Administration · People and access

Set Up Users and Roles

Add the people who work in your books, give each one a role, choose the locations they work at, and reset passwords.

☰ Company ▸ Set Up Users and Roles…☰ Menu ▸ Admin ▸ Users & Roles
serobooks / company / set up users and roles…Live
Watch it in the appUsers, roles and permissions Staff accounts, roles, View and Allow on every screen and action, and approvals at the till.

Users & Roles is where you decide who can sign in to your company and what each person can do. Every person who works in SeroBooks — the owner, a bookkeeper, an accounts clerk, your outside accountant's staff — should have a login of their own. Each login carries one role, and the role decides which screens and buttons the person sees and which ones need a manager's approval.

Use this screen when you:

  • add a new member of staff, or give your bookkeeper their own login instead of sharing yours;
  • change what someone may do by moving them to a different role;
  • reset a forgotten password;
  • stop someone signing in (make the user inactive) when they leave;
  • decide which of your locations a person works at.

Opening Users & Roles

  • From the menu bar: Company ▸ Set Up Users and Roles…
  • From the left menu: click the Menu button (☰) at the left of the top bar, choose Admin, and click the Users & Roles tile in the Settings section.

Both routes open the same screen. Before it opens, SeroBooks checks that your role holds the Users & Roles permission (in the Workspace tab of the role editor). If it does not, a Manager Approval box appears: an Admin or a Manager types their Login ID and Password to let you in for this one visit. See Roles and permissions explained.

The Users & Roles screen

The screen heading reads Users & Roles, with Staff accounts for this business underneath.

Part of the screenWhat it does
Refresh (circular arrow, top right)Re-reads the list of users and roles from this computer's copy of your company.
Manage roles & permissionsOpens the Roles screen, where you create and edit roles. See Roles and permissions explained.
The user listOne row per user in this company, sorted by first name.
Add User (button, bottom right)Opens the Add User form. The button is not shown until at least one role exists.
? (Help, top bar)Opens help for this screen.

Each row in the list shows:

ItemMeaning
IconColoured for an active user, grey for an inactive one.
NameThe user's first and last name. If both are blank, the login name is shown instead.
Second lineThe user's login name, their role, and the word Inactive if they cannot sign in.
Reset password (padlock icon)Opens the Reset password box for that user.
Edit (pencil icon)Opens the Edit User form for that user.

If the company has no users on this computer yet, the list reads No users found.

Adding a user

  1. Open Company ▸ Set Up Users and Roles….
  2. Click Add User. A Loading... message appears briefly while SeroBooks asks the server for your company's staff login handle.
  3. Fill in the form (every field is described in the next table).
  4. Click Add.
  5. The User added card appears with the new login and password. Click Copy login details to copy both to the clipboard, or click the eye icon to show the password, then click Done.

Give the person their login and password. They sign in with exactly that login on the sign-in screen.

The Add User and Edit User form

FieldWhat to enter
First name *Required. The name shown in the user list, on the audit trail and in chat.
Last nameOptional.
Username *The name part of the login only — for example sarah. The box shows @yourhandle after what you type, and a line underneath reads They'll sign in as sarah@yourhandle. Type just the name: the @ part is added for you. See Staff sign-in names.
Business login handle *Shown only when your company does not have a staff login handle yet. The first user you add sets it for the whole company. SeroBooks suggests one from your company name and checks it as you type.
Email (optional)Leave it blank if the person has no email. If you fill it in, it must be a real email address. Nobody signs in with it.
Password *New users only. The rule depends on the role you pick — the hint under the box changes as you change the role.
Role *Choose from your company's roles. The # and number that SeroBooks stores after each role name are not shown.
ActiveOn: the person can sign in. Off: the login is kept but refused at sign-in.
Works at *Tick every location this person works at. For a new user every location is ticked to start with. At least one must be ticked.

On a company whose staff sign in with plain names (an older company that has never used a staff login handle), the Username box is called Login username and takes the whole login.

Password rules

RoleThe password must have
Admin or ManagerAt least 8 characters with upper and lower case letters, a number and a symbol, and it must not be a password found in a known data leak.
Any other roleAt least 8 characters with at least one letter and one number.

The form checks the password before it is sent. The server checks it again, including the data-leak check for Admin and Manager passwords; if it refuses, the message appears in red at the bottom of the form and everything you typed stays in place so you can pick another password.

Validation messages on the form

MessageWhat to do
First name is requiredType a first name.
Enter a usernameType the name part of the login.
Leave out the @ — it is added for youDelete the @ and everything after it.
Usernames cannot contain spacesRemove the spaces, or use a dot, dash or underscore instead (sarah.k).
Use 2 to 30 letters, numbers, dots, dashes or underscoresShorten the name or remove other characters. It must start with a letter or number.
Enter a valid email, or leave it blankCorrect the email or clear the box.
Use at least 8 characters, Include at least one letter, Include at least one number, Include both upper and lower case letters, Include at least one symbolChange the password to meet the rule for the role.
Tick at least one locationTick at least one location under Works at.
"name@handle" is already taken. Choose a different username.Someone already has that login. Use a different name, such as sarah2 or sarah.k.
Your plan's user limit is already used. Upgrade the plan or deactivate a user first.Your subscription's user allowance is full. See Your subscription and plan.
This business does not have an active subscription.Renew the subscription before adding users.

Your plan includes a number of users: SeroBooks Standard includes 5 and SeroBooks Pro 10, plus any extra users you have added to the plan (during the free trial, the Pro allowance applies). When that many users already exist, clicking Add User opens an Upgrade to SeroBooks Pro card (Your plan includes N users) instead of the form. It lists what SeroBooks Pro adds and says that extra users can be added to any plan. See Pro plans opens the SeroBooks pricing page in your browser; Not now closes the card.

Editing a user

  1. Click the pencil icon on the user's row.
  2. Change the fields you need. The password is not on this form — use Reset password instead.
  3. Click Save. A green message confirms User updated successfully.

Things to know when editing:

  • A login keeps its shape. A name@handle login stays name@handle: you edit only the name part. An older plain login is shown whole and stays a plain login. SeroBooks never moves an existing login onto the new scheme.
  • Works at shows the locations the user already has. If SeroBooks cannot read them, the section is hidden rather than shown empty, so saving cannot take their locations away.
  • The last Admin is protected. You cannot make the only active Admin inactive (Cannot deactivate the last active Admin), and you cannot move them to another role (Cannot remove the Admin role from the last active Admin). Make someone else an Admin first.
  • Changing a user's role takes effect the next time that person signs in. Ask them to sign out (File ▸ Sign Out) and back in.

Resetting a password

  1. Click the padlock icon on the user's row. The Reset password for … box opens.
  2. Type the New password. The hint under the box shows the rule for that user's role.
  3. Click Reset.
  4. The Password reset card shows the login and new password with Copy login details and Done.

If the server refuses the password (for example because it appears in a data leak), the reason appears in red and the box stays open so you can type another.

Making a user inactive

To stop someone signing in without losing their history, edit the user, switch Active off and click Save. Their row then shows Inactive. Every document they entered keeps their name. Switch Active back on to let them sign in again.

There is no delete button for users on this screen: making the user inactive is the safe way to remove access.

Locations: "Works at"

A location is a branch, shop or warehouse of your company. Works at controls which locations the person can see and work in. If the role does not have Allow multiple locations switched on (in the role's Web Access tab), each user on that role works at exactly one location.

If you see the red message Works at: no locations are available to your account, so this cannot be set here. Sign in as an admin to assign locations to this user., your own login has no locations it may manage. Sign in as the Admin to assign locations.

Roles

A role is a named set of permissions: what a person sees, and what they may do without asking. Click Manage roles & permissions to open the Roles screen, where you can:

  • add a role, starting from one of the ready-made SeroBooks roles (Accountant, Bookkeeper, AR Clerk, AP Clerk, Sales Clerk, Auditor (read-only));
  • edit what a role may see and do;
  • delete a role that nobody uses.

Every company has an Admin role, which is the owner's. It is marked with a shield and padlock and cannot be edited or deleted: the Admin always has full access. A role named Manager can approve other people's locked actions.

Roles and permissions explained describes the Roles screen, every permission and the ready-made roles in full.

Tips

  • Give everyone their own login. The audit trail, document history and approvals all record who did what. A shared login makes them meaningless.
  • Start from a ready-made role. On the role editor, Start from a role fills in a sensible set of permissions in one click; adjust from there.
  • Copy the login details straight away. The User added card is the only place the new password is shown. If you close it, reset the password to get a new one.
  • Deactivate, do not share. When someone leaves, make their user inactive rather than changing the password and passing the login on.

Common problems

The Add User button is missing. No roles exist on this computer yet. Click Refresh; if the list of roles is still empty, open Manage roles & permissions and create a role, or use Sync DataBase from the left menu.

The new user cannot sign in. Check that they typed the full login shown on the User added card, including the @handle part, and that Active is on. See Staff sign-in names.

A user sees screens they should not, or cannot see screens they need. Their role decides this. Open Manage roles & permissions, edit the role, and check the SeroBooks Access tab. See Permissions: "you do not have access".

A Manager Approval box appears when I open Users & Roles. Your role does not hold the Users & Roles permission. Ask an Admin or Manager to approve, or ask the Admin to tick Users & Roles in your role's Workspace tab.