Invite New Users
Efficient management of user accounts is essential in a business environment for ensuring security and access control. This document outlines the processes involved in managing user accounts within HirePOS, including inviting new users, setting permissions and roles, linking staff, and utilising single sign-on options.
User Email Address
It is recommended to use email addresses associated with your business domain for user accounts. However, if this is not feasible, personal email addresses may be utilised.
Inviting New Users
To invite new users, follow these steps:
Navigate to Setup > Preferences > Users.
Enter the user's email address in the Invite User box and click Email User Invitation.
Confirm the New User
After the new user registers, you can either confirm the user via the automated email that is sent to your admin email address or you can return to Setup > Preferences > Users, select the user to edit, check the Confirm User checkbox, set roles and permissions, and click Save Changes.
Two-Factor Authentication
When a user signs in with their email address and password, HirePOS may email them a verification code as an additional security measure.
Where possible, users should activate an authenticator app on their mobile phone, such as Microsoft Authenticator or Google Authenticator. This is the recommended option when Microsoft, Google, or Xero SSO is not available.
Why not send verification codes by SMS?
HirePOS does not recommend SMS verification codes because SMS can be vulnerable to risks such as SIM-swap attacks, mobile number porting fraud, mobile account compromise, message interception, phishing, and loss of access to the phone number.
For stronger account protection, users should use Single Sign-On (SSO) or an authenticator app where available.
Email verification codes provide an extra layer of protection and are still significantly safer than password-only sign-in. However, this method is only as secure as the user’s email account, so users should also ensure their email account is well protected.
User Permissions
User permissions provide fine control over user access. To set permissions, follow these steps:
Go to Setup > Preferences > Users.
Select a user to edit and adjust permissions as needed.
User Roles
HirePOS requires individual user logins. The first user created is automatically assigned the Administrator role. To change user roles, follow these steps:
Navigate to Setup > Preferences > Users.
Select a user to edit, then set roles and permissions accordingly.
Linking Staff & Users
Staff and users can be linked by matching email addresses. This linkage streamlines record creation and management, and is essential for enforcing user roles and permissions.
Adding Staff Members
To add staff members, follow these steps:
Go to Setup > Staff.
Click + New Staff and fill in the relevant details.
Staff details should include basic information, address, phone numbers, and additional notes for internal reference.
Transfer a User Login to a different Staff record
To transfer an existing User Login account to a different Staff record in HirePOS please review the following help guide: https://docs.hirepos.com/en/articles/11993537
Recent Logins and User History
Access user history and recent logins via Setup > Preferences > Users. This feature aids in tracking user actions and system interactions.
Single Sign-On (Microsoft or Google)
After you initially invite and confirm a new user, consider enhancing security by using Microsoft or Google accounts for single sign-on and multi-factor authentication instead of relying on a traditional username and password.
