> For the complete documentation index, see [llms.txt](https://help.enterprise.ledger.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.enterprise.ledger.com/help-center-v2/guides/users.md).

# Users

How an Administrator creates PSD and API users on Ledger Enterprise, tracks registrations, and suspends or revokes access.

**Role: Administrators.**

**Users** lists everybody in the Workspace. It has two tabs: **Users** and **PSD registrations**.

The list carries each user's name, type, role, status, creation date and identifier. Filter it by state, role or type.

## The two user types

PSD is short for **Personal Security Device**: the credential that identifies a user and signs their approvals.

| Type         | How they work                                                   | What they need                           |
| ------------ | --------------------------------------------------------------- | ---------------------------------------- |
| **PSD user** | Signs in and approves through the interface, on a Ledger device | A registration link, and the device's ID |
| **API user** | Works entirely through the API, signing with its own key        | An externally generated public key       |

A third type, **Soft PSD**, holds its credential in software and also works through the API. It appears in the list and in the type filter.

Both types take a role, **Operator** or **Administrator**. Names are limited to 19 characters.

> **Important:** Administrator creation is paused while a quorum change is in flight. Operator creation stays available. See [**Workspace settings**](/help-center-v2/guides/workspace.md).

## Creating a PSD user

You need the invited person's **device ID** first: the 16-character identifier shown in the Ledger Vault app, in the form `DEAD-BEEF-DEAD-BEEF`. Ask them for it before you start.

1. Select **Create user**, then **PSD user**.
2. Enter the name and the device ID.
3. Select the role.
4. Submit.

The form rejects a device ID already used by an active user or an ongoing registration.

You then get a **registration link**. Send it to the invited user.

## Creating an API user

1. Select **Create user**, then **API user**.
2. Enter the name.
3. Paste the public key. It must be an uncompressed secp256r1 key: `04` followed by 128 hex characters.
4. Select the role.
5. Select **Review**, and confirm on your device.

The form rejects a public key already used by an active user.

> **Note:** An API Administrator is **restricted to read-only Requests when it is registered**. Full administrative rights require assignment to an Administrator group by a person. The permissions it does get come from the API admin Rules in [**Workspace settings**](/help-center-v2/guides/workspace.md).

## Tracking registrations

The **PSD registrations** tab follows an invitation from creation to activation.

| Status                   | What it means                                            |
| ------------------------ | -------------------------------------------------------- |
| Invitation created       | The link exists. The user has not completed registration |
| Pending admin approval   | Registration is complete and locked, awaiting approval   |
| Pending admin activation | Awaiting an Administrator to activate the user           |
| Activated                | The user exists and can work                             |

From a registration you can **copy the registration link**, **activate** the user, or **abort**.

Aborting deletes the invitation. The copied link stops working, and the person cannot complete registration from it.

## Managing an existing user

| Action              | What it does                                        |
| ------------------- | --------------------------------------------------- |
| Suspend             | Blocks access immediately. Reversible               |
| Restore access      | Lifts a suspension                                  |
| Revoke              | Ends access permanently                             |
| Refresh credentials | Issues a new API key ID and secret, for an API user |
| Link portfolios     | Attaches Portfolios to the user                     |

A user's status is **Active**, **Suspended** or **Revoked**.

### Suspending

Access is blocked immediately. The user loses the platform, any pending Requests, and any Account information. You can restore it at any time.

### Revoking

Revocation is permanent and it is a Request, so it needs approval.

For most users, access is blocked immediately and the revocation is finalized when the Request is fully approved.

> **Important:** An Administrator who is a PSD user keeps access while their revocation is being approved. They can still use the platform and see pending Requests. They cannot approve or reject their own revocation.

### Refreshing API credentials

This issues a new **API key ID** and **API key secret**.

> **Warning:** The existing credentials stop working immediately. The new secret is shown once, and is cleared when the dialog closes. Copy it before you close.

## Related

* [**Workspace settings**](/help-center-v2/guides/workspace.md)
* [**Groups**](/help-center-v2/guides/governance/groups.md)
* [**How governance works**](/help-center-v2/concepts/how-governance-works.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.enterprise.ledger.com/help-center-v2/guides/users.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
