Moderator

Moderator • LockSelf

The moderator


The moderator is identified by a grey crown. This account has full rights to manage users and shared spaces.

Important: the moderator cannot appoint other moderators, create sub-organizations, or manage the entire configuration of the environment: SSO interconnection, activation and renewal of the subscription.

Moderator rights

Action / Permission Main administrator Organization administrator Moderator

Management

Create / delete a user Yes Yes Yes
Create / delete a group Yes Yes Yes
Block / unblock a user Yes Yes Yes
Create / delete an organization Yes Yes No
Import / export users Yes Yes Yes
Create / delete an API user Yes Yes No
Create / delete a moderator Yes Yes No

Configuration

Enable / disable SSO Yes No No
Activate / renew the subscription Yes No No
Dashboard access Yes Yes Yes
Enable / disable SMTP Yes No No
Enable / disable White Label Yes Yes No

LockPass

Import passwords Yes Yes Yes
Export shared passwords Yes Yes Yes
Configure shared spaces Yes Yes Yes
Access management Yes Yes Yes
Manage shared passwords Yes Yes Yes

Promote a user to moderator

  1. From the Administrator account, click on the account to promote.
  2. Click on "Set as moderator".
  3. Confirm.

Demote a moderator to user

  1. From the Administrator account, click on the account to demote.
  2. Click on "Set as user".
  3. Confirm.

The blind moderator


The blind moderator is a moderator who manages users and shared spaces without accessing sensitive content (passwords). They keep their management rights but cannot view or use passwords.

Who can make a moderator blind?

An administrator of an organization higher up in the tree, from the moderator's profile panel, by enabling the "blind" toggle. The action is reversible.

What the blind moderator can do in a shared category

  • Manage access: add / remove users and groups, promote a manager.
  • Manage settings: monitor usage, hide passwords, allow editing / deletion.
  • Edit a category and delete an empty category.

What they cannot do

  • Delete a category containing at least one password.
  • View the sensitive information of a password.
  • Use a password (view it, copy it, use it).
  • Delete, move or edit a password.

Sensitive data: password, username, OTP, description, optional field 1, optional field 2, optional field 3.

Updated