# Identity and access

5 operations.

Who can sign in and what each role allows — users, roles and their assignments.

## Operations

| Operation | Kind | What it does |
| --- | --- | --- |
| [copyCannedRole](/reference/identity-and-access/copyCannedRole/) | mutation | Copy a platform-preset role template you can copy into your group into your own group — your editable copy of the platform preset. |
| [issueCollaboratorInvite](/reference/identity-and-access/issueCollaboratorInvite/) | mutation | Send a collaborator their sign-up invite — a one-time code you pass along; issuing again replaces the old one. |
| [resetConsumerPassword](/reference/identity-and-access/resetConsumerPassword/) | mutation | Reset a shopper’s password, as staff — the recovery lane. |
| [revokeCollaboratorSessions](/reference/identity-and-access/revokeCollaboratorSessions/) | mutation | Sign a collaborator out everywhere — revoke all their sessions, as staff. |
| [revokeConsumerSessions](/reference/identity-and-access/revokeConsumerSessions/) | mutation | Sign a shopper out everywhere — revoke all their sessions, as staff. |
