Access Control¶
Manage user accounts, roles, and access control settings.
The Access Control module provides comprehensive management of users and roles for system authentication and permission control. It enables administrators to create and manage employee accounts, define role-based access control (RBAC), and configure security-related settings.
Navigation: Admin → Users & Security
What You'll Configure¶
Employee accounts and group management
Role-based access control configuration
Authentication and login configuration
Documents in This Section¶
Create and manage system user accounts for employees. Assign users to groups and roles to control permissions.
View Documentation →Define role-based access control (RBAC) with specific permissions. Manage standard and custom roles for different responsibilities.
View Documentation →Configure authentication methods, login settings, registration policies, and password reset functionality.
View Documentation →Module Structure¶
The Access Control module includes the following sections:
- Users - Create and manage system user accounts for employees.
- Roles - Define role-based access control with permissions.
- User Login & Security Settings - Configure authentication methods and security policies.
Key Operational Considerations¶
Users¶
- Users represent employees who need system access
- Each user has a unique User ID used for login and tracking
- Users can be assigned to groups for organizational structure
- Users can have multiple roles for different responsibilities
- Disabling a user is preferred over deletion to maintain audit history
Roles¶
- Roles define permissions and access levels in the system
- Standard roles are created during initial setup
- Permissions can be customized for each role
- Users inherit all permissions from assigned roles
- Multiple roles can be assigned to a single user (permissions combine)
User Authentication¶
- Password security should follow organizational policies
- Users can reset passwords if configured
- Login settings can be customized per organization
- External authentication providers may be integrated
- User session and access logging is maintained
Access Control Best Practices¶
- Create users only for employees who need system access
- Assign the minimum roles required for job responsibilities
- Regularly audit user accounts and role assignments
- Use user groups to organize employees by department or location
- Implement strong password policies and change procedures
- Disable rather than delete user accounts when employees leave
- Monitor access patterns and system usage for security purposes
- Document access level assignments and maintain audit trails