> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/user-management/manage-users-in-the-cortex-agentix-tenant.md).

# Manage users in the Cortex AgentiX tenant

To access Cortex AgentiX users must be created in the [Customer Support Portal (CSP)](https://support.paloaltonetworks.com/) and added to the tenant or created via SSO. When logging into Cortex AgentiX users must have a direct role or a user group role. If no role is assigned either directly or via a user group, they do not have access to the tenant.

{% hint style="info" %}

### Note

To remove users that were added to your CSP account, you need to do this in the CSP and not in the tenant or Cortex Gateway.
{% endhint %}

When right-clicking a user on the **Users** page, you can do the following:

* Add/update the user role
* Edit user permissions

  View the user's details. You can add a phone number, which enables playbooks and scripts to trigger direct analyst communication by phone.<br>

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Non-administrator users with <strong>Access Management</strong> permissions cannot grant, modify, or remove the <strong>Instance Administrator</strong> role for users, user groups, or API keys.</p><p>The <strong>Edit</strong> and <strong>Remove</strong> buttons are hidden for users with an effective <strong>Instance Administrator</strong> role.</p></div>
* Remove User Role
* Hide the User
* Deactivate User
* Import user roles

<details>

<summary>Add/update user roles</summary>

You can update user roles for one or multiple users. You can add/update the following user roles:

* **Pre-Defined roles**: Instance Administrator and Account Admin. If you want to remove the Account Admin role from a user, you need to remove it in Cortex Gateway.
* **Custom roles**: Includes out-of-the-box roles and roles created in Cortex Gateway or the tenant.

{% hint style="info" %}

### Note

To update the permissions attributable to each role, change them in the **Roles** tab or Cortex Gateway.

If users have been created in the CSP, but you want them to access the tenant through SSO only, you should not assign a direct role. If you sign a direct role, users can access the tenant through both the CSP and SSO.
{% endhint %}

1. Go to **Settings** → **Configurations** → **Access Management** → **Users**, and do one of the following:
   * To edit one user, right-click the user's name and select **Edit User Permissions**.
   * To edit multiple users, select multiple users, right-click, and select **Edit Users Permissions**.
2. In the **Role** field, select one of the pre-defined or custom roles.

   * Pre-Defined Roles
   * Custom roles

   If no role is assigned either directly or via a user group, users do not have view or edit permissions in Cortex AgentiX.\
   \
   The **Show Accumulated Permissions** field shows the roles and user groups assigned to the user. You can also select the specific roles assigned to the user, which enables you to compare available permissions based on the roles selected. This can help you understand how the role permissions for a particular user are built. For example, if you need to isolate a specific component, the permissions are provided by a particular role or user group.
3. Add User Groups if required.
4. (Optional) If Scope-Based Access Control is enabled for the tenant, click **Scope** and select a tag family and the corresponding tags.

</details>

<details>

<summary>Import multiple user roles</summary>

Rather than assigning roles to each user, you can import multiple user roles to add users who have a Customer Support Portal account and assign them existing predefined or custom roles in Cortex AgentiX. On the Users page, when clicking Import Multiple User Roles, download the example file and replace the file contents with the data to upload. The following values must be included:

| Parameter                          | Value                                                                                                                                                                             |
| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| User email                         | The email address of the user belonging to the Customer Support Portal account that you want to import.                                                                           |
| Role name                          | The name of the role that you want to assign to this user. The role must already be created in Cortex AgentiX.                                                                    |
| Is an account role (default=false) | Determines whether the user role is created in Cortex Gateway or the tenant. If defined in Cortex Gateway, set the value to True; otherwise, the value is set to False (default). |

</details>

<details>

<summary>Remove a user role</summary>

If a user has a role in the tenant (not Account Admin), you can remove their user permission to access the tenant. If no direct or user group role has been assigned, the user role displays **No Role**, and has no permission to view or edit on Cortex AgentiX.

1. In the **Users** tab, right-click the user's name and select **Remove User Role**.
2. Confirm that you want to **Remove** the user role.

</details>

<details>

<summary>Deactivate users</summary>

Users should be deactivated to temporarily remove user access to the Cortex AgentiX tenant. All user information is maintained for deactivated users. Users should be permanently removed from the CSP if they no longer need access to Cortex products. If you want to remove a user from the CSP, you need to reassign issues and tasks to another user before removing them.

{% hint style="info" %}

### Note

You cannot deactivate a user who has an Account Admin role. If you want to deactivate users from all tenants, deactivate them in Cortex Gateway.

The user will be deactivated in the tenant, but may still be active in other tenants. If you want to deactivate the tenant for multiple tenants, deactivate the user in Cortex Gateway.
{% endhint %}

Go to the **Cases** page and search for **Status != Resolved** **AND Assignee = \<name of assignee>** to find any cases the user is assigned and reassign.

If the user is assigned to cases and issues, these assignments do not automatically change when the user is removed or deactivated. We recommend changing issues and task assignments manually before removing or deactivating users.

Any reports the user has created remain available. Reports are not owned by specific users and can be edited or deleted by other users.

{% hint style="info" %}

### Note

When you remove a role, the role associated with the API keys is deleted.

* If more than one role was associated with the API key, a yellow warning symbol appears next to the API key in the API key table. When you hover over the symbol, a message indicates that some of the roles associated with the API key have been deleted.
* If all roles associated with the API key are removed, a red warning symbol appears next to the API key in the API key table. When you hover over that symbol, a message indicates that the key is no longer usable because it does not have a role associated with it. The API key is still visible in the API table, but it cannot be assigned.

When a user is deactivated, API keys that the user created are not revoked.
{% endhint %}

Before you deactivate a user, reassign open cases and issues to another user by going to the Cases page and search for **Status != Resolved AND Assignee = \<name of assignee>** and reassign.

#### How to deactivate users

1. From the **Users** page, right-click the user's name and select **Deactivate User**.
2. In the dialog box, **Deactivate** the user.

</details>

<details>

<summary>Hide users</summary>

Hides users from the user list in the tenant. This is useful when you have users who are not related to your Cortex tenant and will not be designated with a role, such as CSP Super Users, and you want to hide them from the list. Non-administrator users with **Access Management** permissions can hide any user, including those assigned the **Instance Administrator** role.

You cannot view the user or search for the user when hidden. To hide a user, select the name, right-click the user's name, and select **Hide user**. The user is no longer displayed when the table is configured to hide hidden users (default). To view the user, select **Actions → Show Hidden users**. If you want to remove the hidden designation, right-click the user's name and select **Unhide user**.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/users-and-roles-management/user-management/manage-users-in-the-cortex-agentix-tenant.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
