Skip to main content

User Management and Setting Permissions

Invite teammates, change roles, remove users, and control what each role can do in the Acenda Admin.

S
Written by Sam E.

Effective user management keeps your organization secure while making sure your team has exactly the access it needs. This article covers inviting teammates, assigning roles and permissions, and the day-to-day tasks you'll use most — changing someone's role, resending an invite, and removing a user who's left the company.

Everything here lives under ADMINISTRATION > Users in the left sidebar: the Users tab (invite, edit, and remove people) and the Authorization tab (define what each role can do).


Inviting a new user

  1. Go to ADMINISTRATION > Users.

  2. Click + Invite User in the top right.

  3. In the Invite User panel, enter the person's Email Address and choose a User Role from the dropdown. The dropdown lists your built-in roles plus any custom roles you've created.

  4. Click Invite User to send the invitation. (Click Cancel to close the panel without sending anything.)

The new row shows up in the Users table with a Pending status until they accept. The table also shows each person's roles, status (Active, Pending, or Expired), last login, and IP address.

Tip: Only Owners, Admins, or users with the users:create permission see the + Invite User button.


Day-to-day user tasks

  1. Changing a user's role. Click the pencil (Edit) icon on their row to open Edit User, update User Roles — a user can hold more than one — and click Save. The Owner role can't be removed from a user who has it. The pencil appears on rows for users who have accepted their invite; rows with an Expired invite only show the reactivate and remove icons.

  2. Resending or cancelling an invite. While an invite is Pending, click the resend icon on that row. If it's Expired, the same icon (hover text: Reactivate invite) reactivates it instead. To cancel an invite, click the trash icon (hover text: Remove invite) and confirm.

  3. Removing a user. Click the trash icon on their row and confirm. This immediately revokes their access — there's no separate "deactivate" step. This is how to cut off access for someone who's left your team; you can always invite them again later if needed.


Setting roles and permissions

Click the Authorization tab, next to Users, to open User Authorization. Each role — the built-in Owner, Admin, Employee, and Api Client, plus any custom roles your team has added — has its own tab.

Open a role's tab to see:

  • A Description field you can edit to note what the role is for.

  • A permissions table listing every resource (Items, Orders, and so on) with Create, Read, Update, and Delete checkboxes. For example, selecting Create, Read, and Update — but not Delete — for Items lets someone manage your catalog without being able to delete products.

  • A select-all checkbox for an entire row or an entire column, so you don't have to click every box one at a time.

Click Save to apply changes. Owner always has full access and can't be edited. Built-in roles can't be deleted, but you can add your own: open the + tab, enter a Role Name and Role Description, and click Create New Role.

The Api Client role controls what your API keys can do; manage the keys themselves from the API Keys tab on the same page. Keep in mind that the API Keys tab displays your client secrets in plain text, so open it only when no one else can see your screen and don't record or share it. See API Documentation to get started — and never paste a real API key, client ID, or secret into a support request or screenshot. Use a placeholder like YOUR_API_KEY instead.


Account security

Two-factor authentication (2FA) is required for every Acenda user who signs in with a username and password, and it can't be turned off. Acenda also supports Google Single Sign-On (SSO), and we highly recommend it over 2FA codes because it's much more convenient: just choose the Google sign-in option on the Acenda login page. If someone loses access to their 2FA device, contact Acenda Support to reset it. If a code just won't accept, see My Acenda 2FA Code Isn't Working. What's Wrong? or How do I reset my Two-Factor Authentication (2FA) for the Acenda Admin Tool?

Keeping your account secure is a shared responsibility: Acenda provides the security tools, and your team is responsible for enforcing good internal practices. A few habits worth building in:

  • Remove a user as soon as they leave your team rather than leaving the account active.

  • Give each person the least access they need to do their job — you can always add more later.

  • Revisit the Authorization tab whenever a role's day-to-day responsibilities change.

  • Set internal rules for strong, unique passwords and change them regularly.


Troubleshooting

  • The + Invite User button isn't showing. You need Owner or Admin access to invite users — ask one of them to send the invite or grant you that role.

  • An invited user says they never got the email. Check their row in the Users table. If it says Pending, click the resend icon; if it says Expired, click the same icon to reactivate the invite. Have them check their spam or junk folder too.

  • I don't see a pencil (Edit) icon on a user's row. The user's invite is probably still Pending or Expired. Reactivate or resend the invite; once they accept, you can edit their roles.

  • I can't find where to deactivate a user. There's no separate deactivated state — remove the user instead to revoke access immediately.

  • I removed someone by mistake. Invite them again with + Invite User; you'll need to re-select their roles.

  • Delete is greyed out for a role. Owner, Admin, Employee, and Api Client are built in and can't be deleted. Create a custom role instead.

  • A teammate's 2FA code won't work. See My Acenda 2FA Code Isn't Working. What's Wrong? If they've lost the device entirely, contact Acenda Support for a reset.


Related articles

Still stuck? Contact Acenda Support and we'll help you sort it out.

Did this answer your question?