User Management: Metric Reference
This page is the source of truth for the in-app Explain this panels on the
User Management page (/users). Each section is written once as
a content partial under _explain/users/ and rendered both here and inside the app's info panel
(scripts/build-explain.mjs compiles the registry).
User Management requires the ManageMembers permission, held by Admin and SuperAdmin by default.
Manage organization members, their roles, and pending invitations.
How it's calculated
- The page requires the ManageMembers permission, held by Admin and SuperAdmin only — every other role is kept off the route before it loads.
- The KPI strip always reflects the whole organization; the Members table below it is a separate, independently filtered and paginated view. Narrowing the table never changes the KPI numbers.
- Inviting a member sends an invite with an email, optional name, and a role. Editing a member changes name and role; email is fixed once an account exists.
Reading it
Use the KPI strip for a quick read on headcount and pending onboarding, then use the Members table's own filters — Role, Status, and Added date range — to find a specific person or audit a role assignment.
Total Members
How many members belong to the organization, regardless of status or role.
How it's calculated
- Counts every row returned by the unfiltered organization member list — not the Members table below, which can be narrowed by its own filters.
- Includes both Active members and members still in Invited status.
Reading it
This number won't move when the Members table is filtered or searched. If it looks wrong, check whether you're comparing it against a filtered table view rather than the organization as a whole.
Active
How many members have status Active.
How it's calculated
- Counts members from the unfiltered organization list whose status is Active — the status a member moves to automatically on their first successful login.
- Independent of the Members table's own Status filter; this KPI always reflects the whole organization.
Reading it
Active plus Pending Invite should equal Total Members — every member is in exactly one of those two states. A large gap between Total Members and Active can point to invitations that were never accepted.
Pending Invite
How many members are invited but haven't logged in yet.
How it's calculated
- Counts members from the unfiltered organization list whose status is Invited — the state every new member starts in until their first successful login flips it to Active.
- Independent of the Members table's own Status filter; this KPI always reflects the whole organization.
Reading it
A rising count with no matching Active growth usually means invitations are going out but not being completed — worth a follow-up nudge rather than assuming the invite failed outright.
Admins
How many members hold the Admin role.
How it's calculated
- Counts members from the unfiltered organization list whose role is exactly Admin. SuperAdmin is a distinct role and is not counted here.
- Independent of the Members table's own Role filter; this KPI always reflects the whole organization.
Reading it
Admin and SuperAdmin are the only roles that can manage members, view billing and audit logs, and manage integrations — see Roles & Permissions for the full breakdown by role.
Roles & Permissions
What each role can do across Logstag.
How it's calculated
- Admin and SuperAdmin hold every permission: managing members, billing, API keys, databases, agents, alerts, and integrations, plus viewing databases, alerts, billing, and audit logs.
- DBA holds ManageDatabases, ViewDatabases, ManageAlerts, and ViewAlerts — full control over monitored databases and alerting, but no access to members, billing, or audit logs.
- Dev holds ViewDatabases and ViewAlerts only — read access to monitoring, no management actions.
- Billing holds ManageBilling and ViewBilling only — access to billing screens and nothing else in the product.
- Roles are assigned per member from the Invite or Edit dialog. A member can only ever hold one role at a time.
Reading it
Permission, not role name, is what actually gates a screen — for example Audit Logs is gated by the ViewAuditLogs permission, which today only Admin and SuperAdmin carry. Assign the narrowest role that covers what a member needs to do.
Members
Every organization member, searchable and filterable by role, status, and when they were added.
How it's calculated
- Columns: avatar initials, Name / Email, Role, Status, and Last login (or "Never" if the member hasn't logged in yet).
- Backed by a paginated, filtered endpoint — search text, the Role and Status column filters, and the Added date range all round-trip to the server. This is a different query from the KPI strip above, which always reads the full organization.
- Status shows Active or Invited as a colored badge; Role shows Admin, DBA, Dev, or Billing (SuperAdmin members don't appear editable from this table the same way, since role changes go through the same Edit dialog).
- Edit opens a dialog to change first name, last name, and role; email cannot be changed once a member exists. Inviting a new member is a separate action from the toolbar above the table.
Reading it
Use the Added date range together with Status to find recent invitations that are still pending, or filter Role to review who currently holds elevated access.