Documentation
Getting Started
Data Grid
Modeling
Business Rules
Approvals
Administration
Integration & API
Installation
Migrating from MDS
Architecture

User Management

Every person who signs in to Primentra needs a user account. Accounts are created and managed in Settings → Access Management → Users.

The Users tab in Access Management, showing accounts with their roles, status and last password change
The Users tab in Access Management, showing accounts with their roles, status and last password change(click to enlarge)

The user list

The list is a sortable table. Click any column header to cycle through ascending, descending, and unsorted.

ColumnShows
UserDisplay name, email address, and badges
RolesEvery role the user belongs to
StatusActive or Inactive
Password changedWhen the user last set a password, or Never

Three badges can appear next to a name:

  • Admin (crown) — the user belongs to a role with the Administrator flag
  • System — Primentra's own account, see below
  • API — an API service account, see below

Click a row to open the account. The action buttons on the right send the welcome email, edit the account, or delete it.

Create a user

  1. Click New user.
  2. Enter the Email. This is the login name and must be unique.
  3. Enter the Display Name. It appears in the settings menu and the audit log.
  4. Enter a Password, or click Generate for a random 16-character password. Use the eye icon to check it.
  5. Leave User must change password at next login ticked if the user must choose their own password.
  6. Leave Send welcome email ticked to mail the account details.
  7. Set Status to Active.
  8. Tick the roles the user belongs to.
  9. Click Create user.
A user with no roles can sign in but sees no data. Administrator access comes from a role with the Administrator flag — see Administrator & Moderator.

The welcome email

The welcome email is branded HTML. What it contains depends on the Must change password setting.

Must change passwordThe email contains
OnA one-click sign-in link, valid 72 hours, single use. No password is included.
OffThe login name, the password, and a sign-in button.

Both versions list the user's role memberships.

To send it again later, click the mail icon on the user's row. A resent email never contains a password, because passwords are not stored in readable form.

The Application URL must be set under Settings → General Settings first. Without it, Primentra refuses to send the mail, because the sign-in link would have nowhere to point.

Sending is non-blocking. If the mail server is unavailable, the account is still created and a toast reports the failure.

Edit a user

Open the account and change any field. Leave the password box empty to keep the current password. Role changes apply as soon as you save.

The Password last changed date is shown at the bottom of the form and cannot be edited.

Deactivate or delete

Clear the Active checkbox to block sign-in without removing anything. This is also how you unlock an account after a lockout — see Account Security.

Deleting is a soft delete:

  • The account is marked deleted and set to inactive.
  • Role memberships, favorites, hidden entities, and personal settings are removed permanently.
  • Audit log entries stay, so the history of what the user did remains readable.
  • The email address becomes free again, because the uniqueness rule only covers accounts that are not deleted.

Primentra refuses any change that would leave the installation without an active administrator. Deleting the last administrator returns an error instead.

Accounts Primentra creates itself

Two account types appear in the list that nobody created by hand. Both carry a blue badge.

BadgeAccountWhy it exists
Systemsystem@mds-importCreated during database setup. Primentra records its own work under this name: scheduled staging runs and MDS migration imports. It cannot be deleted.
APIapi-…@api.internalCreated with each API user. Calls made with that key are traceable in the audit log. Manage it under Administration → API Users.

Neither account has a password, so neither can sign in. The email addresses are internal identifiers — no mail is ever sent to them.

Ready to get started?

Start managing your master data with Primentra today.

View Pricing
User Management | Users, Roles & Security | Docs | Primentra