> ## Documentation Index
> Fetch the complete documentation index at: https://anaconda.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# What is a user?

export const DefinitionDescription = ({children}) => <dd className="definition-description">{children}</dd>;

export const DefinitionTerm = ({children}) => <dt className="definition-term">{children}</dt>;

export const DefinitionList = ({children}) => <dl className="definition-list">{children}</dl>;

A user is a person or machine user that can access your platform. Every action on the platform is performed by a user, and what that user can do is determined by their [role and privileges](/docs/platform/concepts/roles-and-privileges).

## Types of users

The platform recognizes two kinds of user:

<DefinitionList>
  <DefinitionTerm>
    Human users
  </DefinitionTerm>

  <DefinitionDescription>
    People who use the platform, such as data scientists and administrators. Human users sign in through your organization's single sign-on (SSO), so access is managed with the same identity provider your organization already uses.
  </DefinitionDescription>

  <DefinitionTerm>
    Machine users
  </DefinitionTerm>

  <DefinitionDescription>
    Non-human identities used for automation, such as CI/CD pipelines or scheduled jobs. A machine user authenticates programmatically (using a token or API key) rather than through a browser sign-in, so automated [workloads](/docs/platform/concepts/what-is-a-workload) can run without a person present.
  </DefinitionDescription>
</DefinitionList>

<Note>
  Machine users appear as **Machines** in the platform UI and are called `ServicePrincipal` in the platform's API (example: `UserType.ServicePrincipal`).
</Note>

## Why the distinction matters

Separating human users from machine users lets your organization manage people and automation independently. People are governed through your SSO provider and can have access granted or revoked as they join or leave teams. Automation runs under its own identity with its own credentials, so a pipeline's access can be scoped and audited separately from any individual's.

Both types of user are granted access the same way: through a [role](/docs/platform/concepts/roles-and-privileges) at the platform level and privileges on the [perimeters](/docs/platform/concepts/what-is-a-perimeter) they work in.

## Managing users

Administrators can invite users, create machine users, and assign roles and privileges from the platform UI.
