Employee account and security settings control sign-in access, security roles, and invitation emails.
Understand employee account and security settings #
The Account & Security screen controls the employee's system account. From this screen you have the ability to create or modify a username, reset the user's password, modify the Security Roles the user is a member of, as well as the ability to lock or disable the user's account, prohibiting them from logging in.
Tip: It is important to understand that creating an employee record does not automatically give that person permission to sign in. Once a new employee is created and saved in the system you must proceed to the employee's 'Account & Security' section to set up the user's login and permissions.
Options and field descriptions #
Username – The name or email address the employee uses to sign in.
Note: If 'Is Email Address Username?' is enabled in the system Security Settings the username field will be disabled and contain the user's email address.
Reset Password – Sends the employee the information needed to create a new password. MindSalt does not email the employee’s password.
Email the New User their Login Information? – This option is only available when creating a new employee's account. When selected (selected by default), after you select the 'Save' button the new user will receive an email stating that their account has been set up. Included with the email will be the user's system login credentials, including a system-generated password and a link to the login screen.
User is a System Administrator – This option indicates whether or not the user should be given full, administrative access to the system. Full, administrative access includes access to all menu selections, screens, and reports, regardless of the Security Roles selected for this user.
Security Roles – Select the appropriate Security Roles that the user should have access to. Multiple Security Roles can be selected, even if their permissions overlap.
Note: If the 'User is a System Administrator' option is selected, the user will have full, administrative access to all menu selections, screens, and reports, regardless of the Security Roles selected.
Setting up an Employee's Login #
Note: When creating a new employee or user (see Create and manage employees), the 'Account & Security' screen will not be available until you save the employee details. The employee details is the screen that contains general information about the employee and is the first step in creating a new employee. After selecting save on the employee details screen the 'Account & Security' link will be available on the left-hand side of the screen.
- Browse to Admin, select Employees, and then select Employees.
- Select an employee from the list.
- Select Account & Security.
- Provide a username (if applicable).
- Select the appropriate Security Roles the user should be a member of.
- Select Save.
Set up sign-in and send an invitation #
An employee record and sign-in access are related but separate. After the employee record has been saved:
- Browse to Admin, and then select Employees.
- Open the employee.
- Select Account & Security.
- Review the username or email address used to sign in.
- Make sure sign-in is active.
- Select the employee’s security roles.
- Select the option to email an invitation when the employee should receive one.
- Select Save.
The invitation email gives the employee a secure link to set up access. If the message is not received, confirm the email address and ask the employee to check the spam or junk folder before sending another invitation.
Reset access or offboard an employee #
Use Reset Password when an employee who signs in directly to MindSalt needs to create a new password. If your organization uses single sign-on, use the identity provider’s password recovery process instead.
Before offboarding an employee, review pending time, expenses, approvals, project assignments, and manager responsibilities. Disable sign-in or archive the employee according to your company’s policy, and preserve the history needed for reports.