> ## Documentation Index
> Fetch the complete documentation index at: https://www.marqeta.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Managing User Access with UAM

> Learn how to invite, manage, and remove users in User Access Management (UAM).

<Note>
  **Note**<br />User Access Management (UAM) launches October 1, 2026 for the Disputes portal only.
</Note>

User Access Management (UAM) is a self-serve tool where Customer Admins can manage who within their organization can access Marqeta products and what they can do once they have access. As a Customer Admin, you use UAM to invite users, assign their programs, products and role access, managing their access over time without the need to contact Marqeta.

This guide covers what you're responsible for as a Customer Admin, and how to get help if something doesn't go as expected.

<h2 id="_quick_reference">
  Quick reference
</h2>

The table below provides an overview of the tasks you can perform using UAM. The rest of this guide goes into detail on each row.

| Task | Description |
| - | - |
| Inviting users | Sending invites (to up to 10 users at a time) <ul><li>Choosing the program(s), product, and role(s) for each user is a required part of the invitation step.</li></ul> |
| Managing account recovery | Managing user Password and MFA resets. |
| Changing a user's programs | Updating user access to programs.<br />The changes takes effect at the user's next login, not immediately. |
| Changing a user's product and role | Updating what a user can do, including promoting or demoting other customer admins in your organization. |
| Deactivating and reactivating users | Changing a user's access within UAM on or off. Deactivating a user will remove all product, project, and role access. Reactivating a user will re-enable the access they have before deactivation. |

<h2 id="_inviting_users">
  Inviting users
</h2>

Inviting users into UAM gives you the ability to manage their access to Marqeta products. When inviting a new user you will be required to select the program(s) they have access to, and the product and role(s) within each program. If a user needs access to more than one product, repeat the invite for that user.

<Note>
  You can send up to 10 invites in a single submission, and every invite in that submission shares the same role, programs, and product. Users who need different access must be invited separately. You cannot submit two invites for the same email address in one batch.
</Note>

1. Under **User Management** in the side navigation bar, select **Invite**.
2. Enter the email address(es) of the people in your organization you want to give access to.
   <Note>
     Add up to 10 emails, every email account in a submission will receive the same access.
   </Note>
3. From the **Programs** dropdown, select the program(s) the user will need to access. You must select at least one program.
4. From the **Product** drop down, select the product(s) you would like to give the user(s) access to.
5. From the **Roles** drop down, select the role(s) you would like to give the user(s) access to. You must select at least one role.
6. Select **Review**.
7. Check that the users you are inviting are the correct recipients with the correct program(s), product, and role(s) assigned. Select the **Confirm** button to send the invite.

After you submit an invite, it moves to **Pending** and can be viewed in the [**Pending** tab](#pending_tab).

Once the person accepts the invitation and sets up multi-factor authentication (MFA) or single-sign on (SSO), they move from the **Pending** tab to the [**Users** tab](#Users_tab) and their status is set to **Active**.

<h2 id="_managing_the_user_listing">
  Managing users
</h2>

Managing invited users can be done in the **Pending** and **Users** tabs. The **Pending** tab contains a listing for users who have an invite that is pending action or has failed. Each row shows the user's email, program(s), product(s), and actions the admin can perform for that user. The **Users** tab contains a listing for each user that has successfully accepted their invite and set up MFA or SSO.

### Pending tab

On the **Pending** tab you can view a list of users that have yet to accept their invite and set up MFA or SSO. From here you can copy and manually resend the invitation link, resubmit a failed invite creation, or revoke a pending invite, depending on the Status.

#### **Actioning on an invite status**

Before a user accepts their invite they are in a holding pattern inside the Pending tab. Here you can see if the invite has failed. Note that expired invitations will not be listed. If you do not see a user you previously invited, please run through the invite process again.

The following actions are available based on the user's status in this tab. Select the action you would like to apply to the user:

| Status | Available actions |
| :- | :- |
| Invited | <ul><li>Copy link - requires you to manually send the link to the user in question.</li><li>Revoke - revokes the invitation.</li></ul> |
| Creation Failed | <ul><li>Retry - resubmits the users invite.</li></ul> |

### Users tab

On the **Users** tab, you can view users who are currently set to a status of Active, or have at one point been Active users. <br /><br />From this tab you can filter the results down by status, created date, last login date, and the number of logins.

<Warning>
  **Warning**<br />You can't demote or deactivate yourself, and your organization can never be brought down to zero customer admins.
</Warning>

#### **Deactivating a user**

Deactivating a user means they will lose access to all products immediately. The user can be reactivated later, restoring their prior roles and programs.

To deactivate a user with a Status of **Active** do the following:

1. In the User's tab, navigate to the user you would like to deactivate. To deactivate a user, they must have a Status of Active.
2. Navigate to the **Actions** column.
3. Select the deactivate icon in that user's row.

#### Reactivating a user

To Reactivate a user with a Status of **Deactivated** do the following:

1. In the User's tab, navigate to the user you would like to reactivate. To reactivate a user, they must have a Status of **Deactivated**.
2. Navigate to the **Actions** column.
3. Select the reactivate icon in that user's row.

<Note>
  Reactivating a user restores their prior programs, product, and roles as they were before deactivation.
</Note>

#### **Editing a user's programs, products, and roles**

To edit a user's programs, products, and/or roles, do the following:

1. In the User's tab, navigate to the user you would like to update.
2. Select the user's row. This opens the user details pane.
3. Select the edit icon next to the user's programs, products, and roles to edit the selections.
4. When finished with your edits, select **Review changes**.
5. Review your changes and select **Confirm changes**.

<Note>
  Users must have access to at least one product, project, or role. Changes take effect at the user's next login.
</Note>

#### Viewing a user's organization

Users are always associated with an organization. To view a user's organization do the following:

1. In the User's tab, navigate to the user in question.
2. Select the user's row. This opens the user details pane, where their organization is listed.

<Note>
  Bulk actions are not available at launch, and editing user access must be done one user at a time.
</Note>

#### **Managing user credentials**

Customer Admins can help users manage their credentials by setting up a password or MFA reset. They can also prompt an end to all active sessions for a user, triggering the re-login that is necessary to apply account changes.

To manage a user's credentials, do the following:

1. In the User's tab, navigate to the user in question.
2. Select the user's row. This opens the user details pane.
3. Select one of these user credential management options:
   | Button | Description |
   | - | - |
   | End sessions | This will log the user out of any active sessions they are in. This is useful when you require a user to re-login in order to see any account changes you have applied. |
   | Reset password | This sends the user a password reset link. The user will no longer be able to log in with their current password. |
   | Reset MFA | This clears the user's registered authenticator. They'll be prompted to enroll a new one at next sign-in. |
   | Deactivate | This immediately removes a user's access to all products. The user can be reactivated later, restoring their prior roles and programs. |

## Audit actions

The **Audit** tab provides Admin users with a record of every access change that has been made in their organization. Customer Admins can search for results and filter the list down based on actions performed, who performed the action, and date range in which the action was performed.

<h2 id="_getting_help">
  Getting help
</h2>

If something doesn't match what's described here, or a user gets stuck partway through a flow (for example, an invite stuck in a failure state, or a role or program change that isn't reflecting after a the users next login), try the following:

* Check the user listing first. Most stuck states, including pending or failed invites, can be regenerated or copied and manually resent to the user, directly from a user's row.
  <Note>
    If a user's invite isn't successfully actioned on within 7 days, it expires and the process must be started again for that user.
  </Note>

* If a change hasn't applied yet, confirm whether the user has refreshed their session. Program and role changes apply at the user's next login, not immediately.

* For anything this guide doesn't cover, or an error you can't resolve, contact support via our [support portal](https://customers.marqeta.com/) with the user's email, the action you were trying to take, and roughly when it happened.


## Related topics

- [UAM Roles and Permissions](/docs/developer-guides/user-access-management-roles-permissions.md)
- [Risk, Fraud, & Disputes Release Notes](/docs/developer-guides/risk-fraud-disputes-release-notes/2026.md)
- [Managing User Profiles in the Marqeta Dashboard](/docs/developer-guides/user-profiles-dashboard.md)
- [Managing Customers in the Marqeta Dashboard](/docs/developer-guides/customers-dashboard.md)
- [Users](/docs/core-api/users.md)
