Skip to content

Setup

3 screens.

Users

Setup → Users

Who can sign in, as what. Permissions belong to the role, never to the person.

What you see

Every active user with their email, name, role, linked customer and status. An active user who has not yet chosen their own password carries the caption must set password.

A tick box brings disabled users back into the list, greyed.

Fields

Field What goes in it
Email, Full name, starting password, Role… All required to create a user.
Subsidiary (optional) Optional.
Linked customer id (portal only) Ties the account to that customer's orders. Portal logins only.

Buttons

Button When you can use it What it does
+ New user Always. Reads Cancel once open. Opens the form.
Create user Once the required fields are filled in. Creates the account. Tell them the password you set — they are required to replace it the first time they sign in.
Edit On any user. Turns the name and role into editable boxes in place.
Save While editing. Saves the name and role.
Cancel While editing. Abandons the edit.
Disable On an active user. Reads Enable on a disabled one. Asks first, saying which way it is going. Disabling stops sign-in immediately and can be undone.
Reset password On any user. Asks for the new password in a prompt, then resets it and ends every session that person has open. Use sparingly.
Unlock On any user. Clears a lockout. It does not change the password and does not end their sessions. One of the six that deliberately does not ask.
What can they do? On any user. Shows exactly what this person can reach and how they got it, resolved the way the system enforces it.

Rules this screen enforces

  • There is no delete. Disabling stops somebody signing in immediately and can be undone; deleting them would strip their name off every journal, pick task and approval they ever touched.
  • The last active administrator cannot be disabled or demoted, and you cannot remove your own administrator access. The server refuses and says why.
  • Ask for an unlock, not a password reset. The reflex is a reset, which forces a change on somebody whose only mistake was typing badly and ends every session they had.
  • An account in the administrator centre bypasses every permission check. The panel says so rather than showing an almost-empty permission list that does not govern it.

Roles

Setup → Roles

What each job can reach. A role has a centre, which decides which menus and dashboard its holders see, and a set of permissions, which decides what they can open.

What you see

One panel per role, with its centre, how many users hold it, and its granted permissions. A tick box brings retired roles back into view.

Fields

Field What goes in it
Role name, Centre, Description (optional) A new role.
The permission matrix Every record type with a level.

Buttons

Button When you can use it What it does
+ New role Always. Reads Cancel once open. Opens the form.
Create role Once a name is filled in. Creates it. Assign it to somebody on the Users tab.
Edit permissions On any role. Opens the matrix in place.
Save permissions While editing. Saves them.
Retire On a live role. Reads Reactivate on a retired one. Asks first. Retiring means nobody new can be given it; it is retired, not deleted, because its name appears in the audit trail.

Rules this screen enforces

  • The admin centre bypasses every permission check. Anybody given a role in that centre has full access to the entire system, including payroll and this screen, whatever is ticked below it. Choosing it raises a red warning.
  • Levels build on each other: edit includes create, create includes view.
  • Anything left at none is revoked when you save.
  • A role cannot be retired while anybody still holds it, and the last administrator role cannot be retired at all.

Tax Codes, Currencies, and the system logs

Setup → Tax Codes · Currencies & Rates · Sign-in Record · Audit Trail · Governance

Rates that change over time, and the record of what happened.

What you see

On Tax Codes: every code with its current rate. Clicking one shows its rate history and a form to schedule a new rate.

On Currencies: every currency, which are in use, how many rates are on file and the latest. If one is used by a company and has no rate at all, a warning sits at the top.

On Sign-ins: a filter by email, a failures-only tick box, and the attempt log — when, who, the result, why, the address and the browser. Entering an email also shows whether that address is locked and for how long.

On Audit: changes to records. On Governance: usage metering and anything that was throttled.

Fields

Field What goes in it
Rate (%), Effective from Scheduling a tax rate. Type 9 for 9%, not 0.09.
Currency, Effective date, 1 XXX = ? SGD An exchange rate. The caption is generated from the currency you chose, so the direction is in the label.
Email, Failures only Filters on the sign-in record.

Buttons

Button When you can use it What it does
Rates On any non-base currency. Loads that currency's history and selects it in the form.
Save Only once a currency, a date and a rate are filled in. Records the rate.
Schedule Once a rate and a date are filled in. Schedules the new tax rate.
Refresh On the sign-in record. Re-reads the log.
Unlock now When the email you entered is locked. Clears the lockout. It does not change the password and does not end their sessions; the failed attempts stay on the record. One of the six that deliberately does not ask.
Close On the rate-history panel. Dismisses it.

Rules this screen enforces

  • Read the sanity line before saving an exchange rate. As soon as you type a number the screen reads it back both ways round — "Reads as: 1 MYR = 0.29 SGD · 1 SGD = 3.448276 MYR." Typing a rate the wrong way round is the commonest and quietest error in the whole system, and this is the one thing that catches it.
  • A wrong rate is corrected by entering the right one for the same date. Both stay on file; nothing is edited in place, because a rate that changed silently would restate postings nobody looked at again.
  • Scheduling a tax rate never rewrites tax already posted. Only transactions dated on or after the effective date use it.
  • Successes are on the sign-in record deliberately. A log of failures alone shows you an attack only after it worked; the pair shows you an unfamiliar address signing in at four in the morning.
  • The password is never recorded, not even on a failure — a failure very often contains a real password with a typo in it.
  • Custom Fields, Workflows and Saved Searches are read-only lists on this screen; they are defined elsewhere.

When there is nothing to show

Where What it says
Sign-in record, unknown address Nothing recorded for that address yet.