dahoam.digital
← Back to help

Users and roles

This is where you decide who works with aYOUne and what that person may do. The two hang together: an account on its own sees nothing — only the role decides which areas open up.

The idea in three sentences

A role is a ready-made bundle of permissions that you put together once and hand out as often as you like. A user is an account to which you assign exactly one role. If you change the role later, access changes immediately for everyone who holds it — you never have to touch an individual account.

That is why it pays to build the roles first and create the people afterwards.

Creating a role

Administration → Roles → Create

The overview shows every existing role with four pieces of information:

Column Meaning
Name What the role is called, for example Sales or Service
Description What it is meant for — fill this in, your future self will thank you
Default If ticked, it is suggested for new accounts
Permissions How many permissions the role covers

When creating a role you give it a name and pick which areas it should open. The areas are grouped by topic, so you do not have to scroll through an endless list.

A practical piece of advice: create few well-considered roles rather than many special cases. Five to ten roles are enough for the vast majority of companies. If you need a variant, duplicate an existing role and adjust it instead of starting from scratch.

When an area cannot be granted

Some areas cannot be selected even though you can see them in the list. In that case the area is not part of the scope you have booked. This is not a misconfiguration you could fix yourself — talk to your contact about an extension.

The other way round: a role can never open more than your scope allows. So there is nothing you can break by configuring it.

Creating a user

Administration → Users → Create

The "Create user" form with all of its fields The form asks for:

Field Note
First name, Last name How the person appears in lists and assignments
Email Also the sign-in — it has to be right, the invitation goes there
Username A short form, for signing in and for mentions
Position Free text, for example Head of Sales
Phone Optional
Role The choice from the previous section
Active On by default — only an active account can sign in
Admin Off by default. See below

Then save. The person receives an email and sets their own password.

Next to Create there is Invite team member. The difference: when creating, you fill in the master data yourself; when inviting, the invited person adds it on first sign-in. For a single new colleague, inviting is the shorter route.

The admin switch

The Admin switch lifts an account beyond its role and gives it access to the administration itself — that is, to exactly the chapters of this handbook. Hand it out sparingly and only to people who really are meant to maintain accounts and roles.

Rule of thumb: in a company of thirty people, two or three need this switch, not ten.

Leavers: deactivate rather than delete

When someone leaves the company, switch Active off instead of deleting the account. Signing in is blocked immediately, but everything that person created — records, notes, assignments — stays readable and correctly attributed.

Delete the account instead and you lose that attribution. Deleting is meant for test accounts, not for former colleagues.

What the overview shows you

The user list tells you at a glance whether an account is active, since when it has existed and when the person last signed in. The Last login column is the fastest way to find orphaned accounts: anyone who has not signed in for months probably no longer needs access.

Was this article helpful?

👎 No (0)
Leave a comment

Didn't find what you were looking for?

Get in touch