Audience: System Administrators and Security/IT staff who manage staff user accounts in Admin > Users
What this guide covers
When a staff member leaves your organization, takes an extended leave, or no longer needs system access, you can now deactivate their user account instead of permanently deleting it. Deactivation immediately blocks them from logging in while preserving their account record — if they return later, you can reactivate them in seconds without having to recreate the account from scratch.
This guide covers:
- What deactivation and reactivation do (and why you'd use them instead of deletion)
- How to deactivate a user account
- How to reactivate a user account
- Permissions required
- Common scenarios and what happens in each
- Key things to know before you start
Why deactivate instead of delete?
Deactivation removes a user's login access immediately but keeps their account record in the system. Deletion permanently removes the account and its history.
| Situation | Use Deactivation | Use Deletion |
|---|---|---|
| Employee on extended leave (sabbatical, maternity, unpaid time off) | ✓ | |
| Contractor's engagement ended, but they might return | ✓ | |
| Employee left the organization permanently | ✓ (in most cases — see below) | |
| Account created by mistake with no activity | ✓ | |
| Duplicate account that shouldn't exist | ✓ |
Why it matters: deactivation preserves the account's audit trail and history. If someone asks "who processed that payment in 2022?" the deactivated account's records stay findable. Deletion removes all trace of the account entirely — useful for cleanup, but irreversible. When in doubt, deactivate instead of deleting. If your institution's compliance or audit policy specifies otherwise, consult your Security team before deleting accounts.
Permission requirements
You need one of the following to access Admin > Users and use deactivate/reactivate:
- The Manage Users permission (permission code
MANAGE_USERS) - The Security/IT role
No separate permission is required for deactivate vs. reactivate — if you can add/edit users, you can deactivate and reactivate them.
If Admin > Users doesn't appear in your Admin menu, you don't have the required permission. Contact your administrator to request access.
How to deactivate a user
- Navigate to Admin > Users for the correct institution (if your organization has multiple locations).
- Find the user in the user list. You can:
- Scroll through the list
- Use the search box to filter by name or email
- Use any other filters your system offers to narrow the list
- Click the Deactivate button next to the user's name (the button's exact position depends on whether you're on the new or legacy Admin screen, but it's in the user's row).
- Confirm the action in the dialog box that appears. You'll see a message like "Are you sure you want to deactivate this user?" — click Confirm or Yes (exact wording varies). There's no going back after this point without reactivating, so double-check you've selected the right person.
- Deactivation is immediate. The user is blocked from logging in right away — if they try, they'll see an error message similar to "Invalid username or password," even if their password is correct. Their SSO access (if your organization uses single sign-on) is also blocked instantly.
Important: no email is sent to the user when you deactivate them. If they need to know they've been locked out, you'll need to tell them separately (e.g., an exit email as part of an offboarding process).
Can I deactivate someone who's already deactivated?
Yes, it's safe — clicking Deactivate on an already-deactivated account is a no-op (nothing happens). This also means if you accidentally click the button twice, don't worry.
How to reactivate a user
- Navigate to Admin > Users for the correct institution.
- Check the "Show Inactive Users" checkbox (located above or within the user list, depending on your Admin screen version). By default, deactivated users are hidden so they don't clutter your active user list.
- Find the deactivated user in the now-expanded list. Deactivated users show a small "Inactive user" icon or tooltip next to their email so you can spot them at a glance.
- Click the Activate button next to their name. Unlike deactivation, no confirmation dialog is required — the action completes immediately.
- The user receives a reactivation email with the subject line "Your Flywire Health Account Has Been Reactivated" and a button to set a new password and log back in. The email is sent automatically — you don't need to do anything else.
- The user's original email and username are restored. Before reactivation, their email was temporarily obfuscated (mangled with markers) to free it up in case someone else needed to register with the same address. Reactivation restores it.
What if reactivation fails?
Most common reason: another active user already has that email address.
When you try to reactivate an account, the system checks whether the original email is still available. If another active user is using it (maybe someone new joined and grabbed the email address), reactivation is blocked with an error message, and the account stays deactivated — it won't leave things in a half-restored state.
What to do:
- Note which email is causing the conflict (the error message usually tells you)
- Contact your Security/IT team or check your records to confirm whether the other account is legitimate
- If the other account is a duplicate or mistake, delete or deactivate it first, then try reactivating again
- If both accounts are legitimate, you'll need to either:
- Assign the deactivated user a different email address (contact your admin team — this requires a manual backend change)
- Keep the account deactivated and create a new account for the returning user with a different email
Can I reactivate someone who's already active?
Yes, it's safe — clicking Activate on an already-active account is a no-op. The account stays active, and no duplicate reactivation email is sent.
Searching for deactivated users
By default, deactivated users are hidden from the user list and from search results. This keeps your active user list clean and prevents accidentally selecting the wrong person.
To see deactivated users:
- Check the "Show Inactive Users" checkbox
- The list refreshes to include both active and deactivated users
- Deactivated users are marked with a small "Inactive user" icon or tooltip
To hide them again, uncheck the box.
Common scenarios
| Scenario | What to do | Notes |
|---|---|---|
| Employee is on maternity leave for 6 months | Deactivate their account | When they return, reactivate it. They'll get a reactivation email with a password reset link. |
| Contractor's 1-year engagement ended; they might come back in Q4 | Deactivate their account | Clean and simple. If they're back, reactivate in one click. |
| Employee left the company — we're sure they're not coming back | Deactivate their account | Even for permanent departures, deactivation preserves the audit trail. Delete only if there's a compliance reason to remove the record entirely. |
| User accidentally created with the wrong email; they never logged in | Delete the account | Since there's no history or activity, deletion is safe and saves space. |
| I need to check who accessed the system on a specific date in 2023 | Deactivated accounts still appear in audit logs | Deletion removes the account entirely, including its historical activity. If you anticipate needing records later, deactivate instead of deleting. |
| User is temporarily locked out — should I deactivate? | No, don't deactivate | If the problem is a forgotten password or a temporary access issue, reset their password or contact your Security team. Deactivation is for access you don't want them to have at all. |
| Manager wants me to delete a user instead of deactivating | Consult your Security/Compliance team first | Deletion is permanent and can't be undone. Deactivation is the safer default; deletion should be a deliberate, documented decision. |
Things to know before you start
- Deactivation is immediate — the user is locked out right away. There's no "grace period" or warning.
- No email is sent on deactivation — if the user needs to know, tell them yourself.
- Reactivation sends an email — the user will get a reactivation notification with a password-reset link. They can't log in with their old password after reactivation.
- Deactivated accounts are soft-deleted — they're not truly removed from the system, so they can be reactivated. If your institution's audit or compliance policy requires true deletion for certain users, that's a different process; check with your Security team.
- You can't temporarily lock a user out — deactivation and reactivation are the main tools for access control. If you need to block someone for a specific time window, deactivation is the way to do it; there's no "disable until date X" feature.
- If reactivation fails because of an email conflict, you need help — the blocked account can't be automatically re-enabled. Contact your Security/IT team or system administrator to resolve the duplicate email and try again.
Related topics
- Managing Staff User Roles and Permissions — how to assign Security/IT roles and individual permissions
- Admin Menu Overview — other admin tools and features
- Compliance and Audit Logs — how deactivated accounts appear in your audit trail
This guide reflects the User Deactivation Workflow in HC 5.0. For updates or issues with this feature, contact your Security/IT team or file a support request. Questions about whether to deactivate vs. delete? Check your institution's compliance policy, or reach out to your administrator.