Setup¶
3 screens.
Users¶
Setup → Users
Who can sign in, as what. Permissions belong to the role, never to the person.
What you see¶
Every active user with their email, name, role, linked customer and status. An active user who has not yet chosen their own password carries the caption must set password.
A tick box brings disabled users back into the list, greyed.
Fields¶
| Field | What goes in it |
|---|---|
| Email, Full name, starting password, Role… | All required to create a user. |
| Subsidiary (optional) | Optional. |
| Linked customer id (portal only) | Ties the account to that customer's orders. Portal logins only. |
Buttons¶
| Button | When you can use it | What it does |
|---|---|---|
| + New user | Always. Reads Cancel once open. | Opens the form. |
| Create user | Once the required fields are filled in. | Creates the account. Tell them the password you set — they are required to replace it the first time they sign in. |
| Edit | On any user. | Turns the name and role into editable boxes in place. |
| Save | While editing. | Saves the name and role. |
| Cancel | While editing. | Abandons the edit. |
| Disable | On an active user. Reads Enable on a disabled one. | Asks first, saying which way it is going. Disabling stops sign-in immediately and can be undone. |
| Reset password | On any user. | Asks for the new password in a prompt, then resets it and ends every session that person has open. Use sparingly. |
| Unlock | On any user. | Clears a lockout. It does not change the password and does not end their sessions. One of the six that deliberately does not ask. |
| What can they do? | On any user. | Shows exactly what this person can reach and how they got it, resolved the way the system enforces it. |
Rules this screen enforces¶
- There is no delete. Disabling stops somebody signing in immediately and can be undone; deleting them would strip their name off every journal, pick task and approval they ever touched.
- The last active administrator cannot be disabled or demoted, and you cannot remove your own administrator access. The server refuses and says why.
- Ask for an unlock, not a password reset. The reflex is a reset, which forces a change on somebody whose only mistake was typing badly and ends every session they had.
- An account in the administrator centre bypasses every permission check. The panel says so rather than showing an almost-empty permission list that does not govern it.
Roles¶
Setup → Roles
What each job can reach. A role has a centre, which decides which menus and dashboard its holders see, and a set of permissions, which decides what they can open.
What you see¶
One panel per role, with its centre, how many users hold it, and its granted permissions. A tick box brings retired roles back into view.
Fields¶
| Field | What goes in it |
|---|---|
| Role name, Centre, Description (optional) | A new role. |
| The permission matrix | Every record type with a level. |
Buttons¶
| Button | When you can use it | What it does |
|---|---|---|
| + New role | Always. Reads Cancel once open. | Opens the form. |
| Create role | Once a name is filled in. | Creates it. Assign it to somebody on the Users tab. |
| Edit permissions | On any role. | Opens the matrix in place. |
| Save permissions | While editing. | Saves them. |
| Retire | On a live role. Reads Reactivate on a retired one. | Asks first. Retiring means nobody new can be given it; it is retired, not deleted, because its name appears in the audit trail. |
Rules this screen enforces¶
- The admin centre bypasses every permission check. Anybody given a role in that centre has full access to the entire system, including payroll and this screen, whatever is ticked below it. Choosing it raises a red warning.
- Levels build on each other: edit includes create, create includes view.
- Anything left at none is revoked when you save.
- A role cannot be retired while anybody still holds it, and the last administrator role cannot be retired at all.
Tax Codes, Currencies, and the system logs¶
Setup → Tax Codes · Currencies & Rates · Sign-in Record · Audit Trail · Governance
Rates that change over time, and the record of what happened.
What you see¶
On Tax Codes: every code with its current rate. Clicking one shows its rate history and a form to schedule a new rate.
On Currencies: every currency, which are in use, how many rates are on file and the latest. If one is used by a company and has no rate at all, a warning sits at the top.
On Sign-ins: a filter by email, a failures-only tick box, and the attempt log — when, who, the result, why, the address and the browser. Entering an email also shows whether that address is locked and for how long.
On Audit: changes to records. On Governance: usage metering and anything that was throttled.
Fields¶
| Field | What goes in it |
|---|---|
| Rate (%), Effective from | Scheduling a tax rate. Type 9 for 9%, not 0.09. |
| Currency, Effective date, 1 XXX = ? SGD | An exchange rate. The caption is generated from the currency you chose, so the direction is in the label. |
| Email, Failures only | Filters on the sign-in record. |
Buttons¶
| Button | When you can use it | What it does |
|---|---|---|
| Rates | On any non-base currency. | Loads that currency's history and selects it in the form. |
| Save | Only once a currency, a date and a rate are filled in. | Records the rate. |
| Schedule | Once a rate and a date are filled in. | Schedules the new tax rate. |
| Refresh | On the sign-in record. | Re-reads the log. |
| Unlock now | When the email you entered is locked. | Clears the lockout. It does not change the password and does not end their sessions; the failed attempts stay on the record. One of the six that deliberately does not ask. |
| Close | On the rate-history panel. | Dismisses it. |
Rules this screen enforces¶
- Read the sanity line before saving an exchange rate. As soon as you type a number the screen reads it back both ways round — "Reads as: 1 MYR = 0.29 SGD · 1 SGD = 3.448276 MYR." Typing a rate the wrong way round is the commonest and quietest error in the whole system, and this is the one thing that catches it.
- A wrong rate is corrected by entering the right one for the same date. Both stay on file; nothing is edited in place, because a rate that changed silently would restate postings nobody looked at again.
- Scheduling a tax rate never rewrites tax already posted. Only transactions dated on or after the effective date use it.
- Successes are on the sign-in record deliberately. A log of failures alone shows you an attack only after it worked; the pair shows you an unfamiliar address signing in at four in the morning.
- The password is never recorded, not even on a failure — a failure very often contains a real password with a typo in it.
- Custom Fields, Workflows and Saved Searches are read-only lists on this screen; they are defined elsewhere.
When there is nothing to show¶
| Where | What it says |
|---|---|
| Sign-in record, unknown address | Nothing recorded for that address yet. |