Manage users and access
Summary: As an administrator, you will add and manage the people in your organization and control what each can reach.
Who can manage users
User management (creating people, changing roles, deactivating and reactivating, provisioning sign-in accounts, and password or MFA resets), is limited to Administrators (and Retailium Platform Administrators). Supervisors and Managers can open the administration area for other reasons (such as store administration) but the user list does not load for them, and no other role can reach the area at all.
The user administration screen
The screen is a browsable list of everyone in the organization, searchable by name, email, and category. Each row shows the person's role, their status, and the actions available on them. Creating and editing a person happens in a panel that slides in from the side, so you keep the list in view: an administrator usually creates one person, sees it appear, and creates the next.
Two badges tell you a person's state: Pending (created but never signed in) and Inactive (deactivated).
Create a person
- Select the action to add a user and fill in their name, email, and role.
- Optionally assign categories and territory scope now (see below).
- Save.
Creating a person does not create a sign-in account: it records the assignment. The person shows a Pending badge until they first sign in through your organization's sign-in provider with the same email, at which point the assignment is claimed automatically.
- A pending person occupies a seat from the moment they are created, not from first sign-in.
- A pending person can be given categories and territory scope (both are held on the assignment and take effect at first sign-in). They cannot be sent a password reset or have a password/MFA set until they have signed in at least once.
- A pending person keeps the role you chose; the sign-in provider's own idea of their role is ignored for them.
There is no bulk import and no CSV upload: people are added one at a time, or arrive by signing in. There is no export of the user list.
Assign categories
Categories are the same named labels used to tag cases. Assigning categories is an access-control act, not a tagging convenience: for every role at or below the Chinese Wall, a person can reach a case only if they hold one of its categories, and a person holding none reaches no case at all. Removing someone's last category takes their case access away. (Roles above the wall (Administrator, Supervisor, Auditor), never consult categories.)
Categories also seed the default labels on cases a person creates, and drive the label filter on case lists. A category change takes effect at the person's next sign-in refresh. See Labels and case visibility.
Assign territory scope (RAPM / DAPL)
Regional and District Asset Protection Managers reach only the stores and incidents inside their assigned territory. Set scope per person on this screen:
- Scope types: region, district, area, or individual store.
- One person may hold several scope rows of mixed types; their reach is the union of all of them.
- Saving replaces the whole set: any scope row not shown when you save is removed.
- A person with no scope reaches no stores or incidents at all.
Deactivate and reactivate
Deactivation is reversible and destroys nothing: the account, the record, and all history are preserved, and everything the person created stays attributed to them.
- It takes effect immediately: the person is signed out of everything on their next page load.
- It frees a seat at once.
- It is refused for the organization's last active Administrator, so an organization can never be left with nobody to administer it.
- The deactivate control is disabled on your own row.
- Reactivating is subject to the seat limit.
There is no hard delete of a person and no way to purge someone's history.
Seats
If your organization has a seat limit, this screen shows usage ("12 of 25 active users"), warns from 90%, and disables Create User at the limit. Deactivated people hold no seat; pending (invited) people do. Only Retailium can raise the limit: see Organization settings.