Navigation
Users and Groups
Managing users, roles, groups, and access permissions
This section covers how to manage users, create groups (organizations), assign roles, and control access to repositories.
Users
Creating a User
If open registration is disabled, the administrator creates users manually:
- Administration -> Users
- Click “Add User”
- Enter a username, email, password
- Optionally: assign the administrator role
Editing
On the user page, the administrator can:
- Change the role (user / administrator)
- Block or unblock the account
- Reset the password
- Assign or remove a seat (if a Pro or Max license is activated); in Max, an account that signs in only through SAML or LDAP cannot work without one - see Corporate sign-in and Max seats
- Log in as the user (impersonation) - for diagnostics
Blocking sign-in is a temporary measure
The lock on the user page closes all sign-in paths at once: password, external providers, personal access tokens and SSH keys; issued tokens are revoked, and that author’s scheduled pipelines stop with the reason creator_blocked. Data, authorship and group membership stay in place, and content is not hidden.
The measure is meant for a holiday, a suspected stolen password, a security review, a contractor leaving while the history stays - and it is lifted with the same toggle.
There are two restrictions, both about not losing control of the instance: you cannot block yourself, and you cannot block the last administrator who signs in with a password - there would be nobody left to unblock them. Administrators coming from the directory do not count here: once the licence’s grace period ends, sign-in through SAML and LDAP closes, and only the password remains a way in that depends on nobody else.
Blocking and unblocking go into the audit log as the events block_user and unblock_user. A build already started by a blocked author is carried to the end: the job token belongs to the job, not to the person; new runs are closed together with sign-in.
If accounts are managed by an HR system, the same closure is done by deactivation (active=false over SCIM), and the decision belongs to that system.
Deletion
Administration -> Users -> find the user -> “Delete”. The account, its tokens and keys disappear; unlike blocking sign-in, this cannot be undone.
Deletion is forbidden while repositories are still owned by the user: transfer them to another owner or delete them first.
Groups
A group (organization) is a way to unite users and repositories. For example: backend-team, frontend, devops. Repositories within a group are accessible to all its members according to their role.
Creating a Group
- Click “+” in the top bar -> “Group”
- Enter a name (Latin letters, digits, hyphens) and description
- Click “Create”
Adding Members
- Open the group -> “Members”
- Click “Add Member”
- Find the user by name or email
- Select a role
Built-in Roles
| Role | Permissions |
|---|---|
| Guest | View public repositories |
| Reporter | View all group repositories, create issues |
| Developer | Push to unprotected branches, create pull requests, manage issues |
| Maintainer | Merge pull requests, manage branch protection, repository settings |
| Owner | Full control: manage members, delete repositories, group settings |
Custom Roles (Pro)
If the built-in roles are not enough - create custom ones with an arbitrary set of permissions.
- Open the group -> “Settings” -> “Roles”
- Click “Create Role”
- Enter a name and select permissions
- Assign the role to group members
Repositories in a Group
Repositories created within a group inherit the group members’ permissions. For example, if a user has the Developer role in the group - they can push to all repositories in that group (to unprotected branches).
Creating a Repository in a Group
- Open the group
- Click “New Repository”
- The repository will appear with the path
group/repository
Repository-Level Collaborators
In addition to group permissions, you can add individual users to a specific repository:
- Open the repository -> “Settings” -> “Collaborators”
- Click “Add”
- Select the user and role
Storage Quotas (Max)
Limiting disk space for users and groups. Useful to prevent a single user from filling the entire disk with large Docker images or LFS files.
Configuration
- Administration -> Quotas
- Set a global limit - the default for everyone
- For individual users or groups - set an individual override (more or less than the global limit)