Overview
Use Users and roles to control who can access the Nexudus dashboard and what they can do. A user is an individual staff account. A role is a permission, and a user role is a reusable group of permissions that you assign to users. Go to Settings → Users to manage staff accounts, and Settings → Roles to manage permission groups. You need administrator access or the corresponding user and role permissions.Permissions are additive. A user receives the combined permissions of every user role assigned to them.
Create a user
1
Open Users
Select Settings → Users and add a user.
2
Enter account details
Add the person’s name, email address, preferred language, and default location.
3
Set sign-in access
Set or generate a password. Enable password reset on first sign-in when appropriate.
4
Set location access
On the access section, select the locations the user can work with.
5
Assign user roles
Assign the permission groups needed for the person’s work, then save the account.
User fields
Build a permission group
1
Open user roles
Go to Settings → Roles → User roles.
2
Create or copy a group
Create a named group, or start from a supplied template such as read-only, billing, or operations.
3
Choose permissions
Select the permissions needed for the job, then save the group.
4
Assign the group
Return to the user record and add the group in its access section.
Permission names
Permissions use an entity and action, such asCustomer-Read or Invoice-Create.
Administrators and API access
An administrator has unrestricted dashboard access. Administrator access overrides assigned user roles, so reserve it for staff who administer the platform. Enable API access only for accounts used by a trusted integration. Use a separate, least-privilege account where possible and review it when the integration changes.Best practices
- Give users the smallest set of permissions that lets them complete their work.
- Restrict users to the locations they need.
- Use named user roles instead of manually recreating the same permissions for each user.
- Remove access promptly when a staff member changes role or leaves.