> ## Documentation Index
> Fetch the complete documentation index at: https://docs.azalt.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Update user role and site assignment

> Modify an existing user's role and site assignments within the organization.

**Updatable Permissions**:
- Organizational role (Owner, Manager, Collector, Viewer)
- Site assignments and access scope
- Tags for user categorization within the organization
- Specific permission overrides

**Role Change Impact**:
- **Owner**: Can only be changed by other owners, affects billing access
- **Manager**: Changes site management capabilities and user permissions
- **Collector**: Affects data entry permissions across forms and sites
- **Viewer**: Modifies read-only access scope and reporting capabilities

**Site Assignment Changes**:
- Adding sites grants access to related forms and data
- Removing sites revokes access and hides related information
- Hierarchical changes affect child site access automatically
- Changes are applied immediately for active sessions

**Security Considerations**:
- Cannot modify users with higher or equal permissions
- Audit trail maintained for all role changes
- Immediate session updates for security-sensitive changes
- Prevents accidental privilege escalation

Requires site manager permissions and appropriate scope to modify the target user's access.



## OpenAPI

````yaml https://app.azalt.co/api/v1/openapi.json patch /organizations/current/users/{userId}/role
openapi: 3.0.3
info:
  title: Erguvan Public API
  version: 1.0.0
servers:
  - url: https://app.azalt.co/api/v1
security: []
paths:
  /organizations/current/users/{userId}/role:
    patch:
      tags:
        - Organization
      summary: Update user role and site assignment
      description: >-
        Modify an existing user's role and site assignments within the
        organization.


        **Updatable Permissions**:

        - Organizational role (Owner, Manager, Collector, Viewer)

        - Site assignments and access scope

        - Tags for user categorization within the organization

        - Specific permission overrides


        **Role Change Impact**:

        - **Owner**: Can only be changed by other owners, affects billing access

        - **Manager**: Changes site management capabilities and user permissions

        - **Collector**: Affects data entry permissions across forms and sites

        - **Viewer**: Modifies read-only access scope and reporting capabilities


        **Site Assignment Changes**:

        - Adding sites grants access to related forms and data

        - Removing sites revokes access and hides related information

        - Hierarchical changes affect child site access automatically

        - Changes are applied immediately for active sessions


        **Security Considerations**:

        - Cannot modify users with higher or equal permissions

        - Audit trail maintained for all role changes

        - Immediate session updates for security-sensitive changes

        - Prevents accidental privilege escalation


        Requires site manager permissions and appropriate scope to modify the
        target user's access.
      operationId: updateUserRole
      parameters:
        - in: path
          name: userId
          schema:
            type: string
          required: true
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                role:
                  type: string
                  enum:
                    - COLLECTOR
                    - APPROVER
                    - VIEWER
                    - MANAGER
                    - OWNER
                assignedSiteIds:
                  type: array
                  items:
                    type: string
              required:
                - role
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                  message:
                    type: string
                required:
                  - success
                  - message
        '400':
          description: Invalid input data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.BAD_REQUEST'
        '401':
          description: Authorization not provided
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.UNAUTHORIZED'
        '403':
          description: Insufficient access
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.FORBIDDEN'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.NOT_FOUND'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.INTERNAL_SERVER_ERROR'
      security:
        - Authorization: []
components:
  schemas:
    error.BAD_REQUEST:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Invalid input data
        code:
          type: string
          description: The error code
          example: BAD_REQUEST
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Invalid input data error (400)
      description: The error information
      example:
        code: BAD_REQUEST
        message: Invalid input data
        issues: []
    error.UNAUTHORIZED:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Authorization not provided
        code:
          type: string
          description: The error code
          example: UNAUTHORIZED
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Authorization not provided error (401)
      description: The error information
      example:
        code: UNAUTHORIZED
        message: Authorization not provided
        issues: []
    error.FORBIDDEN:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Insufficient access
        code:
          type: string
          description: The error code
          example: FORBIDDEN
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Insufficient access error (403)
      description: The error information
      example:
        code: FORBIDDEN
        message: Insufficient access
        issues: []
    error.NOT_FOUND:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Not found
        code:
          type: string
          description: The error code
          example: NOT_FOUND
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Not found error (404)
      description: The error information
      example:
        code: NOT_FOUND
        message: Not found
        issues: []
    error.INTERNAL_SERVER_ERROR:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Internal server error
        code:
          type: string
          description: The error code
          example: INTERNAL_SERVER_ERROR
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Internal server error error (500)
      description: The error information
      example:
        code: INTERNAL_SERVER_ERROR
        message: Internal server error
        issues: []
  securitySchemes:
    Authorization:
      type: http
      scheme: bearer

````