# Create Your First User

> Add team members to your CloudRepo organization: create a user, set read-only access and administrator permissions, change a password, remove a user.

Your own login administers the account. To publish artifacts to your repositories, or to retrieve them, your team needs *repository users*: accounts you create in the admin portal, each with an email address and a password.

This guide walks through creating one and setting what it can do.

## How Access Works

Two things control what a repository user can do, and both are set on that user’s settings page after the account exists:

- *Repository access is account wide.* A user either has read and write access to every repository in your account, or read only access to every repository. There is no per repository assignment.
- *Administrator permissions are granted one area at a time*: billing, repositories, software distribution, users and webhooks. A user you create has none of them.

## Creating a User

### Step 1: Open the Users Page

1. Log in to the [CloudRepo Administrator Portal](https://admin.cloudrepo.io)
2. Click **Users** in the sidebar
3. Click **Create User**

Until you have created anyone, the page reads “No users yet” and offers a second **Create User** button in the middle of the page. Either one opens the same form.

### Step 2: Fill In the Form

The **Create a Repository User** form asks for three things:

1. **Email Address** - this becomes the username for repository access
2. **Password** - at least 8 characters
3. **Confirm Password** - must match the password

Each password field has an eye icon on the right that reveals what you have typed.

The **Create User** button at the bottom of the form stays disabled until all three are valid. A password under 8 characters is marked `Password must be at least 8 characters`, and a confirmation that differs is marked `Passwords do not match`.

![Email Address holds jordan.kim@example.com; the password and its confirmation are entered.](/docs/_astro/shots/users/3-details.fc6ca41d72127926.png)

### Step 3: Create the Account

Click **Create User**. If you have not confirmed your identity in the last 15 minutes, a **Confirm Your Identity** dialog comes first: enter your password and click **Confirm**. The portal then returns to the **Repository Users** list with the new account in it.

![The Confirm Your Identity dialog asks for your password before the user is created.](/docs/_astro/shots/users/4-confirm-identity.2e0c272714dd6046.png)

![jordan.kim@example.com is now in the list with Read + Write.](/docs/_astro/shots/users/5-created.8ff2a5cda47510ca.png)

You chose this user’s password, so you are the only one who has it. CloudRepo does not email it to them. Send it over a channel you trust, and send it on its own.

## Changing What a User Can Do

Click a row in the **Repository Users** list to open that user’s **User Settings** page.

### Read Only Access

A new account gets your own repository access. When you have read and write access, **Read Only User** is off for it, which the page states as “User has read and write access to all repositories”. Turn it on to limit that user to reading.

### Administrator Permissions

Five toggles delegate account administration, one area each:

- **Manage Billing**
- **Manage Repositories**
- **Manage Software Distribution**
- **Manage Users**
- **Manage Webhooks**

They are independent of repository access, and they are all off for a user you create. See [User Management](/docs/manage/users.html) for what each one covers.

### Changing a Password

Click **Change Password** on the user’s settings page. The **Manage Member** page that opens asks for a **New Passphrase** and a **Confirm New Passphrase**.

## Removing a User

1. Open the user’s settings page from the **Repository Users** list
2. Click **Delete User**
3. Type the user’s email address into the confirmation box. The dialog warns that “This action cannot be undone. The user will be permanently removed”, and its **Delete User** button stays disabled until the address matches
4. Click **Delete User**

## Best Practices

- *Grant the minimum.* A user you create starts with your own repository access: read and write when you have it. If the account only needs to download artifacts, turn on **Read Only User** as soon as you have created it.

- *One account per person, and one per system.* Give a CI pipeline its own repository user rather than sharing a teammate’s, so that removing one never interrupts the other.

- *Review the list periodically.* The **Repository Users** page shows every account and its access level in a single table.

## Troubleshooting

- *A user can download but cannot upload*: check whether **Read Only User** is turned on for that account. Open their settings page and turn it off to restore write access.

## Next Steps

- [Repository Tokens: Create One and Authenticate](/docs/authenticate/repository-tokens.html) - Sign in as the new user and create the repository token its builds send, with the user’s email address as the username
- [Basic Configuration Examples](/docs/quick-start/basic-configuration.html) - Configure your development tools
- [User Management](/docs/manage/users.html) - Full reference for user settings and permissions
- [Continuous Integration and Deployment](/docs/integrations/cicd/overview.html) - Set up CI/CD integration

---

The page: https://www.cloudrepo.io/docs/get-started/add-users.html
