User Management
The Users section of the Control Center allows administrators to create, manage, and monitor user accounts across the system.
Viewing Users
User List
Navigate to Control Center > Users to see all users in the system. The user list displays:
- User name and avatar
- Username/email
- Status (Active/Inactive)
- Assigned roles
- Last login date
Filtering Users
Use the tabs and search to find specific users:
| Filter | Description |
|---|---|
| All | Shows all users regardless of status |
| Active | Shows only enabled users |
| Inactive | Shows only disabled users |
| Search | Filter by name, username, or email |
Creating a New User
Step 1: Navigate to Create User
- Go to Control Center > Users
- Click the Create User button
- Fill in the required information
Step 2: Enter User Details
| Field | Required | Description |
|---|---|---|
| Name | Yes | The user's full display name |
| Username | Yes | Unique identifier for login |
| Yes | User's email address | |
| Password | Yes | Initial password for the account |
Step 3: Assign Initial Role (Optional)
You can assign a role during user creation or do it later from the user's profile.
Step 4: Save
Click Create to create the user account. The user can now log in with the provided credentials.
Editing a User
Accessing User Profile
- Go to Control Center > Users
- Click on the user's name or the edit icon
- Make changes to the user's information
Editable Fields
| Field | Description |
|---|---|
| Name | User's display name |
| Username | Login identifier |
| Contact email | |
| Avatar | Profile picture |
Note: Some fields like username may have restrictions to prevent conflicts with existing accounts.
Managing User Status
Enabling a User
If a user account has been disabled:
- Find the user in the user list (check the Inactive tab)
- Click on the user to open their profile
- Click Enable User
- The user can now log in again
Disabling a User
To temporarily revoke a user's access:
- Find the user in the user list
- Click on the user to open their profile
- Click Disable User
- The user will be logged out and cannot log in until re-enabled
Important: Disabling a user does not delete their data. All their records, activity logs, and assignments are preserved.
Password Management
Generating a Temporary Password
If a user forgets their password or needs a reset:
- Open the user's profile
- Click Generate Password
- A secure temporary password will be generated
- Share the password securely with the user
- The user will be required to change their password on next login
Generated passwords include:
- 12 characters minimum
- Uppercase and lowercase letters
- Numbers
- Special characters
Setting a Specific Password
Administrators can also set a specific password:
- Open the user's profile
- Click Set Password
- Enter the new password
- The user will be required to change it on next login
Security Note: Always communicate passwords through secure channels. Never send passwords via unencrypted email.
Managing User Roles
Viewing Assigned Roles
A user's current roles are displayed on their profile page, showing:
- Role name
- Organization scope (if applicable)
- Assignment date
Assigning a Role
- Open the user's profile
- Click Assign Role
- Select the role from the dropdown
- (Optional) Select an organization if the role is organization-specific
- Click Assign
Removing a Role
- Open the user's profile
- Find the role in the assigned roles list
- Click the remove icon next to the role
- Confirm the removal
Note: Some roles may be organization-scoped, meaning the user only has that role's permissions within a specific organization and its sub-units.
Viewing User Activity
Activity Logs
To see what actions a user has performed:
- Open the user's profile
- Navigate to the Activity Logs tab
- View the chronological list of activities
Activity logs show:
- Date and time
- Action performed
- Affected resource
- Additional details
Filtering Activity Logs
| Filter | Description |
|---|---|
| Date Range | Filter by specific time period |
| Event Type | Filter by action type (created, updated, deleted) |
| Log Name | Filter by module or category |
Managing User Sessions
Viewing Active Sessions
To see where a user is currently logged in:
- Open the user's profile
- Navigate to the Sessions tab
- View all active sessions
Session information includes:
- Device type and browser
- IP address
- Last activity time
- Login time
Understanding Session Data
| Field | Description |
|---|---|
| Browser | The web browser being used |
| Device | Operating system and device type |
| IP Address | Network address of the connection |
| Last Activity | When the session was last active |
User Statuses Explained
| Status | Description | Can Login? |
|---|---|---|
| Active | Normal account status | Yes |
| Inactive/Disabled | Account has been disabled by admin | No |
| Password Reset Required | User must change password on next login | Yes (then must reset) |
Best Practices
Creating Users
- Use meaningful usernames - Make usernames easy to remember and identify
- Set strong initial passwords - Use the generate password feature
- Assign appropriate roles - Only give users the access they need
- Document the purpose - Keep records of why accounts were created
Managing Existing Users
- Regular audits - Periodically review user accounts
- Disable instead of delete - Preserve audit trails by disabling rather than deleting
- Monitor activity - Check activity logs for unusual behavior
- Prompt role reviews - Review roles when job functions change
Security Recommendations
- Enforce 2FA - Encourage all users to enable two-factor authentication
- Regular password changes - Implement password rotation policies
- Session monitoring - Review active sessions for suspicious activity
- Principle of least privilege - Assign minimum necessary roles
Common Tasks
Onboarding a New Employee
- Create a new user account
- Generate a secure temporary password
- Assign appropriate roles
- Send login credentials securely
- Guide them to set up 2FA
Offboarding an Employee
- Disable the user account (do not delete)
- Remove sensitive roles
- Review and reassign any pending tasks
- Document the offboarding date
Investigating Security Concerns
- Check the user's activity logs
- Review active sessions
- If suspicious, disable the account
- Generate a new password if account was compromised
- Review audit logs for affected resources