Skip to content

People, access, and profile merges

People is the platform-wide directory of person profiles and the place where elevated access is managed. Any staff member can search it, review incomplete logins, and open a person’s profile; merging, impersonation, and role changes need admin.

Three kinds of authority are separate records, and a change to one never implies a change to the others: platform roles (staff, admin, sysadmin), organization roles, and profile-management grants. A person’s role at an organization is not evidence for a Homeward-wide role, and a platform role does not automatically grant management of every profile.

At the top of the page, Needs attention lists logins under Profile setup incomplete — accounts that have not claimed or created a profile. Each row shows the login email and name, the last activity date, and whether the email is verified.

The actions menu offers two choices, both admin-only:

  • Attach profile — link the login to a person who already has a profile. Search by name, username, or email (at least two characters) and pick from the results. Homeward warns before you confirm: attaching gives that login full access to the selected profile and its history, so confirm the identity first. Attaching never moves a profile away from another login.
  • Delete login — removes only the login and its sessions. It cannot delete a person profile or any profile-owned data. There is a confirmation dialog.

If you cannot find a match, that is fine: the person can sign in and finish creating their profile the usual way, and nothing in the queue has changed.

The People table searches on name and sorts by Person or Last login, 50 rows at a time. Each row shows the avatar and display name, which links to that person’s profile in the admin dashboard, plus:

  • a shield icon with the tier — Sysadmin access, Admin access, or Staff access — for elevated accounts;
  • a login icon when the profile has a user account attached;
  • two hover buttons that reveal cards listing the profiles this person Manages and is Managed by, each linking to that person’s access page.

Last login shows the date and time, or stays blank if the person has never signed in.

The row actions menu offers:

  • Edit profile — open the person’s profile in the admin dashboard. All staff tiers.
  • Manage access — open the person’s Access page. All staff tiers.
  • Merge profiles — open the merge tool. Admin only.
  • Impersonate — admin only, and only for profiles that have a login, hold plain member role, are not a sysadmin, and are not you.
  • Role actions, admin only: promote a member to staff or admin, promote staff to admin or remove staff access, or change an admin back to staff or remove admin access.

Removing access takes effect immediately. Success shows “{Name} now has {role} access.”

Impersonation lets you reproduce what a user sees. The dialog says it plainly: you temporarily act as the owner of that profile in read-only mode, and no password is revealed.

While impersonating, a fixed banner reads “Viewing Homeward as {name}” with a Stop impersonating button. Your original location is remembered, so stopping returns you to where you started — usually the People page.

Read-only here means you cannot change the user’s stored roles, grants, or data while acting as them. You do browse, and your session sees, everything that account sees, which is exactly the point when reproducing a report. Impersonation stays attributable to the admin who started it.

Reached from Manage access, the Access page shows which login owns a profile and who else may act on it.

  • Login credential — the person’s name and login email with an Attached badge, or a notice explaining that no login is attached, either because the login is waiting in the identity queue or because the person has no account yet and assigned managers retain access.
  • Profile managers — the people who can edit this profile, each listed with their own profile and a Remove button. Add one by email with Add manager.

The distinction matters: managers act through their own profiles. Adding or removing a login never changes the profile or its history.

The merge tool combines two duplicate person profiles into one. It is admin-only; other tiers see “Admin access required”.

Choose the destination. The left rail ranks suggested destination profiles, each with its evidence — a matching email, for example — and disables any candidate that cannot be used. Search by name, username, or email to pick a different destination. The profile being merged away is the source; the one that remains is the destination. A swap button reverses the direction if you picked the wrong way round.

Resolve the conflicts. Every conflicting field appears as a radio choice between the source value and the destination value, grouped under headings such as Profile details, Primary records, Health, Travel, Profile access, Published content, Giving, and Directory records. A live counter tracks how many you have resolved.

  • Booleans render as Yes or No; empty values render Not set; records a profile can only have one of render Use this profile’s record.
  • Sensitive conflicts — health items, management grants, travel documents — are masked by default and show Private value hidden until you press Show values. This is deliberate: not everyone reviewing a merge needs to see a medical note.
  • A warning notice lists any plan warnings the comparison produced.

Confirm. The merge button stays disabled until you type the source profile’s username exactly. That friction is intentional — this is the one action that retires a profile.

On success you see “Profiles merged”: the source was combined into the surviving profile, and the merge together with every conflict choice was recorded in the audit log. From there you can open the surviving profile or go back to People.

Related: Staff administration, Managing organizations, Fixing something that is wrong.