Skip to main content
System and administration

Team Management

See who works tickets and who can sign in, check that each person's HaloPSA agent and QuantumOps login are linked, and manage invitations, roles and sign-in from one screen.

Written By Chris Scaminaci

Last updated About 1 hour ago

Team Management lists the people who work tickets in HaloPSA and the people who can sign in to QuantumOps, and joins them into one row per person. Administrators use it to see who is linked, invite people, give them roles and manage their sign-in. The page subtitle names the sign-in service that holds your logins.

Before you start: you need the Administrator role. Logins are listed only when multi-user access is on for your organisation. In single-user mode every agent shows as Agent only and the Invite user button in the header is hidden. Instances that went through the setup wizard have multi-user access on. Which actions appear on a row depends on your sign-in service; see what each sign-in service offers.

Open Team Management

  1. In the sidebar, under Configuration, select Team Management. You can also select the people icon in the header, whose hover text is Multi-user management. On a phone, open More actions in the header and choose Multi-user management.
  2. Read the counters at the top, then use the three tabs: Team Members, Import and Organization.

The older addresses /agent-analysis and /multiusers open the same screen, and /team-management?tab=org opens the Organization tab.

Only the Administrator role can open the page. The sidebar link shows only to Administrators; the people icon in the header shows to everyone, but the page refuses anyone else. See Access denied and sign-in errors.

Refresh at the top reloads the list and the role list from your sign-in service. On the Team Members tab, Invite user sits beside it when multi-user access is on and your sign-in service can invite.

How people are joined

A person can exist in two places. They are an agent in HaloPSA, where tickets come from, and they are a login in your sign-in service. Team Management shows whether the two halves are connected.

CounterWhat it means
Team MembersEveryone, whatever the search box and filters show. People marked inactive count only while Show inactive is ticked.
Fully LinkedThe HaloPSA agent and the login are connected. This is where everyone should end up.
Agent OnlyA HaloPSA agent without a login. Their ticket work is analysed and counted, but they cannot sign in.
Login onlyA login without a HaloPSA agent. They can sign in, but no ticket work is attributed to them.

Under the counters, small pills count the logins that need attention. They appear only when the count is above zero.

PillWhat it counts
invitedInvitations that were sent and have not been accepted yet.
sign-in disabledLogins an Administrator disabled.
lockedLogins the sign-in service locked, usually after repeated wrong passwords.

The counters and pills do not follow the search box or the status, team and role filters; only Show inactive changes them. With a filter applied they can differ from what the list shows.

A login joins an agent automatically when their e-mail addresses match; capital letters do not matter. When they differ, for example because HaloPSA holds a personal address, an Administrator can join them by hand. See Inviting people, roles and agent links. A link made by hand wins over e-mail matching from then on.

Linking matters because a linked person is recognised as that HaloPSA agent:

  • Ticket work is attributed to them. A Login only person has no HaloPSA agent, so none is.
  • The browser extension knows which agent is signed in, so its actions and its Clock tab work. See What each part of the extension needs.
  • Assign to me on a Q-Notice card in Slack or Teams knows which HaloPSA agent to assign the ticket to.

Find people

Above the list you can narrow what you see:

  • The search box matches name, e-mail address and team.
  • All statuses limits the list to Fully linked, Agent only or Login only.
  • All teams limits it to one HaloPSA team.
  • All roles limits it to people who hold one role. It appears when at least one person holds a role.
  • Show inactive brings back people marked inactive. It is off by default, which is why a colleague you marked inactive seems to have vanished.

Table view and Card view switch the layout; the cards show the same people and the same actions.

Export CSV downloads the people currently in view as a file named like team-members-20261006-1530.csv. Its columns are Name, Email, Team, Agent role, Shift, Link status, Login state, the roles column, Language, Supervisor, Inactive, Halo agent id and Login id.

To act on several people, tick the box at the start of each row, or the box in the header to tick everyone in view. A bar shows how many are selected, with Invite selected and Clear. Invite selected invites only the selected people who have an e-mail address and no login; if none qualify, a message says so. See Inviting people, roles and agent links.

Read a row

ColumnWhat it shows
NameThe person's name. A star beside it marks a timeclock supervisor.
EmailThe e-mail address on the agent record or on the login.
TeamThe HaloPSA team, or a dash when there is none.
RoleThe agent role set in Edit details: Agent (the default), SDM_Primary, SDM_Secondary or Dispatch. A login without an agent shows a dash.
ShiftThe agent's shift hours, or a dash for a login without an agent.
StatusThe badges described below.
RolesThe roles the person holds in your sign-in service. The column is headed with the service's name.
LangEN or ES, the person's interface language. Hover to see whether it is the organisation default.
ActionsThe buttons described below.

The Role column and the roles column are two different things. Role is the agent role, and the roles column holds sign-in roles. In the badge table below, SDM is the Service Desk Manager sign-in role and Dispatch is the Dispatcher sign-in role. Neither is the SDM_Primary or Dispatch agent role.

The Status badges are:

BadgeMeaning
Linked, Agent only, Login onlyThe link state, as in the counters above.
InvitedThe first sign-in is not finished yet.
DisabledAn Administrator disabled the sign-in. The row is dimmed.
LockedThe sign-in service locked the account.
InactiveThe person is marked inactive in QuantumOps. The row is dimmed.

Sign-in roles live in your sign-in service, not in QuantumOps. A role you add or remove here takes effect at the person's next sign-in. A session that is already open keeps its old roles for up to 8 hours, so ask the person to sign out and in again if they need the change straight away. Unavailable in the roles column means the roles could not be read just now; it does not mean the person has none. No roles means they hold none. Badges use short names; hover over a badge for the full role name.

BadgeRole
AdminAdministrator
SDMService Desk Manager
DispatchDispatcher
TechTechnician
CSCustomer Success
ClockTimeclock
Clock AdminTimeclock Admin
PayrollPayroll Admin
AccountantPayroll Accountant
Q-DirectorQ-Director Configuration
NoticeQ-Notice Creator
Notice EditQ-Notice Editor
Notice AdminQ-Notice Admin
PartnerWhiteLabelPartner
ID VerifyIdentity Verification Admin

See Roles and access for what each role opens.

Act on a person

Three actions appear as icon buttons on the row; hover over an icon to see its name (Edit details, Manage roles, Invite to QuantumOps). The others are under the More actions button (the three dots). A row offers only the actions that apply to that person and that your sign-in service supports.

ActionAppears whenWhat it does
Edit detailsAlways.Opens the person's details. See Inviting people, roles and agent links.
Manage rolesThe person has a login.Sets the person's complete role list in one step.
Invite to QuantumOpsThe person has an e-mail address and no login.Invites them to sign in.
Resend inviteThe login is Invited and your service can resend.E-mails a fresh invitation link. Earlier links stop working. If no invitation can be sent again, a password-setup e-mail goes out instead and a message says so.
Send password resetThe login can sign in and has an e-mail address.E-mails a link to choose a new password. The current password keeps working until the person uses the link.
Unlock accountThe login is Locked.Lets the person try to sign in again.
Reset multi-factorThe login can sign in.Removes the person's authenticator app, SMS or e-mail codes and security keys; passkeys are not removed. They set up a second factor again at their next sign-in. If they had none, a message says there was nothing to reset.
Disable sign-in / Enable sign-inThe person has a login. The button shows the opposite of the current state.Stops or restores sign-in without deleting anything. The account, its roles and its history are kept, and open sessions end when they next refresh. The same account may be used for other TechPulse products, so disabling it stops those too.
Link a HaloPSA agentA login without an agent.Joins the login to a HaloPSA agent by hand.
Link a loginAn agent without a login.Joins the agent to a login by hand.
Remove from organisationThe person has a login.Removes their access to this organisation. The account itself is kept, so other TechPulse products are unaffected.

Every action that changes someone's access opens a confirmation first. The confirmation explains the effect, and its button repeats the action: Resend invite, Send reset, Enable sign-in, Unlock, and, in red, Disable sign-in, Reset multi-factor and Remove. Select Cancel to leave things as they are. The reset confirmation also reminds you to confirm the person's identity another way first, because until they set up a second factor again their password alone signs them in.

These safeguards apply:

  • You cannot disable your own sign-in or remove yourself from the organisation here. A message tells you so.
  • You cannot remove your own Administrator role.
  • The last Administrator keeps the role. Give it to someone else first.

What each sign-in service offers

The page offers only what your sign-in service can do from QuantumOps. The page subtitle and the roles column name the service your instance uses.

ActionZitadelAuth0Microsoft Entra ID
Invite peopleYesYesNo
Manage rolesYesYesNo
Send password resetYesYesNo
Resend inviteYesNoNo
Disable sign-in / Enable sign-inYesNoNo
Unlock accountYesNoNo
Reset multi-factorYesNoNo
Link a HaloPSA agent / Link a loginYesNoNo
Remove from organisationNoYesNo
  • With Zitadel, an account belongs to one organisation and is shared with other TechPulse products, so QuantumOps never deletes it. Disable sign-in takes the place of removal.
  • With Auth0, the page does not report invited, locked or disabled states, so those badges do not appear, and a pending invitation is not listed until it is accepted.
  • With Microsoft Entra ID, QuantumOps cannot manage logins. The page lists your HaloPSA agents and a note says that sign-ins are managed in your Microsoft Entra tenant, where you assign app roles to the QuantumOps application.

If the page shows a message instead of logins

  • A note beginning Single-user mode means logins are not listed and Invite user is hidden. The note points to Tenant Settings, but multi-user access is not switched on there: contact TechPulse. Instances set up with the setup wizard have multi-user access on. See Getting help.
  • A red banner reading Sign-in organisation misconfigured. means the organisation stored for your instance does not match your sign-in service, so no logins can be listed. Contact TechPulse.
  • A yellow note beginning Logins could not be listed or Role assignments means the sign-in service did not answer in full. Select Refresh. If it persists, contact TechPulse.