specific roles more granularly, you can navigate to the **Groups** tab to create custom groups and assign roles like 'admin' or 'user' to specific networks.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/ff159af8-58e6-4c5f-8e72-b56bd7059e82-screenshot_13_156.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184143Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=fdda3a150798e4c9893b93175321937f5b01366f54f253b6df5719f6fc689d0c" alt=""><figcaption></figcaption></figure>

### Group and Role Management

Netmaker utilizes a group-based system to manage granular access permissions across various networks. This allows administrators to define whether a user acts as an administrator or a standard user for specific network segments, ensuring the principle of least privilege.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/1a935877-9a18-41b4-8037-7c0210c6f389-screenshot_14_202.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184144Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=f6c74ba782417415561f434d5e066e0761232e824b5b211fdff83b1fd7e6ca12" alt=""><figcaption></figcaption></figure>

#### Configuring Default and Custom Groups

While the platform automatically generates default groups for basic administrative and user roles, you can create custom groups for more specific use cases. To create a new group, navigate to the **Groups** dashboard and click the **+ Create Group** button. In the resulting modal, provide a unique **Group Name** and a description to identify the group's purpose.

The core of group management lies in the **Associated Network Roles**. Within this section, you can use a dropdown menu for each specific network to assign roles. Currently, these roles include:

* **Admin:** Grants full management rights over the specific network.
* **User:** Grants standard access to the network without administrative privileges.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/813d76a6-ecaf-4ec0-b8f6-7409c768b29f-screenshot_15_208.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184142Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=ff7329465594167cefe4b534513b29329eb609ac8bbb4eb23c428f202c872b4c" alt=""><figcaption></figcaption></figure>

#### User Onboarding via Invitations

Beyond manual user creation, Netmaker supports an invitation workflow that streamlines onboarding. By clicking the **Invite User** button from the main dashboard, you can enter multiple email addresses to invite users in bulk. This system requires a configured SMTP server to send automated email invites.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/93883508-effb-4ef5-bfb6-7bd5d0ab675e-screenshot_16_224.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184142Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=baafaae1113bd43189fa39bfd3ca05fc76313efeec56b07b4ad8521f921ba52f" alt=""><figcaption></figcaption></figure>

When sending invitations, you must define the **Platform Access Level** (Admin, Platform User, or Service User). This sets the global permission for the invited user before they are assigned to specific network groups. Once configured, clicking **Create User Invite(s)** initiates the delivery of the invitation tokens.

You can monitor the status of sent invitations and manage pending enrollment sign-ups by navigating to the **Invites & Requests** tab at the top of the interface.

### Email Invites and Pending Requests

Netmaker provides streamlined methods for onboarding users through automated email invitations and a self-service sign-up queue. These features allow administrators to manage growth without manually creating every individual account.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/1765d725-d7e9-4af4-a4ed-3dbc050627b9-screenshot_17_240.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184143Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=79b117f598f41c43a939d920d1403f3494007723b4baadf2062449cc49f6c029" alt=""><figcaption></figcaption></figure>

#### Sending Email Invitations

To invite new members to the platform via email, navigate to the **User Management** section and select the **+ Invite User(s)** button. This workflow leverages your configured SMTP server to send automated onboarding emails.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/2d3c679f-a49d-4dd5-aff0-4bb08144bd24-screenshot_18_260.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184142Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=47e83cc6a38254d17451717e9aa35033d02c9bc38ced3233272aa8cf34671214" alt=""><figcaption></figcaption></figure>

* **Recipient Entry:** In the invitation modal, enter one or more email addresses. Multiple addresses should be separated by commas.
* **Set Access Level:** Choose the initial **Platform Access Level** (Admin, Platform User, or Service User) that the invitees will receive upon joining.
* **Finalize:** Click **Create User Invite(s)** to dispatch the emails.

#### Managing Pending Sign-Up Requests

Users who have initiated a sign-up through the Netmaker Web UI or the Netmaker Desktop application without an invitation will appear in the **Requests** section. This acts as an approval queue to ensure only authorized individuals gain access to the network.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/c649691e-6add-48fc-97c0-685f72515a7d-screenshot_19_244.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184144Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=2c364dfa12fa3228ba91d85afeb9f998142f9743218e2a978ddc7fbfd399a038" alt=""><figcaption></figcaption></figure>

To manage these users, navigate to the **Invites & Requests** tab and scroll to the **Requests** table at the bottom of the interface. Here, you can review the pending list and approve users individually. Once approved, you can assign them to specific network groups and define their platform permissions.

<figure><img src="https://limesync-general-production.000da24485a2eb1df827157d23f74fdc.r2.cloudflarestorage.com/c0d109fb-1725-4769-a8ed-443da5e18a40/6681c732-5ec0-44f2-a03e-ba3f00c20d36/b3daad90-eb99-4a97-99d2-0c0b17fc5a23/5743e31a-0082-4196-a0a5-b65742a07b81-screenshot_20_250.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&#x26;X-Amz-Credential=934e8b232ee153ba21e195ef724a2066%2F20260121%2Fauto%2Fs3%2Faws4_request&#x26;X-Amz-Date=20260121T184143Z&#x26;X-Amz-Expires=3600&#x26;X-Amz-SignedHeaders=host&#x26;X-Amz-Signature=cc86314712a8d4c38a397391c53888bf29f0b4e697b334e20e9a8b8e84202986" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://learn.netmaker.io/getting-started/walkthrough/how-to-add-users.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
