Manage a user account
Reset passwords, lock, suspend, archive, end sessions and change a person's access over time.
Before you begin
Open Administration > Users > System users and click the person's row. The record has tabs: General, Employee, Companies, Roles, Data access, Field security, Approval limits, Licence, Security, Sessions and Audit. The nine tiles at the top of the list (Active, Locked, Suspended, Expired, Dormant, Administrators, Must change password, Signed-in devices, Failed sign-ins) help you find accounts that need attention.
You need member.manage. Only a superuser can change a superuser ('Only a superuser can change a superuser.').
Change a person's details
- Open the user and click Edit.
- Change the display name, email, time zone, date format, number format, theme or language on the General tab.
- Click Save. A history entry is kept.
The username, status, authentication method, created date and last sign-in are read-only.
Reset a password
- Open the user and choose Actions > Reset password.
- Type a new temporary password of at least 12 characters. The button stays disabled until it is long enough.
- Optionally type Why.
- Confirm.
The person must change the password at next sign-in, all their sessions end, and failed-sign-in counts reset. If an automatic lock after too many wrong passwords is in place, the reset clears it. A lock you applied by hand stays; see below.
To make someone choose a new password without resetting it, use Actions > Force password change.
Lock and unlock
Use Actions > Lock user to stop sign-in at once while you investigate. Sessions end and sign-in is refused with 'This account is locked. Ask your administrator to unlock it.' Use Actions > Unlock user to restore it.
After five wrong passwords the system locks an account by itself for a while and tells the person 'This account is locked after too many attempts. Try again after HH:MM UTC.' The Security tab shows the wrong-password count (x/5), the last 100 attempts and Locked until.
Suspend, activate and archive
- Suspend user needs a Reason. The person cannot sign in and their licence is released. Their other browser is signed out at the next action.
- Activate user brings a suspended account back.
- Archive user needs a Reason. The person cannot sign in and shows as Archived in the list. The record, history and audit entries remain. Use this for leavers.
A leaver is normally suspended first, then archived once their handover is finished.
End sessions
- Actions > Log out all devices ends every session of that person. If you do it to yourself, your current one is kept.
- On the Sessions tab you can end a single session. You cannot end the session you are using.
Companies, roles and data access
- Companies tab: choose No access, Viewer, Member or Administrator for each company you administer. Companies you do not administer are shown in a note only.
- Roles tab: tick or untick roles. The change applies at once. A banner Conflicting duties appears if the roles clash. See Design roles and keep duties apart.
- Data access tab: limit the person to branches, warehouses, departments or sales teams. Empty means everywhere. Starts in can only be a place they can reach ('Somebody can only start where they can reach.').
- Licence tab: change the licence. It applies immediately. A suspended user cannot be given one ('A licence goes with active access. Activate the account first.').
- Employee tab: link or end the link to an employee.
Rules that refuse
| You try | The system says |
|---|---|
| Lock, suspend or archive yourself | 'You cannot switch off your own account.' |
| Suspend or demote the only administrator | '<username> is the only administrator of this company...' or 'That is the last administrator of that company.' |
| Change the type to API, Integration or Service | Allowed, and all their sessions end |
| Choose a default company they do not belong to | 'Their default company must be one they belong to.' |
Good to know
- Wrong password on a suspended account shows only the usual wrong-password message. The status is never revealed to someone who does not know the password.
- Two-step sign-in appears among the actions but is not available yet. Do not rely on it.
- Everything on this screen is written to the audit trail.