> For the complete documentation index, see [llms.txt](https://docs.sealsecurity.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sealsecurity.io/getting-started/users-and-sso.md).

# Managing users, roles & SSO

Tenant administrators manage users from **Settings**. Seal supports four user roles with distinct permission sets, an invite-based flow for adding team members, and SAML single sign-on for organizations that use it.

<figure><img src="/files/2koBbhLSGDfqLReo7xtN" alt="The Settings > User permissions tab with user rows and the Invite new user button."><figcaption><p>The User permissions tab on the Settings page.</p></figcaption></figure>

* [User roles](/getting-started/users-and-sso/user-roles.md): the four roles (Admin, Sealer, Collaborator, Watcher) and the permission matrix.
* [Inviting and managing users](/getting-started/users-and-sso/inviting-users.md): the invite flow, role changes, and revoking access.
* [SSO and SAML](/getting-started/users-and-sso/sso-and-saml.md): connecting your identity provider through the authentication portal.
