User roles
Every Hadiq.io user has exactly one role. The role controls which admin features they can access and which content they can view.Admins cannot demote their own account from the Admin role. Another admin must make that change.
Inviting users
1
Open the Users panel
Go to Admin > Users.
2
Invite by email
Click Invite Users, then enter one or more email addresses — one per line or comma-separated.If email is configured on your instance, Hadiq.io sends an invitation to each address. Users can sign up and immediately access the workspace.
3
Confirm the invite
Invited users appear in the Invited tab until they accept and sign up, at which point they move to the Active tab.
Changing a user’s role
1
Find the user
Go to Admin > Users and locate the user by email using the search field.
2
Update the role
Click the role dropdown next to the user and select the new role.
3
Confirm the change
The role updates immediately. If you are demoting a Curator, Hadiq.io automatically removes their curator relationship from all groups before applying the new role.
Deactivating and deleting users
To prevent a user from signing in without permanently removing their data, deactivate the account first. Deactivated users cannot log in but their chat history and contributions remain intact.1
Deactivate the user
Go to Admin > Users, find the user, and click Deactivate.
2
Delete the user (optional)
Once the account shows as inactive, click Delete User to permanently remove it. This action is irreversible.
Groups
Groups let you bundle users together and then grant the group access to connectors and agents. When a connector is restricted to specific groups, only members of those groups can see documents from that connector in search and chat results.Creating a group
1
Go to Groups
Navigate to Admin > Groups.
2
Create the group
Click New Group, enter a name, and save.
3
Add users
Open the group and use the Add Users field to search for and add members by email.
4
Assign connectors
Under the Connectors tab within the group, add the connectors you want to restrict to this group. Only members of this group will be able to see content from those connectors.
Designating curators
A curator can manage a group’s membership and connectors without having full admin access. To designate a curator:- Open the group in Admin > Groups.
- Find the user in the members list.
- Toggle the Curator switch next to their name.
Removing a group
Open the group, click Delete Group, and confirm. Users in the group are not deleted — they simply lose access to any connectors or agents that were restricted to that group.How RBAC controls access
Connectors and agents can be set to public (accessible to all users) or restricted (accessible only to specific groups). When a connector is restricted:- Only users in the assigned groups can see documents from that connector in search results and chat responses.
- The restriction applies both at indexing time and at query time.
Permission inheritance from source connectors: When a connector has document-level permissions enabled — for example, a Google Drive connector that respects Google’s native sharing settings — Hadiq.io inherits those permissions from the source. A user must both belong to a permitted group and have access to the document in the source system to see it in Hadiq.io.
Group sync via SSO
Automatic group sync from your identity provider requires OIDC or SAML SSO, which is available on the Enterprise plan. On the Business plan, groups are managed manually through the Admin panel.