---
title: "User Management"
canonical: "https://red-ant-documentation.refined.site/space/RET/79593517/User%20Management"
format: markdown
---
# My Team

The **My Team** area allows authorised users to manage the users who have access to the platform, including creating new users, editing existing users, and managing account access.

My Team can be accessed from the **global side menu**.

Access to My Team is restricted to users with one of the following roles:

- Store Manager
- Area Manager
- Admin
- Red Ant Admin
- Super Admin

> 📝 Users can only view and manage users within the same store(s). Admin, Red Ant Admin, and Super Admin users are additionally only visible to others in these roles.

---

## Viewing Users

Selecting **My Team** displays a list of users that you have permission to view and manage.

The listing provides an overview of user information and supports searching, filtering and customisable columns to help you quickly locate users.

![Screenshot 2026-06-25 at 13.12.28.png](media://84770292-ea82-406f-8a7e-7e1387fb433f)

### Default Columns

The following columns are displayed by default:

| Column | Description |
| --- | --- |
| Name | The user's full name. This column is mandatory and cannot be removed. |
| Stores | The store(s) the user is associated with. |
| Role | The user's assigned role. |
| Login Method | Indicates whether the user logs in via RetailOS credentials or [Single Sign-On](https://redantdigital.atlassian.net/wiki/spaces/RET/pages/362250241) (SSO). |
| Status | Displays whether the user is Active, Locked or Deactivated. |

### Optional Columns

Additional columns can be enabled as required:

- Email
- Username
- Departments
- Last Login Date

![Screenshot 2026-06-25 at 13.13.36.png](media://40031506-3938-483f-b55b-0369338340ec)

### Stores & Departments Display

Users associated with multiple stores or departments are displayed using a summarised format.

For example:

- `Store A, Store B +3`
- `Shop Floor, Stock Room +2`

The `+X` value indicates how many additional stores or departments are associated with the user.

Area Managers may be associated with multiple stores and therefore commonly use this display format.

All roles may be associated with one or more departments.

Admin, Red Ant Admin and Super Admin users are displayed as:

- **All Stores**
- **All Departments**

---

## Searching Users

The user search supports searching across the following fields:

- Name
- Email Address
- Username

> ℹ️ A minimum of **3 characters** is required before the search is triggered.


## Filtering Users

The following filters are available:

| Filter | Type |
| --- | --- |
| Stores | Multi-select |
| Roles | Multi-select |
| Login Method | Multi-select |
| Include Deactivated | Toggle (default: Off) |
| Include Locked | Toggle (default: On) |

![Screenshot 2026-06-25 at 13.14.20.png](media://681211d0-0b76-4288-8811-b2cf20adc4a6)

### Store Filtering

Users may only filter by stores they are associated with.

For example:

- A Store Manager can only filter by their store.
- An Area Manager can filter by the stores they manage.
- Admin, Red Ant Admin and Super Admin users can filter across all stores.

---

## User Permissions & Visibility

User visibility and management capabilities are determined by role hierarchy.

### Viewing Users

Users can only view other users associated with the same store(s).

Admin, Red Ant Admin and Super Admin users are only visible to:

- Admin users
- Red Ant Admin users
- Super Admin users

### Editing Users

Users may only edit users whose role is **less than or equal to** their own role.

### Creating Users

Users may create new users with a role equal to or lower than their own.

Users can only assign stores that they themselves are associated with.

---

## Creating a User

Selecting **Create User** opens the user creation form.

### User Details

| Field | Requirement |
| --- | --- |
| First Name | Mandatory |
| Last Name | Mandatory |
| Email | Mandatory |
| Username | Mandatory |
| Role | Mandatory |
| Store(s) | Mandatory |
| Departments | Mandatory |
| Password | Mandatory |
| Confirm Password | Mandatory |

### Role & Store Assignment

Store assignment varies by role:

- Temporary Workers, Sales Assistants and Store Managers can only be assigned to a single store.
- Area Managers can be assigned to multiple stores.
- Admin, Red Ant Admin and Super Admin users are automatically associated with **All Stores**.

### Department Assignment

Departments are mandatory and support multi-selection for all users.

Admin, Red Ant Admin and Super Admin users are automatically associated with **All Departments**.

### Password Requirements

Passwords must:

- Contain at least one uppercase letter
- Contain at least one numeric character
- Be at least 10 characters long
- Be no more than 30 characters long

The **Confirm Password** field must exactly match the password entered.

### Unsaved Changes

If any information has been entered into the form and the user attempts to navigate away using the back button, a confirmation prompt is displayed.

Users can choose to:

- **Discard Changes**
- **Keep Editing**

---

## Editing Users

Selecting a user from the listing opens their user details. Users with sufficient permissions can update user information and manage account access.

**Editing Your Own Account**

When viewing your own account via My Team, the Role & Access section is not available. Your role, store and department associations cannot be changed from your own profile. To update these, another user with a higher role and appropriate edit permissions will need to make the change on your behalf.

**Editing Restrictions by Authentication Type**

The fields available when editing a user depend on how that user authenticates with the platform.

For **RetailOS (native authentication) users**, all editable fields are available subject to the viewer's permissions.

For **SSO users**, editing is limited to first and last name only. Username and email address are managed by the retailer's identity provider and cannot be changed within the platform. SSO users can still be deactivated by a manager with appropriate permissions.

> ℹ️ Role, store and department associations for SSO users are typically managed by the retailer's identity provider. However, if the retailer's SSO is not configured to set these values, RetailOS can be configured to allow them to be managed within the platform. Contact your system administrator for details.

![Screenshot 2026-08-10 at 13.09.50.png](media://74dc8275-c1bd-4b27-b138-a00684eb6518)

---

## Account Statuses

Users can have one of three account statuses:

- Active
- Locked
- Deactivated

### Active

The user can access the platform normally.

---

## Locked Accounts

Locked accounts prevent users from logging into the platform.

An account may become locked when:

- The user enters an incorrect password five times.
- The user has not logged in for three months.

When viewing a locked account, the following banner is displayed:

> Account locked: The user account is currently locked and the user cannot sign in

![Screenshot 2026-08-10 at 13.11.11.png](media://127ce239-6667-4acf-aaeb-a9b52b9db792)

### Unlocking an Account

There are several ways to unlock a locked account, depending on the user's authentication method and who is performing the action.

**Self-service (native authentication users only)**

Users authenticating via RetailOS can unlock their own account using the Forgot Password flow available from the login screen. The user must:

1. Enter their username.
2. Submit the request.
3. Open the password reset email sent to the email address associated with the username.
4. Set a new password.

> 📝 This option is not available to SSO users, as their passwords are managed by the retailer's identity provider.

**Manager unlock**

A manager with appropriate permissions can unlock any locked account, including SSO accounts, directly from the User Details screen using the **Unlock Account** action. This unlocks the account without changing the user's password, making it the appropriate recovery method for SSO users and a convenient alternative for native authentication users.

Unlocking an account sets the account to active and updates the user's last login date to the current date and time.

> ℹ️ For native authentication users, a manager with appropriate permissions can also set a new password for the user via the **Security** section of the user profile, which will also unlock the account.

## Deactivated Accounts

Deactivated accounts are manually disabled to revoke access to the platform.

Only users with sufficient permissions may deactivate or reactivate another user.

Users may only deactivate or reactivate users with a role lower than their own.

When viewing a deactivated account, the following banner is displayed:

> **Account deactivated:** This user cannot log in until reactivated.

![Screenshot 2026-08-10 at 13.12.00.png](media://de13bf54-2188-43e3-9124-9239529a2dd4)

### Reactivating an Account

Selecting **Reactivate Account** displays a confirmation prompt.

Once confirmed:

- The account is reactivated.
- The user can log in again immediately.

---

## My Account

The **My Account** area provides quick access to the logged-in user's own profile and can be accessed in one of two ways:

- Selecting **My Account** from the global side menu.
- Selecting the profile icon in the dashboard header bar.

Users can update their personal information, including changing their password.

> 📝 SSO users can update their first and last name only. Username, email address, and password are managed by the retailer's identity provider and cannot be changed within the platform.

Role, store and department assignments can only be updated by a user with a higher role and appropriate edit permissions. If you need these changed, contact another user who meets these criteria.

---

## Permissions Matrix

A permissions matrix can be defined for each role as part of the system set-up and rollout. Role assignment can be managed via the ‘My Team’ section of the app, or it can be fixed by mapping a ‘role’ field from the retailer’s SSO provider.

The table below lists the RetailOS default role permissions.

|  |
| --- |
| **RetailOS Roles/Permissions** |
|  | **Super Admin** | **Red Ant Admin** | **Admin** | **Area Manager** | **Store Manager** | **Sales Assistant** | **Temporary Worker** |
| **Rank** | 0 | 0 | 1 | 3 | 4 | 5 | 6 |
|  |  |  |  |  |  |  |  |
| **APP TILES** |  |  |  |  |  |  |  |
| Admin Hub | Y | Y | Y | N | N | N | N |
| Territory Management | Y | Y | N | N | N | N | N |
| Region Management | Y | Y | N | N | N | N | N |
| Store Management | Y | Y | Y | N | N | N | N |
| Order Management | Y | Y | Y | Y | Y | Y | N |
| User Management - Full functionality | Y | Y | Y | Y - Store/s Only | Y - Store/s Only | N | N |
| User Management - View only | n/a | n/a | n/a | n/a | n/a | N | N |
| My Account | Y | Y | Y | Y | Y | Y | Y |
| Notifications | Y | Y | Y | Y | Y | Y | Y |
| Retail Analytics | Y | Y | Y | Y | Y | Y | N |
| Customers | Y | Y | Y | Y | Y | Y | N |
| Products | Y | Y | Y | Y | Y | Y | Y |
| Product Waitlist | Y | Y | Y | Y | Y | Y | Y |
| Lookbooks | Y | Y | Y | Y | Y | Y | Y |
| Runner | Y | Y | Y | Y | Y | Y | Y |
| Messaging | Y | Y | Y | Y | Y | Y | N |
| Consultations | Y | Y | Y | Y | Y | Y | Y |
| App Feedback | Y | Y | Y | Y | Y | Y | Y |
| Resources | Y | Y | Y | Y | Y | Y | N |
| Accessory Management | Y | Y | Y | Y | Y | N | N |
| Reporting | Y | Y | Y | N | N | N | N |
| Tasks | Y | Y | Y | Y | Y | Y | Y |
|  |  |  |  |  |  |  |  |
| **SPECIFIC FUNCTIONS** |  |  |  |  |  |  |  |
| Order Management - Refund | Y | Y | Y | Y | Y | N | N |
| Order Management - Exchange | Y | Y | Y | Y | Y | N | N |
| Order Management - Reassign Order | Y | Y | Y | Y | Y | N | N |
| User Management -Can be assigned to multiple stores | Y | Y | Y | Y | Y | N | N |
| User Management - Update another user's role | Y (Ranks 1-6) | Y (Rank 1-6) | Y (Rank 1-6) | Y (Rank 4-6) | Y (Rank 5-6) | N | N |
| Customers - Anonymise customer record | Y | Y | Y | N | N | N | N |
| Accessory Management - Add Funds to Virtual Safe | Y | Y | Y | Y | Y | N | N |
| Accessory Management - Submit Banking Record | Y | Y | Y | Y | Y | Y | N |
| Accessory Management - Sessions / Manage Floats / Reconciliation | Y | Y | Y | Y | Y | Y | N |

## Learn More

- [Authentication](https://redantdigital.atlassian.net/wiki/spaces/RET/pages/33488897)
  - [SSO (single-sign-on)](https://redantdigital.atlassian.net/wiki/spaces/RET/pages/362250241)