Help · Legal & Privacy · Employees, Rights & 2FA

Employees, Rights, and Two-Factor Authentication

A separate account for each person, permissions based on user groups, and an extra layer of security during login: This guide explains how to create employee accounts in the backend, what they are allowed to view and edit, how to secure access, and what to do if someone can no longer log in.

At a Glance

  • Accounts: Under Settings → Administrators → User Accounts, create a separate account for each person. Do not share access.
  • Permissions: A user’s permissions are determined by their user group, which you can configure for each page under Settings → Administrators → User Groups. The “Admins” group always has full access.
  • Two-Factor Authentication: Each user can enable this for their own account under My Account. Only the user themselves or our support team can reset it.
  • Automatic Logout: The session ends after one hour of inactivity. You can adjust the duration under Settings → Privacy → General.
  • Whenan employee leaves: Immediately lock the account, remove trusted devices, and delete the account later.

In this guide


Overview of Accounts, Groups, and Permissions

A user account belongs to exactly one person. Each account is part of a user group, and the group determines which pages the account can access and what changes it is allowed to make there.

WhatWhatWhere
User AccountA person’s name, email address, password, and personal settingsSettings → Administrators → User Accounts
User groupThe permissions shared by all accounts in the groupSettings → Administrators → User Groups
My AccountPersonal information, password, two-factor authentication, signaturesSettings → Administrators → My Account
Trusted DevicesDevices on which the store won't ask for the code for 30 daysSettings → Administrators → Trusted Devices

"Admins" Group

The first group on the list always has full access, including the ability to manage accounts and permissions. Its permissions cannot be restricted, and the group cannot be renamed or deleted. Assign this group only to people who are responsible for the store.

"Support XONIC" Account

Our support team uses this account to assist you in the backend. It cannot be deleted and is not counted as one of your employee accounts. Use the toggle in the “Status” column to lock it; to receive help in the backend, toggle it back to “Active.”

Number of Accounts

If your plan has a limit on the number of employee accounts, the text “Admin slots: … of … occupied” appears above the list. Locked accounts do not count toward this limit. If the quota is full, the “Add” tab will be missing, and locked accounts cannot be unlocked. To add more accounts, see Pricing.

Settings, Administrators, User Accounts: green note “Admin slots: 3 of 5 occupied” and a list with the columns ID, Online Status, Status, 2-Factor Authentication, Name, Username, Email Address, User Group, and Logins; Rows: Support XONIC, Anna Example, Erika Musterfrau (admins, 2-factor auth enabled), Max Mustermann (customer service), and the red-highlighted, locked account for Mia Musterfrau

The user accounts with a quota, status toggle, and two-factor authentication column: locked accounts appear in red in the list and do not count toward the occupied slots. Click to enlarge.


Create Employees

Create a separate account for each person. This is the only way you’ll be able to see later who changed an order or responded to a ticket, and it’s the only way you can revoke access for one person without locking out everyone else.

  1. First, create the appropriate user group with its permissions; see User Groups.
  2. Open Settings → Administrators → User Accounts and click the “Add” tab at the top. The “Create User Account” window will open.
  3. Enter the “First Name,” “Last Name,” and “Email Address.” Each email address may only be used once. The “Username” field is only available if Settings → General → Basic Settings → Allow Admin Login Alias is set to true. It must not be an email address.
  4. Set a “Password” and repeat it under “Confirm Password.” It must comply with the password guidelines. Alternatively, set “Generate Password Automatically” to “Yes.”
  5. Select the “User Group.” The default setting here is “--none--”: An account without a group can only view the dashboard.
  6. If you check “Notify user via email and send password,” the person will receive the backend URL and their login credentials via email. If you use an automatically generated password, this option is enabled automatically.
  7. Click “Add.”
"Create User Account" form with first name Max, last name Mustermann, username max.mustermann, email address max.mustermann@example.com, empty fields for Slack User ID and Skills, "Generate password automatically" set to no, the password fields filled out with the password guidelines checked off in green, “Notify user via email and send password” set to “Yes,” and user group “Customer Service”

A new user account for customer service: As you type the password, the store shows which password guidelines it already meets. Click to enlarge.

The email contains the password in plain text. Ask the person to change it by clicking “Change Password” under “My Account” the first time they log in. For this, their group needs the “Edit” permission for “My Account”; see Assigning Permissions.

Personal Settings

In the same form and later under “Edit,” you can specify additional details. Each person can also change these settings for themselves under “My Account.”

FieldFunction
“Left Navigation”"Expanded" displays the menu permanently on the left side of the page; "Collapsed" displays it only when the "Menu" button is clicked.
“Signature (Ticket System),” “Signature (Orders)”A personalized greeting that the store uses when responding to tickets or updating orders, per language
“Skills (Ticket Assignment)”Free-form text for automatic ticket assignment via AI, such as responsibilities and languages
“Slack User ID”Destination for personalized Slack notifications. Leave blank to disable them.
“Project Manager,” “Alternative Email Addresses,” “CalDAV Synchronization”Settings for the CRM. Only members of the “Admins” group can designate project managers.XONIC Premium: CRM

The name under which a reply appears in the customer’s ticket is determined not by the user account, but by the “Sender (Avatar)” in the ticket system; see Tickets & Tasks.


Create user groups

Group people with the same tasks together, such as “Customer Service,” “Shipping,” or “Accounting.” You can then change permissions once for everyone.

New Group

  1. Under Settings → Administrators → User Groups, click the “Add” tab.
  2. Enter a unique name with at least 5 characters and click “Add.”
  3. In the new group’s action menu, select “Access Rights” and set the permissions; see Assigning Permissions.

Copy Group

Selecting “Copy” from the action menu creates a new group with all the permissions of the original. This saves time when two roles differ only in a few permissions. New stores come with the groups “Level 1” through “Level 3” without any permissions.

Deleting a group deletes its members. The store removes all user accounts belonging to the group along with the group itself. Assign the accounts to another group beforehand. The “User Accounts” column in the list shows how many accounts are in a group.

Assigning Permissions

Permissions apply to each page in the backend: A group may open a page and, depending on the page, edit, create, delete, or perform other actions there. Anything not granted is restricted.

  1. Under Settings → Administrators → User Groups, select “Access Rights” from the group’s action menu. At the top, you’ll see “Access Rights for User Group:” followed by the group’s name.
  2. The pages are organized by main menu, such as “Orders” or “Settings.” Next to each page is its filename in parentheses, such as “My Account (config-admins.php).”
  3. The Yes/No toggle next to the page name determines page access (Read): The page appears in the menu and can be opened. Only then do the additional permissions for that page expand below it.
  4. The three icon buttons at the top (names appear when you hover over them) expand and collapse all sections, set all permissions, or remove all of them.
  5. Click “Update” to save.
Access rights for the Customer Service user group: three buttons at the top to expand and collapse, set and remove all rights; below that, collapsed sections and the expanded "Orders" section with "Orders (orders.php)" set to “Yes” and the sub-permissions Create, Edit (Yes), Delete, Multiple Selection, and Purchase Prices; following a gap, the section “Additional Sections (no menu item)” with a page bearing only its filename, and “Edit Orders (orders-change.php)” set to “Yes” with “Edit”

Permissions for the Customer Service group: Read and edit orders, plus the order editor under “Additional Sections (no menu item)”; the dashed lines indicate omitted parts of the page. Click to enlarge.

When you save, the store logs out all other users (“For security reasons, all other administrators have been logged out.”). Even customers who are currently logged in to the store must log in again. Therefore, do not change permissions in the middle of daily operations. The same applies to locking and deleting accounts.

Permissions

You can see which permissions a page offers at the bottom of the page as soon as “Page Access/Read” is enabled. Not every page has all of them.

PermissionAllows
"Page Access/Read"Open and view the page. Without this permission, the menu item is missing.
"Edit," "Create," "Delete"Save changes, create new entries, delete entries
“Activate/Deactivate,” “Copy,” “Move”Status toggle, copy entries, move entries to other categories
“Import,” “Export”Import and export data, for example in xoPort
“Multiple Selection”Bulk actions for multiple orders at once
“Purchase Prices”Purchase prices and profit in orders, in the order editor, and in the sales report. In orders and the sales report, the store only displays them if Settings → Checkout → Inventory → Profit Calculation (backend) is set to true.
“Lock User Account”Lock and unlock accounts, for user accounts and for customers
“Customize Access Rights”Change user group permissions
“Edit (Super Admin Rights),” “Limit Ticket View to Your Own Tickets”Special permissions in the ticket system; see Tickets & Tasks. Restricting access to one’s own tickets does not affect “Set All Access Rights.”

Permissions apply per page, not per field

Individual fields on a page cannot be hidden. Anyone authorized to open a page can view all information on it. Exceptions are purchase prices and the restriction to one’s own tickets. The settings are also a single page: Anyone authorized to edit them can change all settings groups, including session duration and password policies.

Pages Without a Menu Item

Some pages do not have their own menu item, such as the order editor (orders-change.php), the product editor (xoproducts.php), and the pages for receipts and printing. They appear at the very bottom under “Other Areas (without menu item),” with names such as “Edit Orders” or simply the filename.ab, depending on the versionfrom 4.9.24

Anyone who needs to edit orders therefore requires permissions for “Orders” and for the order editor (orders-change.php).

After an update: If an update introduces a new page, your groups will not initially have access to it. Only the “Admins” group can see it right away. Grant access to the new page to the groups that need it.

Typical Tasks and the Required Permissions

Grant each group only the pages it needs for its work. These examples will help you determine which ones to include.

TaskPage in the Permissions EditorPermissions
View orders and quotes"Orders"“Page Access/Read.” Quotes are located on the same page, under the “Quotes” tab.
Change status, notify customers"Orders"plus “Edit”
Create shipping label"Orders""Edit"from 4.9.25
Delete orders or quotes, delete shipping labels"Orders"“Delete.” This applies to both; there is no separate option just for labels.
Edit items in an orderOrder Editor (orders-change.php) under “Other Areas (no menu item)”“View,” “Edit,” “Add” if necessary, and “Delete”
Customer data and notes about the customer“Customers” and “Admin Notes”“View/Read” for each. The shop only displays the “Notes” tab in the customer profile if the user has “Admin Notes” permission.
Edit Tickets“Tickets & Tasks”See Tickets & Tasks
Read Submissions from Custom Forms“Forms”“Page Access/Read,” see Forms & Spam Protection from 4.10
Change your password and two-factor authentication“My Account”“Page Access/Read” and “Edit.” Grant these permissions to each group.
Remove your own trusted devices"Trusted Devices""Page Access/Read" and "Delete"

Notes for Everyone or Just for Yourself

Each note has a “Visibility” setting: “Any Admin” shows it to all accounts with access to admin notes, while “Only You” shows it only to the person who created it. This allows you to grant a temporary employee access to customer notes without revealing your personal notes.

Dashboard

The dashboard also follows these permissions. The tiles for items, orders, customers, tickets, and notes, as well as the charts for orders and sales, appear only if you have read access to the corresponding page.



Locking, Unlocking, and Deleting Accounts

Locking immediately revokes access and can be undone. Deleting is permanent.

Locking and Unlocking

Under Settings → Administrators → User Accounts, set the toggle in the “Status” column to “Suspended” or select “Suspend User Account” from the action menu. To revert, select “Active” or “Unlock User Account.” Locked accounts appear in red in the list.

  • Your group needs the “Lock User Account” permission to do this. You cannot lock your own account.
  • A locked-out user is immediately logged out. The next time they try to log in, they’ll see the message “User account locked!”
  • If the quota for employee accounts is full, an account cannot be unlocked. Lock another account first.

Delete

Select “Delete” from the action menu and confirm. You cannot delete your own account, the “XONIC” account, or the account with the shop operator’s email address (found under Settings → Interfaces → Email Marketing / CRM → Email Options).

After deletion, the name will no longer appear in transaction histories, such as in order history entries. Therefore, first lock the accounts of former employees and delete them only after all related processes have been completed.

Do not edit locked accounts. If you save a locked account via “Edit” and “Update,” it will revert to “Active.” After every change to a locked account, check the toggle in the “Status” column.

Set Up Two-Factor Authentication

With two-factor authentication, logging in requires not only a password but also a six-digit one-time code from an authenticator app on the phone. Anyone who only knows the password cannot log in. Set this up for every account.

  1. Each person should go to Settings → Administrators → My Account and turn on two-factor authentication.
  2. Click “Update.” From now on, the login process will require the code.
  3. Immediately afterward, click “View 2FA Setup” and scan the QR code with the authenticator app. Instead of the QR code, you can manually enter the key next to it. Select SHA512 as the method; it’s listed in the note above the key.
  4. Test logging in using a private browser window before you log out.
Erika Musterfrau's account with the two-factor authentication toggle enabled and the 2FA setup panel expanded: QR code, note saying “Scan the QR code with your authenticator app,” indication of the sha512 algorithm, field containing the key for a demo account, and a “Copy” button

After enabling and saving, “View 2FA Setup” under My Account displays the QR code and the key for the Authenticator app (demo account). Click to enlarge.

Log In with Code

After entering your username and password, the store will ask for the “one-time code.” Enter the current code from the app. Selecting “Trust this device for 30 days” will prevent the store from asking for the code on this device for a while; see Trusted Devices.

New Phone

As long as two-factor authentication is enabled, “View 2FA Setup” under My Account will display the same QR code. Scan it with your new phone before you hand over your old one.

Turning Off

Under My Account, toggle the switch off and click “Update.” If you turn two-factor authentication back on later, the store will generate a new key. The old entry in the app will then no longer be valid.

Each person sets up two-factor authentication for their own account. In the list of user accounts, the “2-Factor Auth” column shows who has it enabled. You cannot change this setting there.
Backend login page, "One-Time Code" step: an empty "One-Time Code" field; a checkbox labeled "Trust this device for 30 days" with a note stating that 2FA codes will no longer be requested on this device; below that, the "Log In" and "Cancel" buttons

After the username and password, the store will ask for the six-digit one-time code from the app. Click to enlarge.


If the code is incorrect

If the login screen displays “Incorrect one-time code,” it’s usually due to the phone’s clock or an outdated entry in the app.

Check

  • Time: The code is only valid for a short time. If your phone’s clock is off by more than about two minutes, the code won’t work. Set the time to update automatically.
  • Correct entry: If you’ve turned two-factor authentication off and then back on, only the most recent entry in the app is valid.
  • Method: The store uses SHA512. If you entered the key manually, check this setting in the app.
  • Empty field: “Missing one-time code” means the field was submitted empty.

Lost phone, app deleted

Only the user themselves can reset two-factor authentication under My Account. There is no button that allows another administrator to disable it for someone else’s account.

  • If the user has a trusted device on which the store does not ask for the code, they should log in there and disable two-factor authentication under “My Account” or set it up again.
  • Otherwise, please contact our support team. Until then, the user cannot work in the backend; a new password won’t help, as the code will still be required.
Precaution: Store the key from “View 2FA Setup” securely, such as in a password manager, or set up the app on a second device as well. That way, a lost phone won’t be a problem.

Trusted Devices

If a user checks the “Trust this device for 30 days” box when entering a one-time code, the store will not ask for the code again on that device and in that browser for 30 days. A username and password are still required.

List of Devices

Under Settings → Administrators → Trusted Devices, you’ll find all saved devices listed with “Administrator,” “Device,” “IP Address,” “Created On,” “Last Used,” and “Valid Until.” Each user sees their own devices; members of the “Admins” group see the devices of all employees. The store remembers a maximum of 5 devices per account; when a sixth device is added, the oldest one is removed.

Remove Devices

Clicking “Delete” in the row removes a single device (after confirming with “Remove”); “Remove All Devices” removes all visible devices. The store will ask for the code again on these devices the next time the user logs in. Remove devices if a laptop is lost, an employee leaves the company, or a device in the list appears unfamiliar to you. To do this, the group must have the “Delete” permission on this page.

"Trusted Devices" page with a search field and two devices belonging to Erika Musterfrau (Chrome / Windows and Firefox / Mac) with abbreviated IP addresses, created on, last used, valid until "21 days remaining," and a "Delete" button for each; below that, a note regarding a 30-day validity period and a maximum of 5 devices, along with the red “Remove All Devices” button

The saved devices with expiration dates: Remove individual devices using “Delete,” and all visible devices at once using “Remove All Devices.” Click to enlarge.

Only check the box on your own, secure devices—never on shared or public computers.

Forgotten and Changing Passwords

Anyone can reset a forgotten password themselves using a link sent by email. The previous password remains valid until you save a new one.

Forgot Password

  1. On the login page, click “Forgot your password?”
  2. Enter the email address associated with the user account. The username will not work here.
  3. Open the link in the email. It is valid for 30 minutes by default and can only be used once.
  4. Under “Set a new password,” enter the new password twice and click “Save password.”

Didn’t receive an email?

  • The page always displays the same message, even for an unknown address. Check to make sure you entered the email address associated with your user account, and check your spam folder.
  • The store will send a new link for the same account no sooner than 20 minutes later.
  • If you no longer know the registered email address, a colleague with access to the user accounts can set a new password, or contact our support team.

Set a password for a colleague

Go to Settings → Administrators → User Accounts, select “Edit” from the action menu, set “New Password” to Yes, enter the password twice, and click “Update.” The store does not send an email for this. Share the password securely or have the colleague use the “Forgot Password” feature. Each person can change their own password under My Account by selecting “Change Password.”

Setting under Settings → Privacy → Password PoliciesEffectNew stores
“Password Policies: Minimum Length”Minimum number of characters8
“Password Guidelines: Numbers,” “… lowercase letters,” “… uppercase letters,” “… special characters”At least one character of each typeAll set to true
"Admin Password Reset: Feature Enabled"“Forgot Password” in the backend. If set to false, only an administrator can set new passwords.true
"Admin Password Reset: Link Validity (minutes)"How long the link in the email is valid: 5 to 1,440 minutes30

These guidelines apply to passwords that you assign manually in the backend and to the “Forgot Password” feature. The rules regarding renewal after a certain number of months and the locking of old passwords within the same group apply only to customer accounts in the store. You can replace an automatically generated password with your own when you log in for the first time.


Session Duration and Automatic Logout

The store logs users out if there is no activity for a while. This protects the backend if someone steps away from their computer. If you feel this happens too soon, extend the duration.

Set Duration

Under Settings → Privacy → General → Admin Session Timeout (seconds), you can specify after how many seconds without a click the session ends. New stores are set to 3600, which is one hour. 7200 is two hours, and 14400 is four hours.

Setting this to 0 disables automatic logout. We do not recommend this, especially on computers used by multiple people.

IP Check

Under Settings → Privacy → General → Admin Session IP Verification, set the value to “true” to end the session as soon as the IP address changes significantly—for example, when switching from office Wi-Fi to a mobile network or when enabling a VPN. The store tolerates minor changes within the same connection. This check is disabled by default. Leave it disabled if your team works on the go or across different networks.

Settings, Privacy, General: After a blank line, the lines “Enable Admin Session IP Check” set to false and “Admin Session Timeout (seconds)” set to 3600, next to it, the help text is open, showing the default value of 3600 and the examples 1800, 7200, 14400, and 0

Session duration and backend IP verification can be found under Privacy → General, along with the help text explaining the time values in seconds. Click to enlarge.

Other reasons for logging out

What happenedWhySolution
Message: “Your session has expired for security reasons.”The set duration without a click has elapsed.Extend the duration. After logging in, you’ll be redirected to the page you were on. Any unsaved entries will be lost.
Message: “… because your IP address has changed.”IP verification is enabled, and you’ve switched networks.Turn off IP verification or stay on the same network
Logged out without a message while someone else is using the same accountIf the number of employee accounts in your plan is limited, an account is valid in only one browser at a time. Logging in from another location ends the previous session.One account per person; do not work in two browsers at the same time
Everyone logged out at onceSomeone has saved permissions or locked or deleted an account.Log in again; make such changes during quiet times
Logged out on other devicesYou saved this under " My Account." This ends your logins on other devices.Sign in again there
Logged out after closing the browserYour session remains active only as long as the browser is open.Log in again

If the store continues to log you out prematurely despite extended sessions, please contact us. We’ll then check the server settings as well.


If you can’t log in

The login page usually explains exactly what the problem is. This table will help you figure it out.

You’ll seeMeaningSolution
“Incorrect username, email address, or password!”The username or password is incorrect.Log in using the account’s email address; the username can only be used if “Admin Login Alias” is enabled. Otherwise, reset your password.
“User account locked!”The account is locked.A colleague with the “Lock User Account” permission can unlock it; see Locking.
“Invalid one-time code,” “Missing one-time code”The code from the app is missing or does not match.See “Code does not match”
A blank white page instead of the backendAfter several failed attempts, the store blocks login attempts from your IP address for a short time—up to ten minutes. This affects everyone using the same network connection, such as the entire office.Wait, then log in with the correct information. Each additional failed attempt will extend the duration of the next lockout.
“Invalid security token. Please reload the page and log in again.”For example, the login page was left open for too long.Reload the page and log in again
“This account is currently being used on another device or in another browser.”The account is logged in elsewhere. If you log in, the session there will end.Confirm if that’s you; otherwise, change your password
“Connection to the XONIC authentication server failed.” after logging inA verification check with our server failed. You are still logged in.Continue working. If this message persists, please contact us.

After changing your login credentials

If you’ve changed your email address, log in with the new one. Replace any old password saved in your browser. If you enabled two-factor authentication when saving your information under “My Account,” you’ll now need the code from the app.

Login Takes a Very Long Time

After logging in, the store clears old history data and regularly optimizes the database—by default, every 30 days. This login process takes longer. Set Settings → General → Maintenance → Archive Data Deletion on Login - Number of Days to 1 or higher: If set to 0, the store clears data every time you log in, and for large stores, this can cause the login process to time out.


Absence and Substitute

Enter vacation, sick leave, or parental leave in the ticket system, not in the user account. The account remains active.

Under Tools → Tickets & Tasks → Absence & Vacation Mode, you can set the time period and designate a substitute. If a ticket is assigned to an absent person, the shop will automatically enter the substitute’s information and, if requested, notify the customer. Details are available under Tickets & Tasks.

If someone leaves the company, simply marking them as absent is not enough: Lock the account; see Locking.


Who made what changes?

With individual accounts, you can track who did what. You can see this for yourself in these locations.

WhatWhere
Who is currently logged in, when someone was last online, and how often they’ve logged inSettings → Administrators → User Accounts, columns showing online status and “Logins”
When your account was created and last modifiedMy Account, at the bottom: “Account Created,” “Logins,” and “Last Modified”
Who set a status or wrote a comment on an orderOrder history, with name and date/time for each entry
Who replied to a ticket or changed the assigned personTicket history
Who changed which fields for products, settings, or orders, and whenThe store saves these changes along with the user who made them and the time. Our support team will analyze this data for you.
Logins, failed login attempts, and logouts, including the time and IP addressSecurity log on the server. If any suspicious activity is detected, our support team will analyze it.

The store automatically deletes log files on the server after the retention period expires; by default, this is one month.


Data Protection and Responsibility

Your employees can view your customers’ names, addresses, and orders in the backend. Who is allowed to see what is therefore also a matter of data protection.

As little as necessary

Grant each group only the pages they need. A temporary shipping assistant needs access to orders, but not to customer exports or settings. Review permissions whenever tasks change.

Separate Accounts, Two-Factor Authentication

A shared account for multiple people obscures who did what and cannot be locked down for a single person. Set up two-factor authentication for every account, starting with the “Admins” group.

External Service Providers

If an agency, tax firm, or freelancer works in the backend, create a separate account for them with its own group and deactivate it after the job is complete. If service providers view your customers’ personal data, you generally need a data processing agreement under Article 28 of the GDPR. Please consult your data protection advisor for details.

Checklist for Hiring and Termination

New Employee

  • Appropriate user group selected or created
  • Separate account created with a unique email address
  • The group has “Page Access/Read” and “Edit” permissions for “My Account”
  • Password changed upon first login
  • Two-factor authentication set up and tested
  • Created signatures and, if used, “Sender (Avatar)” in the ticket system

Employee is leaving the company

  • Lock the account on the employee’s last day of work
  • Remove the account’s trusted devices
  • Reassign open tickets and tasks
  • Change any login credentials the person knew, such as those for directory protection under Settings → Administrators → .htaccess Protection
  • Delete the account once these steps are complete

Frequently Asked Questions

How do I create a new user for the backend?

Go to Settings → Administrators → User Accounts and click the “Add” tab. Enter the name, email address, and password, and select the user group. Without a group, the account will only see the dashboard. If the “Add” tab is missing, either your employee account quota is full or you lack the “Create” permission. See Create Employees for details.

How do I grant a staff member full admin rights?

Assign their account to the “Admins” group. This group has full access, including the ability to create accounts, change permissions, and modify settings. Grant this group only to individuals responsible for the store. For everyone else, create a group with appropriate permissions.

How do I restrict an employee to orders and quotes?

Create a separate user group and, under “Access Rights,” grant it only “Orders” with the necessary permissions. Quotes are located on the same page. If the person also needs to edit items, additionally grant access to the order editor (orders-change.php) under “Additional Areas (without menu item).” An overview is available under “Typical Tasks.”

A new employee is missing a feature. Why is that?

Most often, their group lacks permission for that page. Go to Settings → Administrators → User Groups, open the group’s “Access Rights,” search for the page (including under “Additional Areas (without menu item)”), and grant “Page Access/Read” along with the necessary additional permissions. Also check whether the account is assigned to a group at all and whether someone has hidden the menu item.

If a group is allowed to edit orders or items but does not have access to the corresponding editor, Tools → Server Info & Health Check will report this and offer to restore the permissions.from 4.9.24

Can I grant the delete permission only for package labels?

No. Anyone with the “Delete” permission on the “Orders” page can delete package labels. The same permission also allows them to delete orders and quotes. Permissions apply per page, not per function.

Can I hide individual fields from employees?

No, permissions apply on a per-page basis. Anyone who is allowed to open a page can see all fields on it. Exceptions are purchase prices with the “Purchase Prices” permission and the restriction to one’s own tickets. If you need more granular control, please contact us to discuss a customization.

How do I give third parties access to customer notes without granting them full permissions?

Create a separate account for that person in a separate group. Grant the group “Page Access/Read” for “Customers” and “Admin Notes,” and nothing else. Notes with the visibility setting “Only You” remain private. If external parties view customer data, keep data protection in mind.

How do I reset another user’s two-factor authentication?

This cannot be done in the backend. Only the person themselves can disable it under Settings → Administrators → My Account. If they can no longer log in without the code, a trusted device on which the store does not ask for the code can help. Otherwise, contact our support team. See “Code Doesn’t Work” for details.

The code from the app is no longer accepted. What should I do?

Set your phone’s time to automatic, as even a two-minute discrepancy is enough to cause issues. Use the most recent entry in the app if you’ve ever set up two-factor authentication again. If you entered the key manually, the method must be set to SHA512.

How do I reset my password for the backend?

On the login page, click “Forgot your password?” and enter the email address associated with your user account. The link in the email is valid for 30 minutes by default. If you no longer remember the address, a colleague with access to user accounts can set a new password for you; otherwise, contact our support team.

Why can’t I access the backend anymore?

Read the message on the login page: incorrect password, locked account, or missing one-time code. If you see only a blank white page, your login has been temporarily blocked for your IP address after several failed attempts; please wait no more than ten minutes. All messages can be found under “Login Not Working.”

How do I reactivate a locked account?

Under Settings → Administrators → User Accounts, set the toggle in the “Status” column to “Active” or select “Unlock User Account” from the action menu. To do this, you need the “Lock User Account” permission. If the quota for your employee accounts is full, lock another account first.

Where do I set the time after which the backend automatically logs me out?

Go to Settings → Privacy → General → “Admin Session Timeout (seconds).” New stores have a setting of 3,600, which is one hour without a click. For two hours, enter 7,200; for four hours, enter 14,400. If you’re still being logged out frequently, check the IP verification settings and see if someone else is using your account; see Session Duration.

I can’t log in after changing my login credentials. Why?

Log in with your new email address if you’ve changed it, and replace any old password saved in your browser. Clicking “Save” under “My Account” will log you out of other devices. If you’ve enabled two-factor authentication, the store will now require the code from the app.

How do I keep the “Tickets” tile and the menu permanently expanded in the dashboard?

The “Tickets” tile appears as soon as tickets are available and your group has “Page Access/Read” permissions for “Tickets & Tasks.” You can set the left-hand menu to “expanded” under “My Account” using “Left Navigation.” The “Menu” button only keeps it expanded until the next login.

Can I see who made a change?

In the history of an order and a ticket, each entry shows who wrote it. The list of user accounts shows when someone was last logged in. The store also saves detailed changes to products, settings, and orders; our support team handles the analysis. See Logs.

Additional Guides

We provide assistance with permissions and access

We work with you to set up user groups for your team, help if someone can no longer access the backend, and analyze the logs in case of suspected issues.

Contact Support Now