Actions and results
What each Administration button and automatic behaviour does, with worked numbers and what the system refuses.
On this page (34)
System usersUser recordRolesField accessRecord accessExceptions and limitsAccess reviewAPI keysSettingsCustom fieldsChange my passwordSensitive-change alertsAudit evidenceRetentionLegal holdsDisposalAlert rulesEmail sendingWhatsAppMenusSequencesPayment termsPayment methodsPrice listsDimensionsCompaniesCompany switcherBranch switcherBranchesAppsApp pageApp page > FeaturesApp page > FieldsApp page > Configuration
System users
| Action | When | What you do | What happens |
|---|---|---|---|
| Summary tiles | Some users in different states | Open System users and compare each tile with the list filtered by that state | Active, Locked, Suspended, Expired, Dormant (30 days), Administrators, Must change password, Signed-in devices, Failed sign-ins (24h) all match |
| Create a user with the wizard | An employee without a login | New system user; pick the employee; type Internal; username auto-filled; Access: Member + a role; Licence default; temporary password 12+; Create | User created, record opens, status Active, 'must change password' set, membership Member, the role held; Audit shows 'user.created' |
| Create an external user (no employee) | New system user; type Customer portal; no employee; fill username and password; Create | Created without an employee link; licence default Portal | |
| Search, filter and open | Several users | Search by part of a username; filter Status = Locked; group by User type; open a row | Correct rows; the record opens; ?user=<id> link opens it directly |
User record
| Action | When | What you do | What happens |
|---|---|---|---|
| Edit general details | A test user | Edit; change display name, email, time zone, theme; Save | Saved; values shown; history entry |
| Reset password | A test user who is signed in on another browser | Actions > Reset password; new 12+ password; Why; confirm | Must change password at next sign-in; ALL their sessions end (other browser is signed out); failed-login count reset |
| Force password change | Actions > Force password change | Flag set; option disappears; next sign-in asks for a new password | |
| Lock and unlock | A test user (not yourself) | Actions > Lock user; try to sign in as them; then Unlock user | Locked: sign-in refused 'This account is locked. Ask your administrator to unlock it.', sessions ended; after unlock sign-in works |
| Suspend and activate | Actions > Suspend user with reason; then Activate user | Suspended: cannot sign in, licence released; Activate: active again | |
| Archive | Actions > Archive user with reason | Archived; cannot sign in; shown as Archived in the list; still in history | |
| Log out all devices | User signed in on two browsers | Actions > Log out all devices | Both sessions end (your own current one is kept if you act on yourself) |
| Clone user | A user with roles, branches and limits | Actions > Clone user; new username and password; Create | New user has the same companies (you administer), roles, scopes, limits, type, licence; NOT the password, sessions or history |
| Link / unlink employee | Employee tab: choose an employee, Link; then End the link | Linked and shown; ended; buttons disabled when nothing changed | |
| Company memberships | You administer 2 companies | Companies tab: give Viewer in the second company; then No access | Membership added then removed; the note shows companies you do not administer |
| Grant and revoke roles | Roles tab: tick a role, untick it | Granted/revoked at once; a conflicting duty shows the 'Conflicting duties' banner | |
| Data access | Data access tab: limit to one branch; set Starts in | Saved; 'Records they reach' list reflects it; signing in as them shows only that branch | |
| Restrict a field for a person | Field security tab: Restrict a field (Contacts > Phone > Masked) | Rule listed; as that user the phone shows ●●●● | |
| Licence change | Licence tab: change licence | Applied at once; history row added | |
| Security and sessions tabs | Some failed sign-ins | Open Security and Sessions; Log out one session | Counts match (wrong passwords x/5, last 100 attempts); the session ends; cannot log out your own current session |
| Photo | Upload a PNG under 2 MB; remove it | Shown on the avatar; removed; falls back to employee photo | |
| Access health score | Open a new user | Score out of 7 lists: can sign in, has a role, licence, employee/none needed, chose own password, no conflicts, not dormant |
Roles
| Action | When | What you do | What happens |
|---|---|---|---|
| Create a role from a template | New role; Start from Accountant; rename; Save | Saved with the template's permissions; Origin 'Yours' | |
| Permission dependencies | In the editor tick a permission that needs another | The needed one is ticked too with the 'Also turned on' note; unticking the base removes dependants | |
| Editor tools | Search permissions; filters All/Enabled/Disabled/Approval/High risk; Enable shown; Copy permissions from a role; Expand all | Each works; nothing saved until Save; 'Unsaved changes' badge; leaving asks to confirm | |
| Copy a role | Copy role; keep '(copy)' name; Save | New role created with the same permissions | |
| Shipped role is read-only | Open a role 'Comes with a2NSoft'; try to change | Cannot change; note says copy it and adjust the copy | |
| Who has it | Who has it; Give it to a member; Take it off | Holder added/removed; members list correct |
Field access
| Action | When | What you do | What happens |
|---|---|---|---|
| Restrict and lift | Restrict a field (Employees > a field > Hidden) for a role; sign in as a holder; then Lift | Field absent for holders (also in exports); after Lift visible again | |
| Same rule twice | Restrict the same record+field+subject again with another mode | Existing rule is updated, not duplicated |
Record access
| Action | When | What you do | What happens |
|---|---|---|---|
| Narrow and lift | Narrow 'Orders and invoices' to Their own for a role; sign in as a holder; Lift | Holder sees only their own orders; after Lift back to the default |
Exceptions and limits
| Action | When | What you do | What happens |
|---|---|---|---|
| Add an exception | Add an exception: person, Orders, an action, Refuse, until next week | Listed; that person is refused that action even though a role allows it | |
| Exception expiry | Add an allow exception until tomorrow; check after it passes | Shows 'Expired' and no longer applies | |
| Approval limit | Set an approval limit Journal limit = 5000; the person approves a 6000 journal | Approval refused above 5000; allowed at or below; Remove -> any amount |
Access review
| Action | When | What you do | What happens |
|---|---|---|---|
| Duty conflicts list | A user with two conflicting roles | Open Access review | The user appears under 'Duties that conflict' with severity and the company decision |
| Decide a rule | Open a rule; choose Refuse the grant; then try to give both roles | The second grant is refused with the conflict message | |
| Accept a risk | Open a rule; Accept the risk with a 10+ character reason | Saved as Risk accepted; grants pass | |
| Review a person | Another admin | Review: Needs narrowing + note | Last reviewed shows the date and reviewer; access is NOT changed by the review |
| Why? inspector | Click Why? on a person | Per record: scope, each action Yes/No with the reason, limits |
API keys
| Action | When | What you do | What happens |
|---|---|---|---|
| Create a key | An Integration-type user | New key: name, integration user, limit to partner.view, ends in 90 days; Create | Key shown ONCE with Copy; afterwards only 'Starts with' prefix is visible |
| Use a key | The key from FN-039 | Call GET .../partners with header Authorization: Bearer <key>; then call an endpoint needing another permission | First works; second refused; key cannot open another company's paths |
| Rotate | Rotate an active key | New key shown once; old key keeps working for 7 days then stops | |
| Revoke | Revoke with a reason; call the API with it | Status Revoked; the next request is refused; cannot be rotated |
Settings
| Action | When | What you do | What happens |
|---|---|---|---|
| Search settings | Type 'theme', then a nonsense word | Matching settings shown; nonsense shows 'No setting matches.' | |
| Theme, colours and language | Switch Dark; change one colour; Reset all colours; switch to Arabic | Applied at once in this browser only; reset restores; Arabic + right-to-left | |
| Developer mode | Turn on; open any record | API field names, record id and revision shown; 'Models & fields' link works for admin | |
| Clear transaction data | A TEST company with transactions (never production) | Danger zone > Clear transaction data; pick the test company; read the preview; type its legal name; Clear | Transactions removed, masters and settings kept, numbering restarts at 1, closed periods reopened; other companies untouched |
Custom fields
| Action | When | What you do | What happens |
|---|---|---|---|
| Add a custom field | Add custom field: Contacts, key x_region, label Region, Text | Listed; appears on the customer form; a value saves | |
| Decimal and Yes/No fields | Add a Decimal field and a Yes/No field on Products; fill them on a product | Decimal keeps 2 places; Yes/No select works |
Change my password
| Action | When | What you do | What happens |
|---|---|---|---|
| Change password from the user menu (control) | User menu (top right) > Change password; current, new, confirm | Works; other sessions signed out; you stay signed in |
Sensitive-change alerts
| Action | When | What you do | What happens |
|---|---|---|---|
| Receive an alert | An alert rule on partner.bank telling user B | User A changes a customer's bank details; user B opens Alerts | B sees the alert (who, what, fields - not the values) with a New badge; A gets no alert for their own change |
| Mark all read | Unread alerts | Mark all read | New badges gone |
Audit evidence
| Action | When | What you do | What happens |
|---|---|---|---|
| Seal new events | Some changes made more than 60 seconds ago | Seal new events | 'N event(s) sealed.'; a new seal row with fingerprint; again -> 'Nothing new to seal.' |
| Verify the trail | Sealed events | Verify the trail | 'Verified: X sealed event(s) intact, Y removal(s) explained, Z not yet sealed.' |
Retention
| Action | When | What you do | What happens |
|---|---|---|---|
| Set retention | Set 10 years; Save retention | Version number increases |
Legal holds
| Action | When | What you do | What happens |
|---|---|---|---|
| Place and release a hold | Admins A and B | A places a hold (name, why, prefix partner.); B releases it with a reason | Hold listed; released by B; A cannot release their own hold |
Disposal
| Action | When | What you do | What happens |
|---|---|---|---|
| Propose and approve a disposal | Sealed events older than retention (test data), admins A and B | A proposes disposal; B approves with a reason; Verify the trail | Events older than the cutoff and not on hold are removed; state done; Verify reports them as 'explained' |
| Reject a disposal | A proposes; B rejects with a reason | State rejected; nothing removed |
Alert rules
| Action | When | What you do | What happens |
|---|---|---|---|
| Create and edit a rule | New rule: name, actions 'account.', tell user B; Save; reopen; untick Active | Saved; inactive rule raises no alerts |
Email sending
| Action | When | What you do | What happens |
|---|---|---|---|
| Add a company mail account | Test SMTP account (e.g. a test mailbox) | Add an account: This company, server, port 587, STARTTLS, user, password, Send from; Save | Listed; 'Your mail goes out as ...' shows it; password not shown back (placeholder 'Saved - leave blank to keep') |
| Account precedence | Company, branch and personal accounts | Send an email (e.g. a quotation) as a user in the branch / with a personal account | Personal beats branch beats company beats everyone; inactive accounts skipped |
| Edit without retyping password | Edit an account; change sender name only; Save | Password kept (sending still works) |
| Action | When | What you do | What happens |
|---|---|---|---|
| Add a company connection | Test Meta app | Add a connection; change Applies to = This company; Phone number ID; token; app secret; Save | Listed; Webhook 'Signed'; the webhook address is shown |
| Webhook handshake | Verify token set | Meta (or curl) GET the webhook with hub.mode=subscribe and the verify token | Challenge echoed; wrong token -> 403 'Verification failed.' |
Menus
| Action | When | What you do | What happens |
|---|---|---|---|
| Rename, hide and reorder | Module Sales: rename an entry (EN+AR), untick one, move one up; Save menus; reload | Menu shows the changes; footer 'X of Y entries changed' | |
| Reset a module | Reset this module | Menus back to shipped (note: no confirmation is asked) |
Sequences
| Action | When | What you do | What happens |
|---|---|---|---|
| Edit a sequence | Invoice numbering exists | Open it; Edit; prefix INV-%(year)s-, size 5, next 100; Save; create an invoice | Preview shows INV-2026-00100; the next invoice gets that number |
| Create a sequence for an unused code | New sequence; pick a code from 'Numbering for'; Save | Name, prefix and size filled from the default; listed | |
| Switch a sequence off | Untick Active; try to create a record of that type | Refused: "The sequence '<name>' is switched off." |
Payment terms
| Action | When | What you do | What happens |
|---|---|---|---|
| Add the standard terms | Add the standard terms twice | 18 standard terms after the first; the second adds nothing | |
| Create a 50/50 term | New term: 50 % at 30 days, balance at 60 days; preview 100,000 dated today; Save | Preview shows 50,000 on day 30 and 50,000 on day 60; saved; usable on a sales order | |
| Early discount and tiers | Add 2 % within 10 days; add tiers 3 %/5 days and 1 %/20 days; preview | Offers table lists the tiers with saving and amount; invalid order refused | |
| Due-date rules | Try each 'Falls due' rule with the preview (end of month, day 31 in a 30-day month, next weekday) | Dates match the rule; day 31 becomes the month's last day; next weekday never today | |
| Archive a term | Set Status Archived; open a new sales order | The term is not offered; old documents keep it |
Payment methods
| Action | When | What you do | What happens |
|---|---|---|---|
| Standard methods and a new one | Add the standard methods; New method PDC, kind Cheque, Lands in a bank account | 7 standard methods; PDC saved with Reference forced Required | |
| Direction | Make a method 'Receipts only'; register a supplier payment | The method is not offered for payments |
Price lists
| Action | When | What you do | What happens |
|---|---|---|---|
| Create and price | New price list (Active), Add a product, set price and a 10+ quantity break; assign to one customer; Save; quote that customer | Quotation uses the list price; quantity 10 uses the break price; another customer gets the standard price | |
| Draft lists do not price | Set the list to Draft; quote the customer again | Standard price used | |
| Add every product / locked rows | Add every product; lock one row; remove it; Save | All products listed; the locked row stays after Save |
Dimensions
| Action | When | What you do | What happens |
|---|---|---|---|
| Create a hierarchy | Cost centres: create PARENT and CHILD rolling up to PARENT | Child shows 'Rolls up to'; smart buttons show counts | |
| Required on every posting | Turn on 'Required on every posting' for Cost centres; post a journal without one; turn it off | Posting refused: '<Type> is required on every posting.' | |
| Close a value | Close this value with Closed after = yesterday; post with it | Refused: '<code> is not available for a posting dated <date>.' |
Companies
| Action | When | What you do | What happens |
|---|---|---|---|
| Create a company | Superuser or can-create user | New company: legal name, code TST01; Create | Created; you are its admin; every available app installed; standard payment terms added; audit company.created |
| Edit company details | Open the company; Edit; fill registration, address and defaults; Save | Saved; setup progress % rises; audit shows before/after |
Company switcher
| Action | When | What you do | What happens |
|---|---|---|---|
| Switch the active company | Member of two companies | Pick the other company in the header | Lists, menus and new records belong to it; choice remembered after reload |
| Read companies together | Companies read together: tick both | Lists show records of both (+N badge); new records still go to the acting company |
Branch switcher
| Action | When | What you do | What happens |
|---|---|---|---|
| Active branch | Branches exist | Choose a branch; create a sales order | The order is tagged with that branch and numbered with its series |
Branches
| Action | When | What you do | What happens |
|---|---|---|---|
| Create a branch | New branch: name, code DXB, type Retail store; Save | Saved; a 'branch' dimension value DXB created; numbering shows SO-DXB-000001 | |
| Branch warehouses and defaults | A free warehouse | Warehouses tab: add it; Operations: set it as default; remove it from the tab | Saved immediately; removing clears the default; a warehouse of another branch is refused |
| Close a branch | Set Closed after = yesterday / Inactive | Its dimension value closes; its own numbering stops |
Apps
| Action | When | What you do | What happens |
|---|---|---|---|
| Catalogue facets and search | Switch facets, filter by category, search, grid/list | Counts and cards correct; view remembered | |
| Install an app with dependencies | A company where an app is not installed | Install it | Its dependencies installed too; audit 'needed by' |
| Turn off an app | An app nothing depends on | Turn off app; open its menu by link | Menus gone; its API refused 'The <app> app is not installed for this company.'; records still there after re-install |
| Cannot turn off a needed app | Try to turn off an app another installed app needs | Disabled with 'Needed by ...' | |
| Billing and Tax come with Finance | Open Billing and Tax in the catalogue | Shown installed when Finance is; 'Comes with Finance'; no Install or Turn off |
App page
| Action | When | What you do | What happens |
|---|---|---|---|
| Tabs | Open Sales: every tab | Overview gates, versions, dependencies, capabilities, Features, Fields, security, evidence, activity all load |
App page > Features
| Action | When | What you do | What happens |
|---|---|---|---|
| Turn a feature off (two people) | Admins A and B | A: Purchasing > Features > Tenders Off; Preview; reason; Propose. B: Approve | After approval the Tenders menu disappears; creating a tender is refused '... is disabled for this company.'; old tenders still readable |
App page > Fields
| Action | When | What you do | What happens |
|---|---|---|---|
| Make a field required (two people) | Admins A and B | A: Purchasing > Fields > Supplier reference = Required; propose. B: approve. Confirm a PO without it | The field shows *; confirm refused '... is required by this company before this step.'; with a value it confirms |
| Hide a field | Hide 'Customer PO number' (Sales); open a new quotation; try the API with a value | The box is gone; API refused '... is turned off for this company.'; old orders keep their value |
App page > Configuration
| Action | When | What you do | What happens |
|---|---|---|---|
| Reject and restore | B rejects a proposal with a reason; later restore an older revision | Rejected listed; restore creates a new proposal needing approval | |
| Industry profile | Sales > Industry profile: Professional services; Preview; Propose; approve | Branch on sales documents off; profile shown as applied | |
| Blocked change | A branch numbers its own documents | Sales: hide Branch with 'No branch'; Preview | Shown as Blocked with the reason; Propose disabled |