Loading

Creating an Account

An administrator can create an account rather than waiting for somebody to register.

Where to find it

Architect Panel → Security:

  • Disabled User Accounts — accounts closed administratively
  • Blocked User Accounts — accounts banned after failed sign-ins
  • Permissions — what a group grants

Architect Panel → Configuration:

  • Site Settings — the welcome e-mail settings

User accounts and groups live in the Admin Panel sidebar under User AdministrationAll Users and User Groups. What a group may reach is granted in the Architect Panel.

What to settle at creation

  1. Which groups — this is the access decision, and the one worth thinking about.
  2. How they will sign in — local password, directory, or something else.
  3. Whether they are told, and what the message says.

Groups are the decision

Everything else is mechanics. Add somebody to the groups their role needs and no more — it is far easier to add a group later than to notice somebody has one they should not.

If you find yourself unsure which groups a role needs, that is worth resolving once rather than deciding case by case, because case-by-case decisions drift generous.

Never set a password and tell them

Send a link that lets them set their own. A password chosen by an administrator and communicated by e-mail sits in a mailbox indefinitely, gets forwarded, and is known to two people.

The welcome message must explain itself

Somebody who did not ask for an account receives an unexpected e-mail saying one has been created for them. With no context, that looks exactly like phishing — and the more security-aware your users, the more likely they are to ignore or report it.

Name the organisation, say why the account exists, and where possible say who asked for it.

Do not create accounts speculatively

Creating accounts for a team "so they have them" produces dormant accounts nobody owns, which is the population most likely to be forgotten at a leaver's departure. Create them when somebody needs one.

Record why

Particularly for local and privileged accounts. An account with no recorded purpose is one nobody will ever feel able to remove.

Check what they can actually see

For a new kind of account — a new role, a new external population — sign in as them once. It takes a minute and it is the only reliable way to know what you have granted.

Worked example

A manager requests an account for a new starter. It is created with the two groups their role needs, a set-your-password link rather than a password, and a welcome message naming the organisation and the requesting manager. For the first account of a new role type, an administrator signs in as them to confirm what is reachable.

Recommendations

  • Decide groups deliberately — that is the access.
  • Send a set-password link, never a password.
  • Say who created it and why in the message.
  • Do not create accounts in advance of need.