Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Users, roles and paid seats. Company administrators manage their own users; billing contacts manage purchases; TLS owners retain platform and deployment authority. Current availability: Available workflow. Before you start. An active company and verified contacts. Step 1. Open Companies > company > Users as the owner, or Company > Users as a company administrator. Add a full name, an address within the registered primary domain and the appropriate role. Step 2. Choose one canonical company role: Company owner, Company administrator, Support manager, Security administrator, Device manager, Knowledge manager, Billing administrator, Auditor, Company user or Executive viewer. Legacy client_admin, billing, requester and executive records map safely to their canonical replacements. No company role grants TLS staff, platform-owner, deployment or secret-vault authority. Step 3. Create a manual access group for immediate company-only role assignment. For a dynamic Microsoft Entra, Google Workspace, Okta or OneLogin group, open Provider membership and synchronization, read the group, explicitly link immutable provider identities to existing active company users, then review and enable synchronization. Matching email addresses alone never grant access. See the Company identity-group synchronization guide. Step 4. Use a temporary delegation for a specific permission and business reason. Delegations expire within 30 days, can be revoked early and never change the user’s base role. Company owners cannot create another Company owner, and Company administrators cannot create peer administrators; TLS retains platform authority. Step 5. Pending invitations, active and inactive non-deleted users reserve a paid seat. Add licenses in Billing before adding or restoring a user beyond capacity. Step 6. Use Activate access after adding an approved user. Identity provisioning requires the configured production service; test environments do not invoke production identity activation. Step 7. Use Disable or Revoke sessions for immediate access changes. Delete uses the existing 60-day recovery workflow; restore is checked against the current paid seat limit. Step 8. Keep at least one active company administrator. Database constraints protect this rule even if two administrators attempt a change at the same time. Paid-term expiry preserves access to billing while service access requires renewal. Now verify the result. A Company user cannot change prices, approve payments or view other-company records. A company administrator cannot promote themselves, assign a peer administrator, create a Company owner or obtain TLS platform permissions. An extra user beyond the paid seat count is rejected, including concurrent requests. If you get stuck. Account at its limit: request more seats or remove a departed user through the documented offboarding flow. A pending invite still consumes a seat. Do not assume inactive means unlicensed. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.