Users
Invite people to sign in, decide what each of them may see and change, and group them for approvals and notifications.
Users is where a propane office controls who can sign in to AimRack and what each person may do once they are in. It is separate from People, which keeps staff records: a driver can have a People record with a shift and a manager, and a Users account decides whether that driver can sign in and which parts of AimRack they can open.
The left sidebar has two groups. Manage holds Accounts, Groups, and Operators when console mode is turned on. Configure holds Employee Types.
How permissions work in AimRack
Every permission is an area of AimRack, such as Sales, Inventory, Purchasing or Accounting, paired with one of four actions: view, create, update or delete. Someone with view on Sales can read quotes and orders; someone with update on Inventory can change stock records. Nothing is allowed that was not granted.
Every permission screen is the same grid: one line per area and one checkbox per action. You can tick a single box, a whole line for an area, or everything at once.
AimRack checks these permissions twice: the screens hide what a person may not use, and the database refuses any request the permissions do not allow, even one that does not come through a screen.
How to invite someone when they need to sign in
- Open Users → Accounts and click Add Account. The Create an account form opens.
- Enter their Email, First Name and Last Name, choose an Employee Type, and pick their Location.
- Click Invite.
AimRack emails them a link to finish joining; you never set a password for anyone. Until they accept, the list shows them as Invited. From the row's menu you can Send Invite again, or Revoke Invite if it was sent by mistake.
The Accounts list shows each person's First Name, Last Name, Email, Employee Type and Status (Active, Invited or Inactive). When the company requires two-factor authentication, it also shows a Two-Factor column: Enabled or Not set up.
How to change what one person may do when their job changes
- Open Accounts and choose Edit Permissions from the person's menu.
- To start from a different template, pick another Employee Type. AimRack asks whether to Overwrite Permissions with that type's defaults or Keep Current permissions.
- Tick or clear boxes in the grid for any exceptions this person needs.
- Click Save.
How to change permissions for many people when a whole team needs the same access
- In Accounts, select the people, then choose Edit Permissions for the selection.
- Pick the Type of Permission Update: Add Permissions adds the ticked boxes to what each person already has and takes nothing away; Update Permissions replaces each person's permissions with exactly the ticked boxes.
- Tick the boxes and click Save.
Use Update Permissions only when you mean to overwrite. Changing an employee type later does not change the people already on it; this bulk edit is how you pass a type change on to existing staff.
How to set up employee types when several people share a role
An employee type is a named set of default permissions, such as one for drivers and one for the office.
- Open Configure → Employee Types and click Add Employee Type.
- Enter the Employee Type name and tick its Default Permissions.
- Click Save.
New people given this type start with these permissions. View Employees lists everyone on a type. A protected type, such as Admin, cannot be deleted.
In the simulated business, every employee is on the one type Driver.
How to group people when approvals or notifications go to a team
A group is a named list of people, used wherever AimRack asks who should approve something or who should be notified, for example the approvers of a large purchase order in Settings.
- Open Manage → Groups and click Add Group.
- Enter the Group Name, add the Group Members, and click Save.
How to remove someone's access when they leave
- In Accounts, choose Deactivate Account from the person's menu, or select several people and choose Deactivate Users.
- Confirm with Deactivate.
Deactivation removes the person from the company and takes away their permissions; their name stays on the records they created. Their status becomes Inactive.
How to help someone who lost their authenticator app
Choose Reset Two-Factor Auth from the person's menu. Their authenticator is removed. When the company requires two-factor authentication, they set up a new one the next time they sign in.
How to read the Operators page when it appears
Operators appears only when Console Mode is turned on in Settings → People. Console mode is a PIN sign-in for shared terminals: an operator is an account with no email sign-in, a First Name, Last Name, Location and a PIN, which the page can copy or regenerate. No screen in AimRack signs in with that PIN, so leave console mode off.