Manage user access
What this achieves
Section titled “What this achieves”This covers what you do with a user account after it exists — stopping someone signing in, restoring them, chasing an unaccepted invitation, or changing what they can reach. Creating the account in the first place is a separate task.
Required role: Administrator.
Before you start
Section titled “Before you start”If you are adding someone new rather than managing an existing account, see Invite your team instead.
- Go to Settings → Users.
- Find the person, using the search if the list is long.
- Use the action you need on their row.
What the list tells you
Section titled “What the list tells you”| Option | Description |
|---|---|
| User | Who the account belongs to. |
| Role | What they can reach. |
| Status | Whether the account is usable. |
| Last Login | When they last signed in. |
Last Login is the column worth scanning periodically. An admin account that has not been used in months is either a person who has changed job or an account that should not still exist.
The actions
Section titled “The actions”| Option | Description |
|---|---|
| Resend Invite | Sends the invitation again, for someone who never accepted it. |
| Lock | Stops the user signing in. |
| Unlock | Restores their access. |
| Reset Password | Starts a password reset for the account. |
Locking is the right tool for a departure
Section titled “Locking is the right tool for a departure”Locking stops someone signing in without deleting anything. Humavera confirms what it will do before you commit — locking makes the person unable to sign in, and unlocking restores their access.
Use it the moment someone leaves or is suspended. It is immediate, reversible, and it leaves their records intact — which deleting would not.
Example: when an HC Corp UK Ltd employee leaves, locking their account stops access on their last day while their employee record, payslips, and history stay exactly as they are.
Locking a user account is not the same as terminating an employee. The employee record and its lifecycle are managed separately; this controls sign-in only.
Changing someone’s role
Section titled “Changing someone’s role”Editing a user lets you change the role they hold. Access is enforced when data is requested rather than by hiding menu items, so a reduced role takes effect promptly — including on pages the person has bookmarked.
Tell people when you reduce their access. Discovering it as an error message is a worse experience than being told.
Invitations that were never accepted
Section titled “Invitations that were never accepted”Resend Invite is for an account created but never taken up. Before resending repeatedly, check the address is right — an invitation going to a mistyped address will never arrive however many times it is sent.
What happens next
Section titled “What happens next”Access changes apply against the account immediately. Where you locked someone because they are leaving, their employee record still needs handling in the employee directory, and any payroll owed to them is settled through payroll rather than here.
Related
Section titled “Related”© 2025-2026 Humavera Documentation - BPilot Ltd. All Rights Reserved