Create a system user

Give a person a login, with the right roles, branches and licence, using the three-step wizard.

Required permission: member.manage

Before you begin

  • You must be an administrator of the company, or hold member.manage through a role.
  • If the person is an employee, the employee record must exist and must not already have a login. An employee is not automatically a user.
  • Decide the person's roles and branches first. See Design roles and keep duties apart.

Steps

  1. Go to Administration > Users > System users and click New system user. The wizard has three steps: Identity, Access and Licence.
  2. On Identity, choose the Linked employee if the person is an employee. Only employees of this company who are not terminated and have no login are offered. Choosing one fills in the name, email, mobile and username. Leave it empty for an external person such as a customer portal user.
  3. Choose the User type. The choices are Internal ERP user, Administrator, Company admin, Branch admin, POS, Warehouse, Mobile, ESS, Customer portal, Vendor portal, Auditor, Temporary, API, Integration and Service. Changing the type resets the licence to that type's default.
  4. Type the Username. Use lower-case letters, digits and the characters . _ - @ only. It must be unique, ignoring case. Capitals you type become lower-case. Example: test.user1.
  5. Fill in First name, Last name and Display name. If you leave the display name empty, the system uses first name plus last name.
  6. Enter the Login email and Login mobile if you have them. The email must contain @ and no spaces. It is not checked for uniqueness.
  7. Click Next. On Access, set In this company to Viewer, Member or Administrator. Viewer is the default.
  8. Tick the Roles the person needs. Only active roles of this company and the roles that ship with a2NSoft are listed.
  9. Tick the Allowed branches. If you tick none, the person reaches every branch. If you tick more than one, a Default branch list appears: choose a branch or Ask each time.
  10. Click Next. On Licence, confirm the Licence (the default follows the user type), choose the Language (English or Arabic), and optionally set Access starts and Access ends.
  11. Type a Temporary password of at least 12 characters. The person must change it at first sign-in.
  12. Click Create. The new user's record opens.

What happens next

  • The account is Active and flagged must change password. The person is asked for a new password at first sign-in.
  • The membership and roles you chose take effect at once. The company's Audit trail records user.created.
  • The new record shows an access health score out of 7: can sign in, has a role, has a licence, employee linked or none needed, chose their own password, no conflicting duties, not dormant. A score under 7 on a new user is normal until they have signed in.
  • Give the temporary password to the person through a safe channel. Do not email it with the username.

Good to know

  • Machine users cannot sign in. API, Integration and Service users are for keys, not for people. They get the message 'This is an integration account. It cannot sign in here.' See API keys for integrations.
  • Access window. Before Access starts the person sees 'This account can be used from YYYY-MM-DD.' After Access ends they see that their access has ended. Access ends cannot be before Access starts.
  • Duplicate names. An existing username gives 'This username already exists.' A name with capitals only changes case, so Test.User1 and test.user1 clash.
  • Employee already linked. You see '<name> already signs in as <username>.'
  • Short password. 'Use at least 12 characters.'
  • Clone instead of starting over. To copy a person's companies, roles, scopes, limits, type and licence, open their record and use Actions > Clone user. The password, sessions and history are not copied. A superuser cannot be cloned ('A superuser's access is not a template.').
  • Photo. On the user record you can upload a PNG, JPEG or WebP up to 2 MB. Larger pictures are refused with 'Pictures must be no larger than 2 MB.'
  • External users. For a customer or vendor portal user, leave the employee empty and choose the matching portal type. The licence defaults to Portal.

Worked example

Sara Ali joins the Dubai Mall branch as an accountant. You create sara.ali, type Internal ERP user, link her employee record, set her to Member, tick the role Accountant, allow only the Dubai Mall branch, choose Professional licence and Arabic, and set a temporary password. After she signs in and changes it, her health score shows 7 of 7.

Next: Manage a user account.