This guide describes the user roles, their permissions and how to create new users. Each user has exactly one role that determines what features they can access.
The system has 6 roles:
| Role | Description |
|---|---|
| Lab Director | Full access. Manage settings, users, approve analyses, QC. |
| Reviewer | Review and approve analyses, access QC data. |
| Analyst | Create/edit analyses and samples, enter measurements. Default role. |
| Worker | Data entry, limited settings access. |
| Receptionist | Sample reception, contact management and invoicing. |
| Client | Client portal access only — view own reports. |
| Feature | Director | Reviewer | Analyst | Worker | Receptionist | Client |
|---|---|---|---|---|---|---|
| System settings | ✔ | — | — | — | — | — |
| User management | ✔ | — | — | — | — | — |
| Approve analyses | ✔ | ✔ | — | — | — | — |
| Create analyses | ✔ | ✔ | ✔ | ✔ | — | — |
| Enter measurements | ✔ | ✔ | ✔ | ✔ | — | — |
| Sample reception | ✔ | ✔ | ✔ | ✔ | ✔ | — |
| Contacts & Invoicing | ✔ | ✔ | ✔ | — | ✔ | — |
| QC & Internal Audits | ✔ | ✔ | ✔ | — | — | — |
| Client portal | — | — | — | — | — | ✔ |
Go to the Users page (Lab Directors only).
Click "+" and fill in:
| Field | Required | Description |
|---|---|---|
| Yes | Unique login email | |
| First Name | Yes | 2-25 characters |
| Last Name | Yes | 2-50 characters |
| Phone | No | Contact phone |
| Job Title | No | Position |
| Hire Date | No | For training records |
| Password | Yes | 6-16 characters |
| Role | Yes | Select from dropdown |
| Active | Auto | Active by default |
The first user (Lab Director) is created during initial setup.
You cannot delete a user — set the Active field to inactive instead. The user will no longer be able to log in, but their action history is preserved.
Can I change a user's role?
Yes. Open the user for editing and change the role. The change takes effect at their next login.
What happens when a user gets locked out?
After multiple failed login attempts, the account is temporarily locked. A Lab Director can unlock it.
How do I enable MFA for everyone?
From Settings → Security, enable "Mandatory MFA". All users will be required to set up an authenticator app.