Core administration and shared controls

Entry: administration is under /admin; shared work includes /search, /logs, /notifications and /account/security. Core remains separate from the ten commercial Modules. Administration tasks require the Protected Administrator; ordinary users only see the shared controls their authority permits.

Give a User the right access

  1. In administration, prepare the appropriate Groups and organizational structure. A Group scopes records; Departments, Teams and dated Positions describe responsibility.
  2. Open Users → Create User. Enter the username, display name and temporary password, and select at least one Initial Group. Share credentials through your approved private process.
  3. Open Roles → User access, select the User and assign the appropriate Role and scope. Use Role library to inspect what a Role permits before assigning it.
  4. Have the User check the intended Module and Group. Confirm both their permitted work and the boundaries of that access.

Expected result: membership and a scoped Role work together. Creating a User or adding a Team position does not automatically grant business access. Assign approval positions separately when the workflow requires them.

Import a license and activate a Module

  1. Open Subscription & Module activation and check the Organization and installation context.
  2. Choose Select License File, select the signed file issued for this installation, and choose Verify and import.
  3. Review the purchased Modules and their current status. For an entitled disabled Module, enter the reason and choose Enable Module.
  4. Before disabling an enabled Module, choose Review disable impact and inspect the affected relationships and work before confirming the displayed action.

Expected result: entitlement and local activation remain visible as separate decisions. Importing a license does not grant a User a Role, and purchasing a Module does not silently enable every workflow.

Find records and review evidence

  1. Use global Search for records you are allowed to read; open the result in its owning workspace.
  2. Review Notifications for assigned workflow outcomes and attention items.
  3. If authorized, open Logs. Activity is the focused default; All history exposes the wider retained history. Apply the available Module, stream and text filters.

No search result grants extra permission. Logs retain evidence within their own scope; they are not a way to open another person's Personal Workspace. Built-in Roles and the Protected Administrator have protected lifecycle rules. Do not use an administrator account as a substitute for a correctly scoped business operator.