A user account is the record that represents one person (or one built-in system identity) in your xMatix organization: it holds their sign-in name, contact details, audience, language and time zone, and it is the anchor for every profile, role, team, license seat and company grant that decides what they can do. Every record in xMatix also points back to user accounts — the Owner, Created By and Modified By of any record are user accounts.
Accounts are created when you invite a user and removed when you offboard them. This page covers everything in between: finding and reading an account, editing it, what each field does, and how the account's settings affect the person's day-to-day experience.
Overview
You manage accounts under Setup → Access Control → Users. The page lists every account in your organization in an All Users table, with a recently-opened strip in the page header and New as the header action. Selecting a name opens the account's detail page, where the header shows its key facts and the tabs below hold its access assignments.
An account has three layers:
- Identity — Username, Email, Phone, the names, and the Audience (Internal or External). These decide how the person signs in and which security profiles can be assigned to them.
- Preferences — Language, Locale and Time Zone. These change how xMatix displays text, numbers and dates for this person.
- Access — profiles, roles, teams, license seats and company access. These are separate records attached to the account, edited on the detail page tabs and on the Company Access tab in Org Settings.
How xMatix handles it
- Sign-in is provisioned separately. Saving an account writes it immediately, but the person's sign-in identity is created in the background. The Sign-in column tracks this: Pending for the first five minutes after creation, Ready once the identity exists, Not provisioned if it does not exist after that, and System for built-in identities. Only accounts with Active switched on, and with a username or e-mail, are provisioned.
- Any save retries provisioning. Saving an active account whose sign-in is not yet ready sends it for provisioning again. This is the supported way to retry after fixing a field.
- Defaults fill gaps. A new account is active and Internal unless you say otherwise. A blank Display Name is composed from First Name and Last Name. The account's Name is taken from the username, falling back to the e-mail and then the display name.
- Addresses are tidied. Leading and trailing spaces are removed from the username and e-mail when you save.
- Three accounts are not people. System Process, System Agent and System Anonymous run scheduled jobs and automation, autonomous agent runs, and anonymous storefront traffic. They never sign in, show System in the Sign-in column, and have no Edit or Delete action. Their detail page shows a Built-in system identity notice. Leave them alone — removing one breaks the work it runs.
Prerequisites
- To open Users, create, edit or delete accounts: the user-administration capability (
setup.security.users.manage) together with the security-administration capability (setup.security.manage), which shows the Access Control menu group. - To see the License Allocations and Access Diagnostics tabs on someone else's account: the licensing capability (
setup.licensing.admin). - To edit your own preferences: no capability — every signed-in user can.
Procedure
Step 1 — Find an account
Open Setup → Access Control → Users. The All Users table shows Display Name, Name, Email, Phone, Active and Sign-in by default, sorted by name. Use the search box in the table header to match on name, display name, e-mail or phone; use the column filters to narrow by Active or Sign-in — filtering Sign-in is the quickest way to find accounts that cannot log in. Refresh reloads the list.
Step 2 — Open the account
Select the person's display name. The detail page header shows Name, Display Name, Email, Audience, Status (Active or Inactive) and Sign-in. If the sign-in identity does not exist, a warning reads This user has no sign-in identity yet — see Common problems.
The tabs below the header are:
- Role Assignments, Profile Assignments and Team Assignments — the person's place in the role hierarchy, the security profiles that grant their access, and their teams. See Security profiles and Roles, teams and business units.
- License Allocations — product, feature and package seats, each with an add control and a Revoke seat action. See Licensing.
- Access Diagnostics — a computed summary of everything the person effectively has: counts and lists of Profiles, Roles, Teams, Business Units, Product Licenses and Capabilities, with Product Licenses, Feature Licenses and Capabilities each split into Allocated to user and Required by profile. An Outlet Transfer card previews which channel partners, HQs and beats the person can transfer outlets between on the field app, and explains why when the answer is none.
Step 3 — Edit the account
On the detail page select Edit in the page header, or select the edit icon in the Actions column of the Users list. The Edit User dialog has the same fields as New User (see Fields). Change what you need and select Save. A confirmation reads User updated, and the detail page reloads.
Username and Email are checked against the sign-in rule before the dialog will save — fix the username if the dialog flags it.
Step 4 — Name a delegated approver
In the Edit User dialog, expand Approvals and pick a Delegated Approver — anyone except the person themselves. From then on, every approval step that resolves to this person also goes to the delegate: it appears in the delegate's approval inbox and notifications, and the delegate may decide it. The original approver keeps the request too; either of them can act. Clear the field to stop delegating. See Common questions for limits.
Step 5 — Set language, locale and time zone
In the Edit User dialog, expand Locale & Time Zone and fill Language, Locale and Time Zone. These are typed as text here, so use the standard codes: a language such as en or hi, a locale such as en-IN, and a time zone name such as Asia/Kolkata. Left blank, the person sees your organization's defaults from Setup → Feature Hub → Administration → Org Settings.
People can also set these themselves — see the next step — where they are picked from lists, which avoids typing errors.
Step 6 — Let people edit their own profile
Any signed-in user can open their profile from the avatar menu (Settings, or select the avatar). On the Account card they select Edit, change Display Name, First Name, Last Name, Phone, Language, Locale or Time Zone, and select Save. Language offers English (en) and Hindi (hi); Locale and Time Zone are lists. Users cannot change their own username, e-mail, audience, active state, delegated approver or access.
A field left empty on the profile page keeps its previous value — users cannot blank a field this way. To clear one, an administrator edits the account.
Step 7 — Grant company access (multi-company organizations)
Company access is not on the user dialog. Open Setup → Feature Hub → Administration → Org Settings → Company Access, choose the person in Select a user, then either switch on Access all companies, or select Grant company access and pick a Company and an Access kind — Transact (see + post) or View (see only). The tab appears only when multi-company mode is on and you hold the company-administration capability. While Access all companies is on, the per-company rows are ignored. How this is enforced is explained in Tenants and companies.
Step 8 — Delete an account
Deleting is part of offboarding — follow Offboard or suspend a user first. Then select the delete icon in the Actions column of the Users list and confirm Delete user?. The account disappears from the list; the business records the person owned or created keep their attribution.
Fields
These are the fields in the New User and Edit User dialogs, in form order.
| Field | What it means | Notes |
|---|---|---|
| Username | The name the person signs in with. | Must equal Email exactly, or be a plain name without @ — letters, digits and . - _ ! # ^ ~, up to 64 characters. A username that is a different e-mail address is rejected. Fills itself from Email (or Phone) until you type in it. Leave it blank to sign in with the e-mail. |
| First Name | Given name. | Used to compose Display Name. |
| Last Name | Family name. | Used to compose Display Name. |
| Work e-mail address. Where the invitation goes, and a sign-in identifier. | Not required to be unique — search before you create. Spaces are trimmed on save. | |
| Phone | Contact phone number. | If the username is a phone number and Phone is empty, it is copied from the username. |
| Display Name | The name shown across xMatix — lists, owner fields, mentions. | Follows First Name + Last Name until you type in it. Composed from them on save when blank. |
| Audience | Internal (employees) or External (portal and partner users). | Required. Default Internal. A security profile scoped to the other audience cannot be assigned. |
| Active | Whether the account is live for provisioning. | On by default. Only active accounts are provisioned and receive the welcome e-mail. Create accounts inactive to prepare them before go-live. Clearing it on an already provisioned account does not stop sign-in — see Offboard or suspend a user. |
| Language | Interface language, as a language code. | Under Locale & Time Zone. Blank uses the organization default. |
| Locale | Regional format for numbers, dates and currency, such as en-IN. | Under Locale & Time Zone. When it refines the chosen language (same base language), it also drives number grouping — en-IN shows lakhs and crores. |
| Time Zone | The zone dates and times are shown in, such as Asia/Kolkata. | Under Locale & Time Zone. Overrides the organization time zone for this person. A name xMatix does not recognise is ignored and the organization zone applies. |
| Delegated Approver | A user who receives, and may decide, this person's approval requests. | Under Approvals. Optional. The person themselves is not offered. |
Read-only facts shown elsewhere: Name (set from the username on creation), Status and Sign-in on the detail page header.
Business rules
- Username rule. On create, and on any edit that changes Username or Email, the pair must be provisionable: the username equals the e-mail, or is a plain name of up to 64 allowed characters. The dialog stops you before saving, and the server enforces the same rule.
- Defaults on create. Active on, Audience Internal, Display Name from first and last name, Name from username, then e-mail, then display name. An explicit Active off is kept.
- Provisioning trigger. Any save of an account that is active, has a username or e-mail, and has no sign-in identity yet sends it for provisioning. Inactive accounts are never provisioned. Once the identity exists, further saves do not send another welcome e-mail.
- No uniqueness check. Two accounts may share an e-mail or username. Search first; a duplicate splits the person's access across two accounts.
- System identities. System Process, System Agent and System Anonymous cannot be edited or deleted from the Users screen.
- Delegation is one step. A delegate is added alongside the approver, not instead of them; a delegate's own delegate is not included. Delegation applies whether or not the original approver is active.
- Self-service limits. On the profile page a user may change only display name, first and last name, phone, language, locale and time zone.
- Deletion. Deleting removes the account from your organization's lists and stops it resolving as a user. It does not delete records the person owned or created, and it does not delete a sign-in identity they also use with another organization.
Example
A distribution company hires a sales coordinator who works from Kochi and approves the field team's expense claims.
- The administrator opens Setup → Access Control → Users, searches
sales.coordinator@example.comand finds nothing. - They select New and type the address in Email — Username fills with the same address. They type Sales and Coordinator in the name fields; Display Name becomes Sales Coordinator. Audience stays Internal, Active stays on. Under Locale & Time Zone they enter
en,en-INandAsia/Kolkata. They select Create. - The row appears with Sign-in Pending; a minute later it shows Ready and the coordinator receives the set-password e-mail.
- On the detail page the administrator adds the coordinator's profile on Profile Assignments and their role on Role Assignments.
- Two months later the coordinator goes on leave. The administrator opens the account, selects Edit, expands Approvals, picks the regional sales manager as Delegated Approver and selects Save. Expense claims routed to the coordinator now reach the manager's inbox too; either can approve.
- When the coordinator returns, the administrator clears Delegated Approver and saves.
Training
Practice exercise
In a sandbox:
- Create an account for a fictitious person with Active switched off. Confirm the list shows Sign-in Not provisioned after five minutes, or Pending before then, and that no e-mail is sent.
- Try to set Username to a different e-mail address than Email. Expected: the dialog refuses with the username rule message.
- Set the person's Time Zone to
Asia/Dubaiand Locale toen-IN, and save. - Name yourself as their Delegated Approver.
- Open their Access Diagnostics tab. Expected: zero profiles, and nothing under Allocated to user.
- Delete the account. Expected: it disappears from All Users.
Quick reference
- Users live at Setup → Access Control → Users.
- Username = e-mail, or a plain name without
@(≤ 64 characters). - Only Active accounts are provisioned; any save of an active, unprovisioned account retries.
- Sign-in: Pending → Ready; Not provisioned after five minutes means fix and save again.
- No profile assignment means an empty workspace.
- User time zone and locale override the organization's for that person.
- A delegated approver shares the requests; they do not replace the approver.
- Company access is on Org Settings → Company Access, not on the user.
- Never edit or delete System Process, System Agent or System Anonymous.
Permissions
| What | Needs |
|---|---|
| See Users in the menu | setup.security.manage and setup.security.users.manage |
| Read, create, edit or delete accounts | setup.security.users.manage |
| Assign profiles, roles and teams | setup.security.manage |
| See License Allocations and Access Diagnostics for another user | setup.licensing.admin (you always see them on your own account) |
| Preview Outlet Transfer scope | setup.featurehub.settings.manage — without it the card says so and the rest of the tab still loads |
| Grant company access or Access all companies | setup.companies.manage, plus access to Org Settings |
| Edit your own profile | Any signed-in user |
A user without the user-administration capability does not see Users in Setup, and calls to read or change accounts are refused. The built-in SystemAdmin profile holds all of these.
Configuration
- Organization defaults — Setup → Feature Hub → Administration → Org Settings → General holds the default locale, currency, time zone and date format that every account without its own value uses. Changing them affects everyone who has not set a personal value.
- Per-user preferences — Language, Locale and Time Zone on the account, set by an administrator or by the user on their profile page.
- Audience — decides which security profiles fit the account. Profiles are scoped to Internal, External or Both on Security profiles.
- Delegated approvers — set per account under Approvals. Approval steps themselves are configured on the approval process; delegation applies to every process.
- Company access — per user on Org Settings → Company Access, when multi-company mode is on. See Tenants and companies.
- License seats — per user on License Allocations; seat enforcement and pools are described in Licensing.
- Deferred invitations — create accounts with Active off to prepare them without provisioning or e-mail, then switch Active on at go-live.
Common problems
"This user has no sign-in identity yet"
The account exists but provisioning has not completed. For the first few minutes after creation that is normal. If it persists, check that Username matches Email or is a plain name without @, and that the account is Active, then save the account again to retry.
The dialog says the username must match Email
The username is a different e-mail address from Email, contains a character outside letters, digits and . - _ ! # ^ ~, or is longer than 64 characters. Make it identical to the e-mail, or a plain name that follows the rule.
Dates and times show in the wrong time zone for one person
Their account's Time Zone is set to another zone, or to text xMatix does not recognise, in which case the organization zone applies. Have them pick the zone from the list on their profile page, or correct it under Locale & Time Zone.
Numbers show millions instead of lakhs
The person's Locale is blank or names a region that formats that way. Set Locale to en-IN (with Language en) or hi-IN (with Language hi).
The delegate cannot see an approval request
Delegated Approver is set on the wrong account — it goes on the account of the person who is away, naming the person who covers. It also covers only one step: if the delegate has their own delegate, that second person is not included.
There is no Edit or Delete on an account
It is one of the built-in system identities (Sign-in shows System). That is deliberate.
I cannot find the Company Access tab
It appears only when multi-company mode is on and you hold the company-administration capability, and it sits in Org Settings, which also needs the Feature Hub and Org Settings capabilities to reach from the menu.
Common questions
Can two accounts share the same e-mail address?
xMatix does not prevent it, but you should not create them. The person's profiles, roles, teams and seats would be split between two accounts, and the e-mail would no longer identify one account. Always search the All Users list by e-mail before selecting New, and reuse an existing account — including one that is inactive — rather than creating another.
Does a delegated approver replace the original approver?
No. The delegate is added to every approval step that resolves to the original approver, so both see the request and either can decide it. Delegation does not depend on the original approver being away or inactive — it applies as soon as it is set — so clear Delegated Approver when cover is no longer needed. Only one step is followed: a delegate's own delegate does not receive the request.
Why do two people see different times on the same record?
Each person sees dates in their own Time Zone when one is set, otherwise in the organization's time zone. Two people looking at the same record can therefore see different clock times for the same moment. The stored value is the same; only its display differs.
Can a user change their own e-mail or username?
No. The profile page lets people change their display name, first and last name, phone, language, locale and time zone only. Changes to sign-in details, audience, active state, delegated approver and access are made by an administrator with the user-administration capability, so that a sign-in identifier always passes the username rule and is re-checked.
What is the Name column, and how is it different from Display Name?
Name is the account's record name, set when the account is created — from the username, or the e-mail, or the display name if both are blank. Display Name is the friendly name shown across xMatix in lists, owner fields and mentions, and it follows first and last name unless you set it yourself.
