Documentation
Users
The Users function manages AkshaERP login identities, business access, account security, profile preferences and server-recognized login sessions.
What the Users function is for
Use Users to create and securely manage the people who can sign in to AkshaERP.
A User combines login identity with roles, organizations, operating locations, profile preferences, account-security state and login sessions. This makes Users a central part of AkshaERP security and multi-entity administration.
- Create new AkshaERP login users.
- Find, sort and review existing users.
- Assign business roles.
- Assign one or more organizations.
- Assign branches, warehouses and stores.
- Maintain profile preferences such as timezone and application language.
- Upload a managed profile picture.
- Activate or deactivate accounts.
- Reset passwords and unlock failed-login locks.
- Review and revoke active sessions.
- Review Activity and Account History.
Find and open a user
Open Access and choose Users. The list gives administrators a security-oriented view of each account.
Use search, sorting and paging to find the required user. Open a user by clicking the row or choosing Open from the row action menu.
Users list information
| Information | What it tells you |
|---|---|
| Username | The login identity of the user. |
| Name | The person associated with the account. |
| The user’s primary email address. | |
| Status | Whether the account is Active, Inactive or Locked. |
| Last Login | The most recent successful login. |
| Last Activity | The most recent recorded authenticated activity. |
| Sessions | The number of active login sessions. |
| Roles | The number of active roles assigned to the user. |
Create a user
Choose Create User from the Users list. Enter the login identity and profile information, then assign the business access required for the person’s work.
A strong initial password is required. After the account is created, the user must change that administrator-set password at first login before normal ERP access is allowed.
Main user information
| Field | What to enter |
|---|---|
| Username | A unique login name for the user. |
| The user’s primary email address. | |
| Aksha Mail | The local Aksha Mail name used by your organization. |
| Initial Password | A strong temporary password required when creating a new user. |
| Confirm Initial Password | Repeat the initial password exactly. |
| First Name | The user’s first name. |
| Last Name | The user’s last name when applicable. |
| Phone Number | A phone number containing between 7 and 15 digits. |
| Date of Birth | Enter/display in DD-MM-YYYY format when maintained. |
| Gender | Choose the configured Gender value when applicable. |
| Timezone | Choose the user’s IANA working timezone, such as Asia/Kolkata. |
| Language | Choose the application language preference. |
| Profile Picture | Upload a managed PNG, JPG/JPEG or WEBP image after the user is created. |
| Address / City / Country / Postal Code | Optional profile/contact information. |
Aksha Mail
Enter only the local name before the Aksha Mail suffix. AkshaERP adds @akshamail automatically in the current Users screen.
For example, entering accounts creates accounts@akshamail.
Profile and preferences
Profile & Preferences keeps the identity-related personal details needed by the application. Employment and personnel records should be maintained in HR Employee when an employee record is linked.
Profile preferences
| Preference | Behavior |
|---|---|
| Date of Birth | Always shown as DD-MM-YYYY in the Users screen. |
| Gender | Selected from configured Gender values. |
| Timezone | Selected from configured IANA timezones instead of free text. |
| Language | Selected from configured application-language values instead of free text. |
| Profile Picture | Uploaded and stored as a managed AkshaERP asset instead of entering a URL. |
Profile picture
For an existing user, choose Upload beside Profile Picture. AkshaERP accepts PNG, JPG/JPEG and WEBP input images with a default maximum upload size of 5 MB.
AkshaERP processes the image and stores it as a managed ERP asset. Use Replace to change the picture or Remove to clear it.
Assign access
Administrators use the Access tab to decide where the user can work and what responsibilities the user can perform.
- Roles — assign only the business responsibilities the person needs.
- Organizations — define the business entities the user can work with.
- Branches — assign permitted branches within the user’s organizations.
- Warehouses — assign permitted warehouses within the user’s organizations.
- Stores — assign permitted stores within the user’s organizations.
Organizations and default context
A user can be assigned to more than one organization, with one organization maintained as the default working context.
Branches, warehouses and stores are assigned within organizations available to the user.
Account security
The Security tab gives administrators a consolidated view of account state and recent security information.
Security information
| Information | Purpose |
|---|---|
| Account Status | Shows Active, Inactive or Locked state. |
| Last Login | Most recent successful login. |
| Last Activity | Most recent recorded authenticated activity. |
| Active Sessions | Current server-recognized sessions. |
| Failed Login Attempts | Recent consecutive failed login attempts. |
| Last Failed Login | Time of the most recent failed login. |
| Locked Until | Temporary lock expiry when the account is locked. |
| Password Changed | Most recent recorded password-change time. |
Activate and deactivate
Use Deactivate when a person should no longer be able to sign in. Deactivation revokes active sessions and blocks new login while retaining the user identity for traceability.
Use Activate to re-enable an inactive account. Old revoked sessions do not become active again.
Password reset
Administrators can reset another user’s password from the Security tab.
The reset can require the user to change that administrator-set password at the next login. Existing sessions are revoked as part of the password reset.
Failed login and account lockout
Repeated incorrect passwords are tracked. When the configured failed-login threshold is reached, the account is temporarily locked.
The Security tab shows failed-attempt and lock information. An administrator can use Unlock Account or Reset Failed Attempts when the action is available.
Sessions
The Sessions tab shows server-recognized login sessions instead of relying only on browser-stored tokens.
Session information helps administrators understand when and where a user is signed in and revoke access when required.
- Review client type, login time and last-seen time.
- Review expiry and session status.
- Review IP address and browser/device user agent when available.
- Revoke an individual session when permitted.
- Use Sign Out Everywhere to revoke all active sessions for the user.
Activity and Account History
Activity shows meaningful recorded activity performed by the user.
Account History focuses on actions affecting the user identity and security state, helping administrators investigate access or support questions.
- User creation and updates.
- Role or organization/location access changes.
- Login failures and account locks.
- Activation and deactivation.
- Password resets.
- Session revocation.
Save, Apply and Close
User page actions
| Action | What happens |
|---|---|
| Save | Validates and saves the user, then returns to the Users list. |
| Apply | Validates and saves the user but keeps the record open so you can continue working. |
| Close | Returns to the Users list without performing a new save. |
If the screen stops you from saving
The Users screen validates important identity and profile information before saving. Correct the displayed message and try again.
- Username is required and must be unique.
- Email must be valid and unique.
- Aksha Mail must be unique.
- First Name is required.
- Phone Number must contain between 7 and 15 digits.
- Date of Birth must use DD-MM-YYYY when entered.
- A new user requires a strong initial password.
- Password confirmation must match.
- Timezone and Language must come from configured selections.
Recommended setup sequence
For a new business user, use a simple sequence that keeps identity and access easy to review.
- Create the login identity and profile information.
- Use Save or Apply to create the User ID.
- Upload a profile picture if required.
- Assign the required organization or organizations.
- Choose the correct default organization.
- Assign required branches, warehouses and stores.
- Assign only the roles the person needs.
- Review the Security tab.
- Have the user sign in and change the initial password.
- Verify the user can see the intended functions and data.
Good administration practices
- Give each person their own User account.
- Use least-privilege role and location access.
- Deactivate leavers instead of deleting identities with history.
- Review Sessions when unusual access is suspected.
- Review Account History after important account-security changes.
- Keep profile timezone aligned with the user’s normal working location.
Related pages
Frequently asked questions
Can a user be assigned to multiple organizations in AkshaERP?
Yes. Multiple organizations can be assigned, with one organization maintained as the default working context.
Can one user have multiple roles?
Yes. Assign only the roles needed for the person’s current responsibilities.
What happens when a user is deactivated?
New login is blocked and active sessions are revoked. The user identity remains available for traceability and account history.
Why must a new user change the initial password?
The initial password is administrator-created. Requiring a first-login change lets the person establish their own long-term password before normal ERP use.
Can an administrator deactivate their own account?
No. AkshaERP blocks self-deactivation, and the built-in admin identity is also protected.
Can I see where a user is logged in?
Yes. The Sessions tab shows server-recognized session information and allows authorized session revocation.
Can I upload a profile picture?
Yes. For an existing user, upload PNG, JPG/JPEG or WEBP. AkshaERP processes and stores the image as a managed ERP asset.
How do I change an existing user’s password?
Use Reset Password from the Security tab. Password is no longer treated as an ordinary profile-edit field.
Why is Deactivate not shown for my admin user?
AkshaERP intentionally hides and blocks self-deactivation to prevent an administrator from locking out their own active account.