RefractSurvey Users
Every person who signs in to manage surveys — as opposed to an anonymous respondent using an access code — has a user account.

Creating a user
From Manage > Users, create a new account with a username, password, and display name. You'll choose their permissions at the same time (either by hand, or by starting from a role preset), and which projects they can access.
You can only hand someone permissions or project access that you yourself already have — so a non-admin managing users can't accidentally (or deliberately) grant someone more access than they themselves hold.
Admin accounts
An account marked as an admin bypasses every permission check entirely — admins can always see and do everything, in every project, regardless of what roles or individual permissions are set on their account. Give this out carefully; for everyday team members, individual permissions or a role preset are almost always the better fit.
Deactivating a user
Rather than deleting an account outright, a user can be deactivated — they immediately lose the ability to sign in, but their name still shows up correctly anywhere they created or edited something in the past.
Password rules
RefractSurvey enforces a minimum password length and nothing stricter than that by default. If your organization wants a tougher password policy, that's expected to be handled as a matter of your own team's policy rather than something hardcoded into the app.
Login protection
Repeated failed login attempts are automatically throttled, both for a specific username and (separately) from a specific network address, so guessing at a password is slow going. See Security Notes for more.