Users is the directory of your organization — who is here, what they can do, and which AI tools they have connected. An Admin and an Analytics Viewer see everyone; a manager sees themselves and their reports; anyone else sees only their own row.
What’s on the page
Tabs
User table
Department and Manager come from your identity provider, so they are changed there rather than here. See Settings → Integrations.
Rows named after a serial number
During an MDM rollout you may see rows whose name and email are a hardware serial at your organization’s email domain —C02XK1ABCDEF@yourcompany.com — with an information icon beside the email pointing at Settings → Devices. Nothing is broken: each row stands in for one device whose owner is not yet known.
These rows read Accepted in the Status column like anyone else, so the serial-shaped email and that icon are what identify one.
A stand-in persists for as long as the serial has no owner attached to it. Resolve one by mapping the serial to a person on the Devices tab of Settings, or by making sure the connected MDM reports a first and last name for that serial.
User Groups
Groups scope policies. They carry no permissions of their own — a group decides which policies reach someone, not what they may do in the dashboard.Unbound Setup in the side panel
A person’s panel shows an Unbound Setup section headed Setup Tampered, listing each machine by serial number with one line per tool:Filters and controls
Search by name, email… filters the directory, from three characters up. Search members… is the picker inside a group. The Unbound Setup filter is held in the URL as
?tampered=true, so a filtered view can be shared.
What you can do
Both bulk changes confirm first, listing every person you picked with the value they move from and to. Anyone already at the target value reads No change and is left alone; if that is the whole selection, the dialog is skipped and the page says No changes needed. Role and Status can also be changed one person at a time, from the badge in their row.
Person panel
Developers can repair their own machines with
unbound doctor --fix. Where a tool was set up by the organization, the command says so and prints the form to run instead: sudo unbound doctor --fix, or the same command in an Administrator terminal on Windows.
Messages you may see
Common questions
Why is a developer being blocked? Select them and read the Policies section of their panel, which resolves every policy reaching them across all their groups, grouped into Tool, Security, Model and Cost. How do I give someone access to Unbound? Invite User, which is an Admin action. Why can a colleague see something I cannot? Roles differ in what they reach. The role table lists which parts of the dashboard each role uses. A developer’s Unbound setup shows as removed — what now? Their panel lists the affected machines and tools. They rununbound doctor --fix; if a tool was set up by the organization, the command names it and prints the form to run instead — sudo unbound doctor --fix, or the same command in an Administrator terminal on Windows.

