How to manage users
User admin is where you create users, set roles and decide which buildings they have access to. The role decides what they can do; the building selection decides where.
How to create a user
- Click User administration at the bottom of the sidebar.
- Click Add user.
- Fill in Create user:
- Name
- Phone
- Role
- Org. or All buildings — see the access section
- Click OK.
You get the message User created: Email: {email} Owner: {owner}. If it fails: Couldn't create user {email} for owner {owner}: {error}.
The roles
Role | What it grants |
|---|---|
Read-only | sees data, but the buttons that change anything are hidden |
User | normal use with write access |
Admin | full access within one organization |
Super | across organizations, including module settings |
Service Desk | for the support function |
Technician app | access to the technician app |
Note: Read-only isn't merely a milder version of User — it hides the actions. A read-only user won't find Create buttons, can't assign incidents and can't change setpoints. If somebody reports that a button "doesn't exist", this is the first thing to check.
Admin can't be combined with several organizations. Try it and the message says Admin role cannot be combined with multiple organizations, with the explanation: An admin has full access within a single organization. To grant access across multiple organizations, choose a non-admin role (user or viewer), or select only one organization to keep the admin role.
How to set building access
Three ways:
- One organization — the user gets that organization's buildings.
- A selection of buildings — tick The user has access to a selection of buildings in different organizations and choose the buildings. Without a selection: Select buildings to continue. Changes cannot be saved until at least one building is selected.
- All buildings — see the warning below.
If nothing is selected, the message says Please select an organization or at least one building.
Note: If you choose the owner granting access to everything, Properate warns you: Selecting {value} as the owner will give this user access to all buildings in the system. and Make sure this is intended before proceeding. Read it before confirming — this is the one setting that's hard to notice after the fact.
Passwords and sign-in
Require the user to create a Properate password and send instructions by email. Use this for customers who do not support single sign-on (SSO).
If the organization has SSO, leave this off — sign-in goes via their own identity provider, shown in the Identity provider column.
Use Reset password to send a new one. You get Password reset; if it fails: Couldn't reset password. Try again.
The columns in the list
Name, Email, Phone, Role, Owner (ALL for full access), Buildings, Tech app and Identity provider.
How to change or delete a user
Edit opens Edit user. If saving fails: Couldn't update user {email}. Try again.
Delete removes the user after the confirmation Delete {email}? You get User deleted: {email}.
Frequently asked questions
What's the difference between user roles and module settings?
The role decides what the user may do. Module settings decide which modules the organization has at all. Both have to be in place. See How to change module access.
Why can't a user see a building?
Check the building selection on the user, and then the module access for the building.
Can a user have access to buildings in several organizations?
Yes, with User or Read-only and a building selection. Not with Admin.
Is the user told when I create the account?
With a Properate password, instructions are emailed. With SSO they sign in through their own solution.
Tip!
Give Read-only as the default to anyone who only needs to follow figures, and User only to those who actually need to change something. Write access to setpoints and alarms is access to change how the building runs — a different kind of permission from viewing an energy graph.