Overview
Different team members need different access levels in DEFT. Administrators manage financial data and system configuration, while standard users process day-to-day tasks like entering expenses and submitting payments. This guide explains user roles, how to add and remove users, and how to manage permissions.
User roles in DEFT
Administrator
Administrators have full control of DEFT and can: - Create and configure databases - Manage all users and permissions - Reset user passwords - Configure SEPA payments and ERR submissions - Access all financial records and reports - Change system settings and preferences - Export and import data
Who should be an administrator: Your finance manager, payroll lead, or IT contact who oversees DEFT day-to-day.
Standard user
Standard users can: - Enter employee expenses and benefits - Process payments (if permissions are granted) - View assigned reports - Update their own password - Access features relevant to their role
Standard users cannot: - Add or remove other users - Change system configuration - Access all company financial data - Reset other users’ passwords
Who should be a standard user: Payroll assistants, expense approvers, or team members who process routine tasks.
Before you begin
You’ll need: - Administrator access to DEFT - Access to the Parameters menu - The ability to log in to DEFT
If you don’t have administrator access, contact your system administrator.
Adding a new user
To add a user to DEFT:
- Log in to DEFT as an administrator
- Navigate to Parameters from the main menu
- Select Users
- Click New (or the Add User button)
- Enter the user’s details:
- Username (a unique login name, e.g., john.smith)
- Full name (for reference)
- Email address (optional, for notifications)
- Department or role (optional, for reference)
- Set the user’s role:
- Administrator: Check the Administrator checkbox if the user needs full access
- Standard User: Leave unchecked for limited access
- Set an initial password:
- Click Set Password or Enter/Change/Reset Password
- Enter a temporary password
- The user will be prompted to change this password when they first log in
- Configure permissions (if applicable):
- If your DEFT version supports granular permissions, select which features the user can access
- For example: Can they submit payments? Can they view all reports?
- Click OK or Save
The new user can now log in with their username and temporary password.
[Insert screenshot showing the Users management dialog with fields for username, full name, administrator checkbox, and password reset button]
Changing a user’s role
To change whether a user is an administrator:
- Navigate to Parameters > Users
- Select the user from the dropdown list
- Change their status:
- To make them an administrator: Check the Administrator checkbox
- To remove administrator access: Uncheck the Administrator checkbox
- Click OK to save
The user’s access level takes effect immediately. If they’re currently logged in, they’ll need to log out and log back in to see the changes.
Suspending or removing a user
Temporarily suspend a user
If someone is on leave or temporarily doesn’t need DEFT access, you can suspend their account.
To suspend a user:
- Navigate to Parameters > Users
- Select the user
- Check the Suspend User’s Access box
- Click OK
The user will no longer be able to log in. No data is deleted—you can reactivate them later.
To reactivate a user:
- Navigate to Parameters > Users
- Select the user
- Uncheck the Suspend User’s Access box
- Click OK
The user can now log in again.
Permanently remove a user
If an employee leaves your organisation or no longer needs DEFT, you can remove their account.
To remove a user:
- Navigate to Parameters > Users
- Select the user
- Click Delete
- Confirm the deletion (you’ll be asked to verify)
The user’s account is deleted. Their historical data remains in DEFT (for audit purposes), but they cannot log in.
Important: This action is permanent. You cannot undo a user deletion. If you’re unsure, suspend the user first instead.
Managing passwords
Reset a user’s password
If a user has forgotten their password or needs a new one:
- Navigate to Parameters > Users
- Select the user
- Click Enter/Change/Reset Password
- Enter a new temporary password
- Re-enter to confirm
- Click OK
The user can now log in with the temporary password. Ask them to change it to something only they know when they next log in.
User password expiration
By default, users are required to change their password: - On their first login - After a set period (usually 30–90 days, depending on your configuration)
Your administrator can configure these settings in Settings > Security.
Best practices for user management
Least privilege: Give users only the access they need to do their job. Don’t make everyone an administrator.
Regular reviews: Periodically review your user list and remove accounts for people who no longer need access.
Strong passwords: Encourage users to create passwords that are difficult to guess. Include letters, numbers, and special characters.
Monitor activity: If available, review activity logs in DEFT to see who accessed what and when. Report suspicious activity to your IT team.
Backup administrators: Have at least two administrators in case one is unavailable.
Document responsibilities: Keep a record of what each user does in DEFT (e.g., “John processes expenses, Sarah submits payments”). This helps if someone needs to step in.
Troubleshooting
A user can’t log in
Possible causes: - Their account is suspended - Their password has expired - They’re entering the wrong username or password - Their account was deleted
Resolution: 1. Check that their account isn’t suspended (navigate to Parameters > Users and verify the Suspend User’s Access box isn’t checked) 2. Reset their password (see “Reset a user’s password” above) 3. Ask them to try logging in again with the temporary password 4. If the problem persists, check that their account still exists in the Users list
I need to add a user, but I don’t have administrator access
Possible cause: Only administrators can add or remove users.
Resolution: 1. Contact your DEFT administrator 2. Ask them to add the user and give you confirmation once done 3. If you don’t know who the administrator is, contact Bright Support
I’m locked out and need to add an administrator
Possible cause: All administrators have left or their accounts are suspended.
Resolution: This is a critical situation. You’ll need to contact Bright Support and provide: - Your company name and DEFT database code - A signed letter from a company director requesting administrative access - Details of who should receive the new administrator account
Bright Support can help restore access, but verification is required.
Frequently asked questions
Q: Can I give a user access to only certain parts of DEFT? A: Yes, if your DEFT version supports granular permissions. Administrators can configure which features each user can access. Contact Bright Support if you need help setting up detailed permissions.
Q: What happens to a user’s data if their account is deleted? A: Their account is deleted, but any data they entered (expenses, payments, etc.) remains in DEFT for audit purposes. You can still view and work with that data.
Q: Can a standard user change their own password? A: Yes. Standard users can change their own password through Settings > Change Password (or similar menu option).
Q: How many users can I have in DEFT? A: There’s no fixed limit, but check your licensing agreement. Contact Bright Support if you need to add more users than your license allows.
Q: Can I temporarily give a user administrator access? A: Yes. You can check the Administrator checkbox, and the user will have full access immediately. You can uncheck it later to remove their administrator rights.
Q: What if a user forgets their username? A: Usernames are case-sensitive and are set by your administrator. Check your internal documentation or contact your administrator to confirm the correct username format.
Q: Can users be assigned to different teams or departments? A: You can record a department or team in the user’s notes, but DEFT doesn’t have built-in team-based access control. All users have access to the same database.
Comments
0 comments
Article is closed for comments.