Core administration and shared controls
Entry: administration is under /admin; shared work includes /search, /logs, /notifications and /account/security. Core remains separate from the ten commercial Modules. Administration tasks require the Protected Administrator; ordinary users only see the shared controls their authority permits.
Give a User the right access
- In administration, prepare the appropriate Groups and organizational structure. A Group scopes records; Departments, Teams and dated Positions describe responsibility.
- Open Users → Create User. Enter the username, display name and temporary password, and select at least one Initial Group. Share credentials through your approved private process.
- Open Roles → User access, select the User and assign the appropriate Role and scope. Use Role library to inspect what a Role permits before assigning it.
- Have the User check the intended Module and Group. Confirm both their permitted work and the boundaries of that access.
Expected result: membership and a scoped Role work together. Creating a User or adding a Team position does not automatically grant business access. Assign approval positions separately when the workflow requires them.
Import a license and activate a Module
- Open Subscription & Module activation and check the Organization and installation context.
- Choose Select License File, select the signed file issued for this installation, and choose Verify and import.
- Review the purchased Modules and their current status. For an entitled disabled Module, enter the reason and choose Enable Module.
- Before disabling an enabled Module, choose Review disable impact and inspect the affected relationships and work before confirming the displayed action.
Expected result: entitlement and local activation remain visible as separate decisions. Importing a license does not grant a User a Role, and purchasing a Module does not silently enable every workflow.
Find records and review evidence
- Use global Search for records you are allowed to read; open the result in its owning workspace.
- Review Notifications for assigned workflow outcomes and attention items.
- If authorized, open Logs. Activity is the focused default; All history exposes the wider retained history. Apply the available Module, stream and text filters.
No search result grants extra permission. Logs retain evidence within their own scope; they are not a way to open another person's Personal Workspace. Built-in Roles and the Protected Administrator have protected lifecycle rules. Do not use an administrator account as a substitute for a correctly scoped business operator.