{% extends "base.html" %} {% block title %}Users & access — BackupWatch{% endblock %} {% block main_class %}wide{% endblock %} {% block subnav %}{% set subnav_active = 'users' %}{% include "_settings_subnav.html" %}{% endblock %} {% block content %} {% macro client_options(prefix) %}
Which clients can they see? None selected
{% for c in clients %} {% endfor %}
{% endmacro %}
SETTINGS / ACCESS REVIEW

Users & access

{{ pend|length }} invite{{ '' if pend|length == 1 else 's' }} waiting · {{ n_admin }} admin · {{ n_stale }} inactive 90+ days {{ seats_used }} OF {{ seat_limit }} SEATS USED
{% if pend %}
PENDING INVITES {{ pend|length }} Invited but never signed in — they hold a seat and can't see anything yet
NAMEROLEINVITEEXPIRES
{% for i in pend %}
{{ i.initials }} {{ i.name }} {{ i.email }} {{ i.meta.label }} {{ i.sent }} {{ i.expires }}
{% endfor %}
No invites match this filter.
{% endif %}
ACTIVE USERS {{ rows|length }} Signed in at least once — ordered by privilege, colour-coded by role {% for k in ('admin', 'tech', 'readonly') %} {{ role_meta[k].label }} {% endfor %}
NAMEROLECAN SEELAST ACTIVE
{% for r in rows %}
{{ r.initials }} {{ r.name }} {% if r.you %}(you){% endif %} {{ r.email }} {{ r.meta.label }} {% if r.scoped %} {% else %} All clients {% endif %} {{ r.last_active }} {% if r.you %} {% else %}
{% endif %}
{% endfor %}
Nobody matches this filter.
WHAT EACH ROLE CAN DO
Admin
Triage and acknowledge · edit rules and schedules · add and remove clients · mail audit · settings and licence · invite and remove users
Operator
Triage and acknowledge · edit rules and schedules · view every client · read mail audit. No settings, no user changes.
Read-only
View the dashboard for the clients they're scoped to. Cannot acknowledge, change rules or export.
{# ---- invite drawer ---- #}
Invite user
First name
Last name
Work email Role
{% for k in ('admin', 'tech', 'readonly') %} {% endfor %}
BackupWatch emails a single-use invite link that expires in 7 days. No password is set here — they choose their own.
{{ seats_used }}/{{ seat_limit }} SEATS
{# ---- reset password dialog ---- #}
Reset password
…
Single use — they must set their own password at next sign-in. Existing sessions are signed out.
{# ---- role dialog ---- #}
Change role
{% for k in ('admin', 'tech', 'readonly') %} {% endfor %}
{# ---- client access dialog ---- #}
Client access
{{ client_options('access') }}
{% endblock %}