Features that control how users are created, organised, and managed within your Tribal Habits portal.
Last updated 23/06/2026
Admins can create individual users via a form in Admin > People, populating standard fields (first name, last name, username, email, type, manager emails) and any configured custom fields. Existing user profiles can be edited at any time. Admins can also reset passwords, resend invitation emails, and manage access permissions from the user profile.
Gives admins full control over who exists in the portal and what information is stored against each person. Keeps user data accurate and up to date without requiring technical skills or external tools.
Last updated 23/06/2026
Admins can create, update, or deactivate multiple users at once by uploading a CSV file via Admin > People > Bulk upload or enrol. Column headers are mapped to standard and custom fields during the import process. Up to 1,500 records can be processed per upload. The same function supports importing historical enrolment data.
Eliminates the need to manually create or update large numbers of users one at a time. Particularly useful at implementation, during organisational changes, or when syncing data from another system without a direct integration.
Last updated 23/06/2026
Every user must be assigned a Type, which is a required standard field defaulting to ‘Staff’. There are 17 type options available (e.g. staff, contractor, volunteer, client). Type is used for filtering in reports, and can be used as a condition in automated enrolment and catalogue rules. The type assigned to users created via self-registration tokens can also be configured per token.
Allows organisations to segment their user base — for example separating staff from contractors or volunteers — and then use those segments to control what training each group sees or is automatically enrolled in.
Last updated 23/06/2026
Admins can create up to 20 custom fields to store organisation-specific user data beyond the standard fields. Field types include text, date, number, and list (single or multi-select). Each field has configurable visibility: filterable in reports, visible to the learner on their own profile, and/or visible to assessors. Custom fields can be populated individually, via CSV upload, or through integrations.
Enables organisations to store and filter on data that is unique to their structure — such as location, department, job title, or employment status. This data then drives smarter reporting, automated enrolments, and catalogue rules without needing a separate HR system to manage it.
Last updated 23/06/2026
Every portal includes Super Admin access, which provides full, unrestricted access to all platform settings, people, knowledge, and reporting. Any number of users can be granted Super Admin access at no additional cost.
Organisations can give as many people as needed full admin access without worrying about per-seat admin charges — a common limitation on competing platforms. Useful for organisations where multiple team members share responsibility for managing training.
Last updated 27/08/2026
In addition to Super Admin, organisations can assign more granular admin roles to users: Standard Admin (day-to-day management, no high-level account settings), Knowledge Admin (manage training only, view-only people access), Instructor Admin (manage enrolments only), People Admin (can create and edit people, but cannot access topics, pathways), Observer Admin (read-only across people and knowledge), Reporting Admin (analytics access only), Restricted Admin (specific report access only) and Library Admin (can only review library content). Each level is assigned individually by a Super Admin via the user’s profile.
Allows larger organisations to distribute admin responsibilities without giving everyone full access. Regional coordinators, L&D team members, or compliance officers can each be given exactly the access they need – no more, no less – protecting data integrity and reducing the risk of accidental changes.
Last updated 23/06/2026
Select admins can be granted the permission to temporarily impersonate any non-admin user in the portal. When impersonating, the admin sees the platform exactly as the learner sees it and can perform actions as if logged in as that user. Impersonation is enabled at two levels: first at the portal level (toggled on at Admin > Account > Subscription by a Super Admin), then per admin user (enabled individually via Edit Permissions on the admin’s profile). To begin impersonation, the admin navigates to the learner’s profile, selects Impersonate User from the I Want To menu, enters a reason, and confirms authorisation. A floating bar is displayed during the session identifying the user being impersonated. Sessions are capped at 15 minutes and end automatically. Impersonation cannot be used on other admin users. All impersonation activity — start, stop, and any actions taken during the session — is recorded in the Timelines report for both the admin and the learner, with a note identifying that the action was performed via impersonation.
Eliminates the most frustrating support scenario — a learner reports being stuck but the admin cannot reproduce the issue from the admin view. Rather than asking the learner to describe what they see or share screenshots, the admin can view the platform exactly as the learner does and resolve the issue directly. The 15-minute session cap and mandatory reason entry ensure the feature is used appropriately, and the full audit trail in Timelines provides accountability for every impersonation session.
Last updated 23/06/2026
Up to five manager email addresses can be assigned to each user. Managers do not need to be users in the portal — an external email is sufficient for receiving notifications. Team Leaders are managers who are also active users in the portal, giving them access to a Team page where they can view their team’s training status, enrol members in training, and subscribe to monthly team report emails.
Connects training visibility to existing management structures. Managers stay informed of their team’s compliance and progress without needing admin access. Team Leaders can take action on behalf of their team directly from their learner dashboard, reducing the admin burden on central teams.
Last updated 23/06/2026
Admins can deactivate users individually via their profile, in bulk via the People page, or via CSV upload. Deactivated users cannot log in but retain all their data and training history and can be reactivated at any time. Deletion permanently removes all user data and training history and cannot be undone. Both actions are available via bulk selection on the People page.
Deactivation is the recommended approach for managing leavers or temporary departures — it preserves training history for audit and compliance purposes while preventing portal access. Deletion is available for cases where data removal is required (e.g. for privacy compliance).
Last updated 23/06/2026
A future deactivation date can be set on any user profile, via CSV upload, or via the API. On that date, the platform automatically deactivates the user. Similarly, a reactivation date can be set to automatically reinstate a deactivated user on a specified future date. Both dates are visible on the People page as filterable fields. Optional automated notification emails can be configured to alert users ahead of their deactivation or upon reactivation.
Removes the need for manual follow-up when managing users with known end dates — such as contractors, secondees, or employees on parental leave. Reactivation scheduling is equally useful for automatically restoring access after a planned absence, ensuring the user returns to an active account without admin intervention.
Last updated 23/06/2026
Admins can enable a publicly accessible registration page and create unique token codes tied to specific topics or pathways. When an external user visits the registration page, enters their details and a valid token, they are automatically created as a user and enrolled in the associated training. Each token can be configured with a usage limit, an expiry date, a user type, and an optional auto-deactivation period. Token usage is tracked via the Tokens report in Analytics.
Allows organisations to onboard external users — such as contractors, volunteers, or customers — into specific training without admin involvement. Particularly useful for high-volume or repeating cohorts where manual user creation would be impractical. Tokens can be distributed in induction packs, emails, or onboarding portals.
Last updated 23/06/2026
Super Admins can create a list of named groups and assign users to one or more groups. Once groups are enabled, all admins (except Super Admins) and assessors have their visibility in the admin area restricted to only users within their assigned groups. Groups can be assigned individually, via bulk action, via CSV upload, or through integrations. Groups can also be used as a filter condition in catalogue and automated enrolment rules.
Designed for larger organisations with regional or divisional admin structures. Prevents admins from viewing or managing users outside their area of responsibility, supporting privacy requirements and operational boundaries. Eliminates the risk of a Brisbane-based admin inadvertently modifying records for users in another division.
| Cookie | Duration | Description |
|---|---|---|
| __cf_bm | 1 hour | This cookie, set by Cloudflare, is used to support Cloudflare Bot Management. |
| __hssc | 1 hour | HubSpot sets this cookie to keep track of sessions and to determine if HubSpot should increment the session number and timestamps in the __hstc cookie. |
| __hssrc | session | This cookie is set by Hubspot whenever it changes the session cookie. The __hssrc cookie set to 1 indicates that the user has restarted the browser, and if the cookie does not exist, it is assumed to be a new session. |
| __stripe_mid | 1 year | Stripe sets this cookie to process payments. |
| __stripe_sid | 1 hour | Stripe sets this cookie to process payments. |
| cookielawinfo-checkbox-advertisement | 1 year | Set by the GDPR Cookie Consent plugin, this cookie records the user consent for the cookies in the "Advertisement" category. |
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| CookieLawInfoConsent | 1 year | CookieYes sets this cookie to record the default button state of the corresponding category and the status of CCPA. It works only in coordination with the primary cookie. |
| elementor | never | The website's WordPress theme uses this cookie. It allows the website owner to implement or change the website's content in real-time. |
| JSESSIONID | session | New Relic uses this cookie to store a session identifier so that New Relic can monitor session counts for an application. |
| rc::a | never | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| rc::c | session | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
| Cookie | Duration | Description |
|---|---|---|
| __hstc | 6 months | Hubspot set this main cookie for tracking visitors. It contains the domain, initial timestamp (first visit), last timestamp (last visit), current timestamp (this visit), and session number (increments for each subsequent session). |
| _ga | 1 year 1 month 4 days | Google Analytics sets this cookie to calculate visitor, session and campaign data and track site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors. |
| _ga_* | 1 year 1 month 4 days | Google Analytics sets this cookie to store and count page views. |
| hubspotutk | 6 months | HubSpot sets this cookie to keep track of the visitors to the website. This cookie is passed to HubSpot on form submission and used when deduplicating contacts. |
| sbjs_current | session | Sourcebuster sets this cookie to identify the source of a visit and stores user action information in cookies. This analytical and behavioural cookie is used to enhance the visitor experience on the website. |
| sbjs_current_add | session | Sourcebuster sets this cookie to identify the source of a visit and stores user action information in cookies. This analytical and behavioural cookie is used to enhance the visitor experience on the website. |
| sbjs_first | session | Sourcebuster sets this cookie to identify the source of a visit and stores user action information in cookies. This analytical and behavioural cookie is used to enhance the visitor experience on the website. |
| sbjs_first_add | session | Sourcebuster sets this cookie to identify the source of a visit and stores user action information in cookies. This analytical and behavioural cookie is used to enhance the visitor experience on the website. |
| sbjs_migrations | session | Sourcebuster sets this cookie to identify the source of a visit and stores user action information in cookies. This analytical and behavioural cookie is used to enhance the visitor experience on the website. |
| sbjs_session | 1 hour | Sourcebuster sets this cookie to identify the source of a visit and stores user action information in cookies. This analytical and behavioural cookie is used to enhance the visitor experience on the website. |
| sbjs_udata | session | Sourcebuster sets this cookie to identify the source of a visit and stores user action information in cookies. This analytical and behavioural cookie is used to enhance the visitor experience on the website. |
| Cookie | Duration | Description |
|---|---|---|
| _cfuvid | session | Description is currently not available. |
| blgj5lst | 5 days | Description is currently not available. |
| m | 2 years | No description available. |
| oxetqk28 | 5 days | Description is currently not available. |
| x4mk8hq1 | 5 days | Description is currently not available. |