> For the complete documentation index, see [llms.txt](https://docs.sealsecurity.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sealsecurity.io/getting-started/users-and-sso.md).

# Managing users, roles & SSO

User roles, inviting team members, and configuring single sign-on.

Tenant administrators manage users from **Settings**. Seal supports four user roles with distinct permission sets, an invite-based flow for adding team members, and SAML single sign-on for organizations that use it.

<figure><img src="https://2109738374-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FytkIsVkwVdKiLQ2CT6Sw%2Fuploads%2Fgit-blob-13fb0bca320d96ed17286b278989ac30cd33bf96%2Froles-and-permissions-page.png?alt=media" alt="The Settings > User permissions tab with user rows and the Invite new user button."><figcaption><p>The User permissions tab on the Settings page.</p></figcaption></figure>

* [User roles](/getting-started/users-and-sso/user-roles.md): the four roles (Admin, Sealer, Collaborator, Watcher) and the permission matrix.
* [Inviting and managing users](/getting-started/users-and-sso/inviting-users.md): the invite flow, role changes, and revoking access.
* [SSO and SAML](/getting-started/users-and-sso/sso-and-saml.md): connecting your identity provider through the authentication portal.
