Manage a user account

Reset passwords, lock, suspend, archive, end sessions and change a person's access over time.

Required permission: member.manage

Before you begin

Open Administration > Users > System users and click the person's row. The record has tabs: General, Employee, Companies, Roles, Data access, Field security, Approval limits, Licence, Security, Sessions and Audit. The nine tiles at the top of the list (Active, Locked, Suspended, Expired, Dormant, Administrators, Must change password, Signed-in devices, Failed sign-ins) help you find accounts that need attention.

You need member.manage. Only a superuser can change a superuser ('Only a superuser can change a superuser.').

Change a person's details

  1. Open the user and click Edit.
  2. Change the display name, email, time zone, date format, number format, theme or language on the General tab.
  3. Click Save. A history entry is kept.

The username, status, authentication method, created date and last sign-in are read-only.

Reset a password

  1. Open the user and choose Actions > Reset password.
  2. Type a new temporary password of at least 12 characters. The button stays disabled until it is long enough.
  3. Optionally type Why.
  4. Confirm.

The person must change the password at next sign-in, all their sessions end, and failed-sign-in counts reset. If an automatic lock after too many wrong passwords is in place, the reset clears it. A lock you applied by hand stays; see below.

To make someone choose a new password without resetting it, use Actions > Force password change.

Lock and unlock

Use Actions > Lock user to stop sign-in at once while you investigate. Sessions end and sign-in is refused with 'This account is locked. Ask your administrator to unlock it.' Use Actions > Unlock user to restore it.

After five wrong passwords the system locks an account by itself for a while and tells the person 'This account is locked after too many attempts. Try again after HH:MM UTC.' The Security tab shows the wrong-password count (x/5), the last 100 attempts and Locked until.

Suspend, activate and archive

  • Suspend user needs a Reason. The person cannot sign in and their licence is released. Their other browser is signed out at the next action.
  • Activate user brings a suspended account back.
  • Archive user needs a Reason. The person cannot sign in and shows as Archived in the list. The record, history and audit entries remain. Use this for leavers.

A leaver is normally suspended first, then archived once their handover is finished.

End sessions

  • Actions > Log out all devices ends every session of that person. If you do it to yourself, your current one is kept.
  • On the Sessions tab you can end a single session. You cannot end the session you are using.

Companies, roles and data access

  • Companies tab: choose No access, Viewer, Member or Administrator for each company you administer. Companies you do not administer are shown in a note only.
  • Roles tab: tick or untick roles. The change applies at once. A banner Conflicting duties appears if the roles clash. See Design roles and keep duties apart.
  • Data access tab: limit the person to branches, warehouses, departments or sales teams. Empty means everywhere. Starts in can only be a place they can reach ('Somebody can only start where they can reach.').
  • Licence tab: change the licence. It applies immediately. A suspended user cannot be given one ('A licence goes with active access. Activate the account first.').
  • Employee tab: link or end the link to an employee.

Rules that refuse

You tryThe system says
Lock, suspend or archive yourself'You cannot switch off your own account.'
Suspend or demote the only administrator'<username> is the only administrator of this company...' or 'That is the last administrator of that company.'
Change the type to API, Integration or ServiceAllowed, and all their sessions end
Choose a default company they do not belong to'Their default company must be one they belong to.'

Good to know

  • Wrong password on a suspended account shows only the usual wrong-password message. The status is never revealed to someone who does not know the password.
  • Two-step sign-in appears among the actions but is not available yet. Do not rely on it.
  • Everything on this screen is written to the audit trail.