Users and Their Permissions
Users are the people who log in, and their permissions decide what each one can reach. How many you can create is set by your subscription pack, and every user falls into one of three roles that determine how far their access extends.
Where to find it
Go to Setup > Users & Void > Users, then Add New.
Users
User accounts are tied to your subscription. If you need more than your pack allows, extra users can be bought from the subscription page, or a custom pack arranged.
Permissions
Not everyone should reach everything. When creating a user you are shown the modules included in your pack, and you tick the ones that person needs. Anything unticked is hidden from them entirely.
Where several people share the same job, define the access once as a role rather than ticking boxes per person — see Roles and Permissions.
User Roles
Three roles classify what a user can do, independently of the module permissions above.
| Role | Reach |
|---|---|
| Super Admin | Owns the company. Reaches every page in the subscribed pack, plus the company-level controls listed below. |
| Admin | Not restricted by Roles and Permissions, and reaches everything the pack allows — but not the Super Admin pages. |
| User | Entry level. Access is limited by their assigned role and by the active subscription. |
Super Admin
The default user of the company, and the only role that can:
- Activate and deactivate add-ons and additional apps.
- Control email templates.
- Create branches and departments, and allow them to be changed on transaction screens.
- Revalue currency accounts.
- Close a financial year and close GL dates.
- Import and export data.
Reseller Super Admins additionally reach the Company menu, translation updates, clearing transactions and activating registered users.
Edit Users
Most user attributes can be changed here. Personal settings — password, language, theme and colours — belong to the user and can only be changed by them from their own account.
Forget Password
A user who has lost their password resets it from the forgotten-password page, which requires a working email address on their account. Where the address is wrong or unreachable, support can reset it for you.
Delete and Inactive
A user who has posted transactions cannot be deleted. The audit trail depends on knowing who made each entry, so the system protects it. Set them inactive instead — access is removed and the history stays intact.
Deletion only becomes possible if the financial years containing their entries are removed, which is not something to do casually.
Related pages
- Roles and Permissions — defining access once per job function
- Users Login History — monitoring access
- Delete and Void — what users can reverse
- Sales Persons — linking a user to a salesperson