How do people get into UprootSecurity — and who gets console access?
There's one way in: connect your identity provider — Google, Microsoft Entra ID or Zoho — and your employees are pulled in from it. There is no invite form, and no way to add a person by hand. Everyone arrives with employee-portal access only, as a Portal User. You give someone the console afterwards, by changing their role in People Access.
Connect your identity provider first
Your identity provider is wherever your company's work accounts live — Google Workspace, Microsoft Entra ID or Zoho. Connect one and, a couple of minutes later, your people are here.
Do this before anything else. Until a provider is connected, People Access is empty and every test that measures your people has nothing to look at, so those tests sit at Pending.
Why isn't the person I added to my directory showing up?
Because the sync isn't continuous. It runs shortly after you connect the provider, and after that only when an Owner or Administrator presses Sync Users on the People Access page. Nobody appears in between.
So if you added someone to Google an hour ago and they aren't here, nothing is broken — press Sync Users. Same after any change at the source: a new joiner, a leaver, a name or title change, someone turning multi-factor authentication on. Get into the habit of pressing it whenever you've been doing admin in your directory, and before you check a people-related test result.
What comes across — and what doesn't
You get the person, their email, their job title, whether multi-factor authentication (a second factor on top of their password) is switched on for them in your provider, and whether their account there is active or suspended. That's what your people tests are built on.
Your directory groups don't come across. Groups in UprootSecurity are created here, under People Access → Settings → Groups, and they exist for one purpose: bundling people together so notifications reach the right set. They are not a copy of your Google or Entra groups, they don't grant anything, and re-syncing won't populate them.
Connecting Google doesn't mean signing in with Google
This is the most common misunderstanding once someone connects a provider. Signing in to UprootSecurity is email and password. Your identity provider tells us who works here — it is not used to log anyone in. There is no single sign-on, and connecting a provider changes nothing about how you or your team sign in.
What a new person gets in their inbox
Anyone new to UprootSecurity gets an email inviting them to set up their account, with a link to choose a password. That link expires in 12 hours.
If it's expired — and it usually is, because people read the mail the next morning — there's nothing for you to do. They go to the sign-in page and use the forgot-password flow to get a fresh link themselves.
Someone who already had a UprootSecurity account is simply added to your organization. They get no email, and they sign in with the password they already have.
How do I make someone an administrator?
Promoting a synced person is how an admin is made. Open People Access, open the person, and set their User Role to Administrator, Member or Auditor. Owners and Administrators can do this; nobody else can. The Owner's own role can't be changed there.
That's the whole flow. If the person isn't in the list yet, they haven't synced — press Sync Users. What each role can actually do is covered in Roles and permissions.
What about my auditor?
Your UprootSecurity team sets the auditor up on your account — you don't have to arrange anything. If you're bringing your own auditor rather than using ours, ask your UprootSecurity contact to add them.
When someone leaves
The way you off-board matters, and the difference is easy to miss.
- Remove them from your identity provider. On the next sync they're marked inactive here, their outstanding compliance items stop counting against your tests, and UprootSecurity then checks the tools you've connected and alerts you about accounts the leaver still holds. That last part — the orphaned-account alert — is the reason to off-board at the source.
- Switch them off by hand here (the Active control on the person's record) and they're deactivated and their items stop counting, but the check for accounts they still hold never runs. You lose the alert.
So for a real leaver, remove them in your identity provider and press Sync Users. Either way it's reversible — switch Active back on and they're back.
For a contractor or anyone who shouldn't be measured but shouldn't be removed, mark them out of audit scope instead. Their items stop counting against your tests without deactivating them at all.
Common mistakes
- Waiting for a sync that never comes. Nothing is scheduled. If the directory changed, press Sync Users.
- Expecting your directory groups to appear. They don't sync — build the groups you need here.
- Chasing an expired set-up link on someone's behalf. They can fix it themselves in seconds — forgot password on the sign-in page issues a fresh one.
- Deactivating a leaver by hand instead of removing them at the source. It looks the same on screen, and you silently skip the check for accounts they still hold.
- Treating the employment status on someone's record as a switch. It's descriptive only — it doesn't change access, and it doesn't change how they're tested.
