User invitations, session management and security settings
Adding users with an invite link, ending sessions, two-factor authentication, password policy, session duration and device management.
The Users tab#
Users is a tab of its own in the Setup header. The heading carries a summary of your org: total users, active users and administrators. The search box beside it filters by name and e-mail. Each row in the table offers Role, Profile, Hierarchy and an active toggle.
Role, profile and hierarchy are three different things#
- Role is the account type: Admin, Standard or Portal. An Admin sees every app and every record; profile restrictions do not apply to them.
- Profile is the permission package: which apps are open, and the read, edit, create and delete rights per object.
- Hierarchy is the position in the role hierarchy and affects data visibility only: whoever is above sees the records of those below.
For the details see Users, profiles and the role hierarchy and Sharing rules.
Adding a user by invitation#
There are two ways to add someone. + New User means you create the account: you enter a name, e-mail and password and pick the role, profile and hierarchy. Send Invite means you never handle the password:
- Press Send Invite, type the e-mail address, and choose the role, the profile and, if relevant, the hierarchy role.
- An invitation link goes out to that address. The link is valid for 7 days.
- The person opens it (the address is
#/davet/<token>), sets their own name and password, and the account is created with the profile and hierarchy role you chose already applied.
Sent invitations sit in the Pending Invites section under the table, showing who invited whom, when it was sent and when it expires. Each row offers Resend and Cancel, and expired invitations carry a badge. If the e-mail cannot be delivered for any reason, the link is copied to your clipboard so you can pass it on directly.
The row menu#
The three-dot menu at the end of each user row offers:
- Change the name: since ownership is held by name, renaming moves the records that user owns to the new name.
- Change the e-mail: this changes the sign-in identity. You are asked to confirm, and both the old and the new address are notified.
- Avatar colour and Reset password (at least 6 characters).
- Sign out everywhere: drops that user's browser and mobile sessions at once. It is the first move for a lost device or a departing employee.
- Login as: lets an administrator see the app through a user's eyes. You return to your own account from the top right. Platform administrator accounts cannot be entered this way, and a new session cannot start while you are already impersonating someone.
You cannot change your own role or deactivate yourself: that guard exists so an org never locks itself out. If people signed up on their own, an Memberships Awaiting Approval card appears at the top where you Approve or Reject each one.
The Security page#
Setup > Security carries four settings, all enforced on the server: a request that violates the policy is rejected regardless of what the UI allows.
- Mandatory two-factor authentication (2FA): when on, everyone in the org enters a 6-digit code sent to their e-mail on every password sign-in, whatever their personal preference.
- Password policy: a minimum length (6, 8, 10, 12 or 16) and, optionally, a letters-and-digits requirement. It applies to newly set passwords; existing ones are untouched.
- Session duration: Unlimited, 8 hours, 24 hours, 3 days, 7 days or 30 days. After that long from sign-in, the password is asked again; the setting applies from the next sign-in.
- API keys: manage your integration keys from here.
Two shortcuts at the bottom lead to Devices and Sessions and the Audit Log; successful and failed sign-ins live on the Login History tab of the Audit Log.
Devices and Sessions#
Setup > Devices and Sessions lists the mobile and desktop sessions in your org: the user, the device type (iOS, Android, desktop or web), the last use and the creation time. The End session button on each row closes a single device. Sessions unused for more than 90 days carry an Inactive badge. Browser sessions live in a cookie and are not listed here; when you need to close every session for a person, use Sign out everywhere in the Users row menu.
The extra user fee#
Your first user is included with the platform subscription; every further active user adds €25 per month. Inactive users are not counted, which makes deactivating a departing employee the right move for cost as well as for security. Your extra user count and its amount appear live in the Package Summary panel; for the details see Pricing and payment.
For the platform's overall security layers, see Security and auditing.