User management in Sitemark allows company administrators to control who has access to your company's data and what they can do with it. This guide introduces the key concepts you'll need to understand before managing users.
Key Concepts
Users
A user is someone with a Sitemark account, identified by their email address. Users can belong to multiple companies, with different permissions in each.
If you have access to multiple companies, you'll be asked to select which company to log in to after authenticating — provided your login method (Email & Password or SSO) is valid for more than one of your companies.
Permissions
Sitemark uses granular permissions. Each user or group can have any combination of permissions, giving you fine-grained control over what people can do. See Permissions for the full list.
Site Access
Beyond permissions, you control which sites each user can access. Users with 'Can access all sites in the portfolio' permissions can see all sites; others only see sites explicitly granted to them. See How to limit access to a single site for details.
Groups
User groups let you manage permissions and site access for multiple users at once. When you assign a permission to a group, all members inherit that permission in addition to their own permission. See Managing User Groups for details.
API Keys
For integrations and automated systems, you can create API keys that provide programmatic access to your company's data. See API Access for details.
Who Can Manage Users?
To manage users in your company, you need the 'Can manage which users have access to specific sites' and the 'Can manage which users have access to specific sites' permission. This allows you to:
Invite new users
Edit user permissions and site access (only permissions and sites you have access to yourself)
Create and manage groups
Remove users from your company
Company Owners
Every company has one or more owners — users with special administrative privileges.
Owner privileges:
Full administrative access to the company
Can manage authentication methods and login policies for the company
Can bypass login policy restrictions (safety feature to prevent lockouts)
Can make other users owners or remove ownership
See Managing Company Owners for details.
Authentication
Authentication Methods
Sitemark supports multiple authentication methods to secure access to your company's data. This article explains the options and how to configure them.
Email & Password: Default login with email and password.
Single Sign-On (SSO): Login via your organization's identity provider, setup by company owner. See Setting Up Single Sign-On (SSO) with Microsoft Entra.
Multi-Factor Authentication: Additional verification with authenticator app, setup by individual users. See How to Enable Two-Factor Authentication.
Login Policies
Login policies control which authentication methods users can use. These can be managed by the company owners. The available login policy options are:
ANY (default): Users can log in with Email & Password or SSO
SSO only: Users must log in through SSO; Email & Password is disabled; exceptions can be added.
