Users and roles
This is where you decide who works with aYOUne and what that person may do. The two hang together: an account on its own sees nothing — only the role decides which areas open up.
The idea in three sentences
A role is a ready-made bundle of permissions that you put together once and hand out as often as you like. A user is an account to which you assign exactly one role. If you change the role later, access changes immediately for everyone who holds it — you never have to touch an individual account.
That is why it pays to build the roles first and create the people afterwards.
Creating a role
Administration → Roles → Create
The overview shows every existing role with four pieces of information:
| Column | Meaning |
|---|---|
| Name | What the role is called, for example Sales or Service |
| Description | What it is meant for — fill this in, your future self will thank you |
| Default | If ticked, it is suggested for new accounts |
| Permissions | How many permissions the role covers |
When creating a role you give it a name and pick which areas it should open. The areas are grouped by topic, so you do not have to scroll through an endless list.
A practical piece of advice: create few well-considered roles rather than many special cases. Five to ten roles are enough for the vast majority of companies. If you need a variant, duplicate an existing role and adjust it instead of starting from scratch.
When an area cannot be granted
Some areas cannot be selected even though you can see them in the list. In that case the area is not part of the scope you have booked. This is not a misconfiguration you could fix yourself — talk to your contact about an extension.
The other way round: a role can never open more than your scope allows. So there is nothing you can break by configuring it.
Creating a user
Administration → Users → Create
The form asks for:
| Field | Note |
|---|---|
| First name, Last name | How the person appears in lists and assignments |
| Also the sign-in — it has to be right, the invitation goes there | |
| Username | A short form, for signing in and for mentions |
| Position | Free text, for example Head of Sales |
| Phone | Optional |
| Role | The choice from the previous section |
| Active | On by default — only an active account can sign in |
| Admin | Off by default. See below |
Then save. The person receives an email and sets their own password.
Next to Create there is Invite team member. The difference: when creating, you fill in the master data yourself; when inviting, the invited person adds it on first sign-in. For a single new colleague, inviting is the shorter route.
The admin switch
The Admin switch lifts an account beyond its role and gives it access to the administration itself — that is, to exactly the chapters of this handbook. Hand it out sparingly and only to people who really are meant to maintain accounts and roles.
Rule of thumb: in a company of thirty people, two or three need this switch, not ten.
Leavers: deactivate rather than delete
When someone leaves the company, switch Active off instead of deleting the account. Signing in is blocked immediately, but everything that person created — records, notes, assignments — stays readable and correctly attributed.
Delete the account instead and you lose that attribution. Deleting is meant for test accounts, not for former colleagues.
What the overview shows you
The user list tells you at a glance whether an account is active, since when it has existed and when the person last signed in. The Last login column is the fastest way to find orphaned accounts: anyone who has not signed in for months probably no longer needs access.