Blumira Users · diff
git:20260728.b7e78fc to git:20260804.f49efe8
11 added, 0 removed. Audit A to A.
---
name: "Blumira Users"
description: >
Blumira organization users: listing and filtering users, user roles, and looking
up the user IDs required for finding assignment and access audits.
when_to_use: >-
When you need a Blumira user ID or are auditing who has organization
access. Use when: blumira user, user list, assign user, or user management.
---
# Blumira Users
## Overview
Blumira users are organization members who can access the portal, investigate findings, and manage the environment. This skill covers user listing and lookup, primarily for finding assignment workflows.
+ ## Anti-triggers
+
+ - **The end user named in a finding** — these are Blumira *portal*
+ members (your analysts), not the M365 or AD account that triggered a
+ detection. Look that account up in `cipp-users` or
+ `inforcer-identity-governance`.
+ - **Creating, disabling, or offboarding anyone** — Blumira's user
+ surface is list-only; account lifecycle is `cipp-users`.
+ - **Users in a managed client account** — `blumira_users_list` is an
+ `/org/*` call; use `blumira_msp_users_list` in `blumira-msp`.
+
## Key Concepts
### User Roles
Users have roles that determine their permissions within the Blumira organization. The API exposes user identity and metadata for assignment and audit purposes.
### User IDs
User IDs (UUIDs) are required when assigning findings to specific analysts. Use `blumira_users_list` to look up IDs.
## API Patterns
### List Users
```
blumira_users_list
page_size=50
```
Response includes user ID, name, email, and role information.
### Filter Users
```
blumira_users_list
email.contains=@company.com
```
## Common Workflows
### Find User for Assignment
1. `blumira_users_list` to get all users
2. Identify the appropriate analyst by name or role
3. Use their `user_id` with `blumira_findings_assign`
### User Access Audit
1. `blumira_users_list` with full pagination
2. Review all users with access to the organization
3. Cross-reference with HR/directory for offboarded users
4. Report any discrepancies
## Error Handling
### Empty User List
**Cause:** Token may not have permission to list users
**Solution:** Verify JWT token has appropriate scope for user management.
## Best Practices
- Cache user lists during triage sessions to avoid repeated API calls
- Use email filtering to quickly find specific users
- For MSP environments, use `blumira_msp_users_list` with account context
- Document user-to-role mappings for escalation workflows
## Related Skills
- [Findings](../findings/SKILL.md) — Assigning findings to users
- [API Patterns](../api-patterns/SKILL.md) — Filtering and pagination
- [MSP](../msp/SKILL.md) — Per-account user management