Help Center

Users and passwords (permissions)

The permissions that control administration of employee logins — create, edit, disable, delete, passwords and 2-factor.

This article covers the permissions that control administration of employee logins — creation, editing, disabling, deletion, passwords and 2-factor.

You find the screen under: Financial → SecurityUsers. The rights themselves are typically assigned to a group (role) via the permission tree, and they apply per organizational unit — that is, only in the store/department where they are granted.

The permissions

Create

Allows creating new users in the selected organizational unit. Without the permission, the button to create a new user is blocked, and the attempt is rejected with "access denied".

Edit

Allows editing another user's details in the organizational unit. Note: the system user and the administrator user cannot be edited by ordinary users.

Enable / Disable

Allows enabling or disabling another user's login.

Important: The same permission also gives access to resetting the failed login attempt counter for a user (e.g. if an employee has locked themselves out). The two actions therefore go together.

System and administrator accounts cannot be disabled.

Delete

Allows deleting (anonymizing) another user's account. System and administrator accounts cannot be deleted.

Enable/Disable 2FA

Allows turning two-factor authentication on or off for other users. You can always manage your own 2-factor; the administrator user's 2-factor is protected.

Change Other User Passwords

Allows changing or resetting other users' passwords.

  • You may always change your own password — that does not require this permission.

  • The administrator user's password is protected and can only be changed by the administrator themselves.

Good to know

  • The permissions apply per organizational unit. An employee may have the right to administer users in one store without having it in another.

  • Administrators by default have all of these rights on the top organizational unit.

  • Allow vs. Deny: An explicit Deny wins over an inherited Allow. Use it if a group would otherwise inherit a right it should not have.

Did this answer your question?
😞
😐
😁