Revoking Access

Revoking access to a single resource

Only enterprise administrators can update access controls on resources. Revoking access to a single resource can be be completed from either the web console or the mobile app.

Web Console

From the resources page select the resource to update to open the resource detail view. Under the Policy panel, press edit, remove the member or group from the Access list, and push save.

Mobile App

Open the Castle mobile app, navigate to the Resources page, and click the resource you want to update to open the resource detail view. Press the Edit button in the upper right corner and remove the member or group from the Share Access panel, and press Save.

Removing a member from a group

Group membership can only be updated via the web console and can only be updated by enterprise administrators. Open the web console and navigate to Members and select the Groups tab. Select the relevant group to open the group details page. Press the Edit button, remove the member from the group, and press Save.

The member loses access to all resources assigned to that group. If they have direct (non-group) access to any resource, that is unaffected.

Effect Timing

All access list and group membership changes take effect immediately. Removed members will no longer have instant access or be able to request access to that resource.

Deactivating a member account

If a team member leaves or no longer needs any access to Castle, deactivate their account entirely. This can only be accomplished by enterprise administrators and can only be accomplished via the web console.

  • Click Members in the top navigation and find the member on the People tab.
  • Click on their name to open their profile.
  • Click Deactivate Account and confirm when prompted. The member will immediately lose access to all resources and will no longer be able to log into the Castle app.