Aksha
Aksha
Business Software

Documentation

Users

The Users function manages AkshaERP login identities, business access, account security, profile preferences and server-recognized login sessions.

System administratorsImplementation teamsAuthorized user administrators
Last updated: 14-08-2026

What the Users function is for

Use Users to create and securely manage the people who can sign in to AkshaERP.

A User combines login identity with roles, organizations, operating locations, profile preferences, account-security state and login sessions. This makes Users a central part of AkshaERP security and multi-entity administration.

  • Create new AkshaERP login users.
  • Find, sort and review existing users.
  • Assign business roles.
  • Assign one or more organizations.
  • Assign branches, warehouses and stores.
  • Maintain profile preferences such as timezone and application language.
  • Upload a managed profile picture.
  • Activate or deactivate accounts.
  • Reset passwords and unlock failed-login locks.
  • Review and revoke active sessions.
  • Review Activity and Account History.

Find and open a user

Open Access and choose Users. The list gives administrators a security-oriented view of each account.

Use search, sorting and paging to find the required user. Open a user by clicking the row or choosing Open from the row action menu.

Users list information

InformationWhat it tells you
UsernameThe login identity of the user.
NameThe person associated with the account.
EmailThe user’s primary email address.
StatusWhether the account is Active, Inactive or Locked.
Last LoginThe most recent successful login.
Last ActivityThe most recent recorded authenticated activity.
SessionsThe number of active login sessions.
RolesThe number of active roles assigned to the user.

Create a user

Choose Create User from the Users list. Enter the login identity and profile information, then assign the business access required for the person’s work.

A strong initial password is required. After the account is created, the user must change that administrator-set password at first login before normal ERP access is allowed.

Main user information

FieldWhat to enter
UsernameA unique login name for the user.
EmailThe user’s primary email address.
Aksha MailThe local Aksha Mail name used by your organization.
Initial PasswordA strong temporary password required when creating a new user.
Confirm Initial PasswordRepeat the initial password exactly.
First NameThe user’s first name.
Last NameThe user’s last name when applicable.
Phone NumberA phone number containing between 7 and 15 digits.
Date of BirthEnter/display in DD-MM-YYYY format when maintained.
GenderChoose the configured Gender value when applicable.
TimezoneChoose the user’s IANA working timezone, such as Asia/Kolkata.
LanguageChoose the application language preference.
Profile PictureUpload a managed PNG, JPG/JPEG or WEBP image after the user is created.
Address / City / Country / Postal CodeOptional profile/contact information.

Aksha Mail

Enter only the local name before the Aksha Mail suffix. AkshaERP adds @akshamail automatically in the current Users screen.

For example, entering accounts creates accounts@akshamail.

Profile and preferences

Profile & Preferences keeps the identity-related personal details needed by the application. Employment and personnel records should be maintained in HR Employee when an employee record is linked.

Profile preferences

PreferenceBehavior
Date of BirthAlways shown as DD-MM-YYYY in the Users screen.
GenderSelected from configured Gender values.
TimezoneSelected from configured IANA timezones instead of free text.
LanguageSelected from configured application-language values instead of free text.
Profile PictureUploaded and stored as a managed AkshaERP asset instead of entering a URL.

Profile picture

For an existing user, choose Upload beside Profile Picture. AkshaERP accepts PNG, JPG/JPEG and WEBP input images with a default maximum upload size of 5 MB.

AkshaERP processes the image and stores it as a managed ERP asset. Use Replace to change the picture or Remove to clear it.

Assign access

Administrators use the Access tab to decide where the user can work and what responsibilities the user can perform.

  • Roles — assign only the business responsibilities the person needs.
  • Organizations — define the business entities the user can work with.
  • Branches — assign permitted branches within the user’s organizations.
  • Warehouses — assign permitted warehouses within the user’s organizations.
  • Stores — assign permitted stores within the user’s organizations.

Organizations and default context

A user can be assigned to more than one organization, with one organization maintained as the default working context.

Branches, warehouses and stores are assigned within organizations available to the user.

Account security

The Security tab gives administrators a consolidated view of account state and recent security information.

Security information

InformationPurpose
Account StatusShows Active, Inactive or Locked state.
Last LoginMost recent successful login.
Last ActivityMost recent recorded authenticated activity.
Active SessionsCurrent server-recognized sessions.
Failed Login AttemptsRecent consecutive failed login attempts.
Last Failed LoginTime of the most recent failed login.
Locked UntilTemporary lock expiry when the account is locked.
Password ChangedMost recent recorded password-change time.

Activate and deactivate

Use Deactivate when a person should no longer be able to sign in. Deactivation revokes active sessions and blocks new login while retaining the user identity for traceability.

Use Activate to re-enable an inactive account. Old revoked sessions do not become active again.

Password reset

Administrators can reset another user’s password from the Security tab.

The reset can require the user to change that administrator-set password at the next login. Existing sessions are revoked as part of the password reset.

Failed login and account lockout

Repeated incorrect passwords are tracked. When the configured failed-login threshold is reached, the account is temporarily locked.

The Security tab shows failed-attempt and lock information. An administrator can use Unlock Account or Reset Failed Attempts when the action is available.

Sessions

The Sessions tab shows server-recognized login sessions instead of relying only on browser-stored tokens.

Session information helps administrators understand when and where a user is signed in and revoke access when required.

  • Review client type, login time and last-seen time.
  • Review expiry and session status.
  • Review IP address and browser/device user agent when available.
  • Revoke an individual session when permitted.
  • Use Sign Out Everywhere to revoke all active sessions for the user.

Activity and Account History

Activity shows meaningful recorded activity performed by the user.

Account History focuses on actions affecting the user identity and security state, helping administrators investigate access or support questions.

  • User creation and updates.
  • Role or organization/location access changes.
  • Login failures and account locks.
  • Activation and deactivation.
  • Password resets.
  • Session revocation.

Save, Apply and Close

User page actions

ActionWhat happens
SaveValidates and saves the user, then returns to the Users list.
ApplyValidates and saves the user but keeps the record open so you can continue working.
CloseReturns to the Users list without performing a new save.

If the screen stops you from saving

The Users screen validates important identity and profile information before saving. Correct the displayed message and try again.

  • Username is required and must be unique.
  • Email must be valid and unique.
  • Aksha Mail must be unique.
  • First Name is required.
  • Phone Number must contain between 7 and 15 digits.
  • Date of Birth must use DD-MM-YYYY when entered.
  • A new user requires a strong initial password.
  • Password confirmation must match.
  • Timezone and Language must come from configured selections.

Good administration practices

  • Give each person their own User account.
  • Use least-privilege role and location access.
  • Deactivate leavers instead of deleting identities with history.
  • Review Sessions when unusual access is suspected.
  • Review Account History after important account-security changes.
  • Keep profile timezone aligned with the user’s normal working location.

Related pages

Frequently asked questions

Can a user be assigned to multiple organizations in AkshaERP?

Yes. Multiple organizations can be assigned, with one organization maintained as the default working context.

Can one user have multiple roles?

Yes. Assign only the roles needed for the person’s current responsibilities.

What happens when a user is deactivated?

New login is blocked and active sessions are revoked. The user identity remains available for traceability and account history.

Why must a new user change the initial password?

The initial password is administrator-created. Requiring a first-login change lets the person establish their own long-term password before normal ERP use.

Can an administrator deactivate their own account?

No. AkshaERP blocks self-deactivation, and the built-in admin identity is also protected.

Can I see where a user is logged in?

Yes. The Sessions tab shows server-recognized session information and allows authorized session revocation.

Can I upload a profile picture?

Yes. For an existing user, upload PNG, JPG/JPEG or WEBP. AkshaERP processes and stores the image as a managed ERP asset.

How do I change an existing user’s password?

Use Reset Password from the Security tab. Password is no longer treated as an ordinary profile-edit field.

Why is Deactivate not shown for my admin user?

AkshaERP intentionally hides and blocks self-deactivation to prevent an administrator from locking out their own active account.

Continue reading