Employees, Rights, and Two-Factor Authentication
A separate account for each person, permissions based on user groups, and an extra layer of security during login: This guide explains how to create employee accounts in the backend, what they are allowed to view and edit, how to secure access, and what to do if someone can no longer log in.
At a Glance
- Accounts: Under Settings → Administrators → User Accounts, create a separate account for each person. Do not share access.
- Permissions: A user’s permissions are determined by their user group, which you can configure for each page under Settings → Administrators → User Groups. The “Admins” group always has full access.
- Two-Factor Authentication: Each user can enable this for their own account under My Account. Only the user themselves or our support team can reset it.
- Automatic Logout: The session ends after one hour of inactivity. You can adjust the duration under Settings → Privacy → General.
- Whenan employee leaves: Immediately lock the account, remove trusted devices, and delete the account later.
In this guide
Overview of Accounts, Groups, and Permissions
A user account belongs to exactly one person. Each account is part of a user group, and the group determines which pages the account can access and what changes it is allowed to make there.
| What | What | Where |
|---|---|---|
| User Account | A person’s name, email address, password, and personal settings | Settings → Administrators → User Accounts |
| User group | The permissions shared by all accounts in the group | Settings → Administrators → User Groups |
| My Account | Personal information, password, two-factor authentication, signatures | Settings → Administrators → My Account |
| Trusted Devices | Devices on which the store won't ask for the code for 30 days | Settings → Administrators → Trusted Devices |
"Admins" Group
The first group on the list always has full access, including the ability to manage accounts and permissions. Its permissions cannot be restricted, and the group cannot be renamed or deleted. Assign this group only to people who are responsible for the store.
"Support XONIC" Account
Our support team uses this account to assist you in the backend. It cannot be deleted and is not counted as one of your employee accounts. Use the toggle in the “Status” column to lock it; to receive help in the backend, toggle it back to “Active.”
Number of Accounts
If your plan has a limit on the number of employee accounts, the text “Admin slots: … of … occupied” appears above the list. Locked accounts do not count toward this limit. If the quota is full, the “Add” tab will be missing, and locked accounts cannot be unlocked. To add more accounts, see Pricing.
The user accounts with a quota, status toggle, and two-factor authentication column: locked accounts appear in red in the list and do not count toward the occupied slots. Click to enlarge.
Create Employees
Create a separate account for each person. This is the only way you’ll be able to see later who changed an order or responded to a ticket, and it’s the only way you can revoke access for one person without locking out everyone else.
- First, create the appropriate user group with its permissions; see User Groups.
- Open Settings → Administrators → User Accounts and click the “Add” tab at the top. The “Create User Account” window will open.
- Enter the “First Name,” “Last Name,” and “Email Address.” Each email address may only be used once. The “Username” field is only available if Settings → General → Basic Settings → Allow Admin Login Alias is set to true. It must not be an email address.
- Set a “Password” and repeat it under “Confirm Password.” It must comply with the password guidelines. Alternatively, set “Generate Password Automatically” to “Yes.”
- Select the “User Group.” The default setting here is “--none--”: An account without a group can only view the dashboard.
- If you check “Notify user via email and send password,” the person will receive the backend URL and their login credentials via email. If you use an automatically generated password, this option is enabled automatically.
- Click “Add.”
A new user account for customer service: As you type the password, the store shows which password guidelines it already meets. Click to enlarge.
Personal Settings
In the same form and later under “Edit,” you can specify additional details. Each person can also change these settings for themselves under “My Account.”
| Field | Function |
|---|---|
| “Left Navigation” | "Expanded" displays the menu permanently on the left side of the page; "Collapsed" displays it only when the "Menu" button is clicked. |
| “Signature (Ticket System),” “Signature (Orders)” | A personalized greeting that the store uses when responding to tickets or updating orders, per language |
| “Skills (Ticket Assignment)” | Free-form text for automatic ticket assignment via AI, such as responsibilities and languages |
| “Slack User ID” | Destination for personalized Slack notifications. Leave blank to disable them. |
| “Project Manager,” “Alternative Email Addresses,” “CalDAV Synchronization” | Settings for the CRM. Only members of the “Admins” group can designate project managers.XONIC Premium: CRM |
The name under which a reply appears in the customer’s ticket is determined not by the user account, but by the “Sender (Avatar)” in the ticket system; see Tickets & Tasks.
Create user groups
Group people with the same tasks together, such as “Customer Service,” “Shipping,” or “Accounting.” You can then change permissions once for everyone.
New Group
- Under Settings → Administrators → User Groups, click the “Add” tab.
- Enter a unique name with at least 5 characters and click “Add.”
- In the new group’s action menu, select “Access Rights” and set the permissions; see Assigning Permissions.
Copy Group
Selecting “Copy” from the action menu creates a new group with all the permissions of the original. This saves time when two roles differ only in a few permissions. New stores come with the groups “Level 1” through “Level 3” without any permissions.
Assigning Permissions
Permissions apply to each page in the backend: A group may open a page and, depending on the page, edit, create, delete, or perform other actions there. Anything not granted is restricted.
- Under Settings → Administrators → User Groups, select “Access Rights” from the group’s action menu. At the top, you’ll see “Access Rights for User Group:” followed by the group’s name.
- The pages are organized by main menu, such as “Orders” or “Settings.” Next to each page is its filename in parentheses, such as “My Account (config-admins.php).”
- The Yes/No toggle next to the page name determines page access (Read): The page appears in the menu and can be opened. Only then do the additional permissions for that page expand below it.
- The three icon buttons at the top (names appear when you hover over them) expand and collapse all sections, set all permissions, or remove all of them.
- Click “Update” to save.
Permissions for the Customer Service group: Read and edit orders, plus the order editor under “Additional Sections (no menu item)”; the dashed lines indicate omitted parts of the page. Click to enlarge.
Permissions
You can see which permissions a page offers at the bottom of the page as soon as “Page Access/Read” is enabled. Not every page has all of them.
| Permission | Allows |
|---|---|
| "Page Access/Read" | Open and view the page. Without this permission, the menu item is missing. |
| "Edit," "Create," "Delete" | Save changes, create new entries, delete entries |
| “Activate/Deactivate,” “Copy,” “Move” | Status toggle, copy entries, move entries to other categories |
| “Import,” “Export” | Import and export data, for example in xoPort |
| “Multiple Selection” | Bulk actions for multiple orders at once |
| “Purchase Prices” | Purchase prices and profit in orders, in the order editor, and in the sales report. In orders and the sales report, the store only displays them if Settings → Checkout → Inventory → Profit Calculation (backend) is set to true. |
| “Lock User Account” | Lock and unlock accounts, for user accounts and for customers |
| “Customize Access Rights” | Change user group permissions |
| “Edit (Super Admin Rights),” “Limit Ticket View to Your Own Tickets” | Special permissions in the ticket system; see Tickets & Tasks. Restricting access to one’s own tickets does not affect “Set All Access Rights.” |
Permissions apply per page, not per field
Individual fields on a page cannot be hidden. Anyone authorized to open a page can view all information on it. Exceptions are purchase prices and the restriction to one’s own tickets. The settings are also a single page: Anyone authorized to edit them can change all settings groups, including session duration and password policies.
Pages Without a Menu Item
Some pages do not have their own menu item, such as the order editor (orders-change.php), the product editor (xoproducts.php), and the pages for receipts and printing. They appear at the very bottom under “Other Areas (without menu item),” with names such as “Edit Orders” or simply the filename.ab, depending on the versionfrom 4.9.24
Anyone who needs to edit orders therefore requires permissions for “Orders” and for the order editor (orders-change.php).
Typical Tasks and the Required Permissions
Grant each group only the pages it needs for its work. These examples will help you determine which ones to include.
| Task | Page in the Permissions Editor | Permissions |
|---|---|---|
| View orders and quotes | "Orders" | “Page Access/Read.” Quotes are located on the same page, under the “Quotes” tab. |
| Change status, notify customers | "Orders" | plus “Edit” |
| Create shipping label | "Orders" | "Edit"from 4.9.25 |
| Delete orders or quotes, delete shipping labels | "Orders" | “Delete.” This applies to both; there is no separate option just for labels. |
| Edit items in an order | Order Editor (orders-change.php) under “Other Areas (no menu item)” | “View,” “Edit,” “Add” if necessary, and “Delete” |
| Customer data and notes about the customer | “Customers” and “Admin Notes” | “View/Read” for each. The shop only displays the “Notes” tab in the customer profile if the user has “Admin Notes” permission. |
| Edit Tickets | “Tickets & Tasks” | See Tickets & Tasks |
| Read Submissions from Custom Forms | “Forms” | “Page Access/Read,” see Forms & Spam Protection from 4.10 |
| Change your password and two-factor authentication | “My Account” | “Page Access/Read” and “Edit.” Grant these permissions to each group. |
| Remove your own trusted devices | "Trusted Devices" | "Page Access/Read" and "Delete" |
Notes for Everyone or Just for Yourself
Each note has a “Visibility” setting: “Any Admin” shows it to all accounts with access to admin notes, while “Only You” shows it only to the person who created it. This allows you to grant a temporary employee access to customer notes without revealing your personal notes.
Dashboard
The dashboard also follows these permissions. The tiles for items, orders, customers, tickets, and notes, as well as the charts for orders and sales, appear only if you have read access to the corresponding page.
Locking, Unlocking, and Deleting Accounts
Locking immediately revokes access and can be undone. Deleting is permanent.
Locking and Unlocking
Under Settings → Administrators → User Accounts, set the toggle in the “Status” column to “Suspended” or select “Suspend User Account” from the action menu. To revert, select “Active” or “Unlock User Account.” Locked accounts appear in red in the list.
- Your group needs the “Lock User Account” permission to do this. You cannot lock your own account.
- A locked-out user is immediately logged out. The next time they try to log in, they’ll see the message “User account locked!”
- If the quota for employee accounts is full, an account cannot be unlocked. Lock another account first.
Delete
Select “Delete” from the action menu and confirm. You cannot delete your own account, the “XONIC” account, or the account with the shop operator’s email address (found under Settings → Interfaces → Email Marketing / CRM → Email Options).
After deletion, the name will no longer appear in transaction histories, such as in order history entries. Therefore, first lock the accounts of former employees and delete them only after all related processes have been completed.
Set Up Two-Factor Authentication
With two-factor authentication, logging in requires not only a password but also a six-digit one-time code from an authenticator app on the phone. Anyone who only knows the password cannot log in. Set this up for every account.
- Each person should go to Settings → Administrators → My Account and turn on two-factor authentication.
- Click “Update.” From now on, the login process will require the code.
- Immediately afterward, click “View 2FA Setup” and scan the QR code with the authenticator app. Instead of the QR code, you can manually enter the key next to it. Select SHA512 as the method; it’s listed in the note above the key.
- Test logging in using a private browser window before you log out.
After enabling and saving, “View 2FA Setup” under My Account displays the QR code and the key for the Authenticator app (demo account). Click to enlarge.
Log In with Code
After entering your username and password, the store will ask for the “one-time code.” Enter the current code from the app. Selecting “Trust this device for 30 days” will prevent the store from asking for the code on this device for a while; see Trusted Devices.
New Phone
As long as two-factor authentication is enabled, “View 2FA Setup” under My Account will display the same QR code. Scan it with your new phone before you hand over your old one.
Turning Off
Under My Account, toggle the switch off and click “Update.” If you turn two-factor authentication back on later, the store will generate a new key. The old entry in the app will then no longer be valid.
After the username and password, the store will ask for the six-digit one-time code from the app. Click to enlarge.
If the code is incorrect
If the login screen displays “Incorrect one-time code,” it’s usually due to the phone’s clock or an outdated entry in the app.
Check
- Time: The code is only valid for a short time. If your phone’s clock is off by more than about two minutes, the code won’t work. Set the time to update automatically.
- Correct entry: If you’ve turned two-factor authentication off and then back on, only the most recent entry in the app is valid.
- Method: The store uses SHA512. If you entered the key manually, check this setting in the app.
- Empty field: “Missing one-time code” means the field was submitted empty.
Lost phone, app deleted
Only the user themselves can reset two-factor authentication under My Account. There is no button that allows another administrator to disable it for someone else’s account.
- If the user has a trusted device on which the store does not ask for the code, they should log in there and disable two-factor authentication under “My Account” or set it up again.
- Otherwise, please contact our support team. Until then, the user cannot work in the backend; a new password won’t help, as the code will still be required.
Trusted Devices
If a user checks the “Trust this device for 30 days” box when entering a one-time code, the store will not ask for the code again on that device and in that browser for 30 days. A username and password are still required.
List of Devices
Under Settings → Administrators → Trusted Devices, you’ll find all saved devices listed with “Administrator,” “Device,” “IP Address,” “Created On,” “Last Used,” and “Valid Until.” Each user sees their own devices; members of the “Admins” group see the devices of all employees. The store remembers a maximum of 5 devices per account; when a sixth device is added, the oldest one is removed.
Remove Devices
Clicking “Delete” in the row removes a single device (after confirming with “Remove”); “Remove All Devices” removes all visible devices. The store will ask for the code again on these devices the next time the user logs in. Remove devices if a laptop is lost, an employee leaves the company, or a device in the list appears unfamiliar to you. To do this, the group must have the “Delete” permission on this page.
The saved devices with expiration dates: Remove individual devices using “Delete,” and all visible devices at once using “Remove All Devices.” Click to enlarge.
Forgotten and Changing Passwords
Anyone can reset a forgotten password themselves using a link sent by email. The previous password remains valid until you save a new one.
Forgot Password
- On the login page, click “Forgot your password?”
- Enter the email address associated with the user account. The username will not work here.
- Open the link in the email. It is valid for 30 minutes by default and can only be used once.
- Under “Set a new password,” enter the new password twice and click “Save password.”
Didn’t receive an email?
- The page always displays the same message, even for an unknown address. Check to make sure you entered the email address associated with your user account, and check your spam folder.
- The store will send a new link for the same account no sooner than 20 minutes later.
- If you no longer know the registered email address, a colleague with access to the user accounts can set a new password, or contact our support team.
Set a password for a colleague
Go to Settings → Administrators → User Accounts, select “Edit” from the action menu, set “New Password” to Yes, enter the password twice, and click “Update.” The store does not send an email for this. Share the password securely or have the colleague use the “Forgot Password” feature. Each person can change their own password under My Account by selecting “Change Password.”
| Setting under Settings → Privacy → Password Policies | Effect | New stores |
|---|---|---|
| “Password Policies: Minimum Length” | Minimum number of characters | 8 |
| “Password Guidelines: Numbers,” “… lowercase letters,” “… uppercase letters,” “… special characters” | At least one character of each type | All set to true |
| "Admin Password Reset: Feature Enabled" | “Forgot Password” in the backend. If set to false, only an administrator can set new passwords. | true |
| "Admin Password Reset: Link Validity (minutes)" | How long the link in the email is valid: 5 to 1,440 minutes | 30 |
These guidelines apply to passwords that you assign manually in the backend and to the “Forgot Password” feature. The rules regarding renewal after a certain number of months and the locking of old passwords within the same group apply only to customer accounts in the store. You can replace an automatically generated password with your own when you log in for the first time.
Session Duration and Automatic Logout
The store logs users out if there is no activity for a while. This protects the backend if someone steps away from their computer. If you feel this happens too soon, extend the duration.
Set Duration
Under Settings → Privacy → General → Admin Session Timeout (seconds), you can specify after how many seconds without a click the session ends. New stores are set to 3600, which is one hour. 7200 is two hours, and 14400 is four hours.
Setting this to 0 disables automatic logout. We do not recommend this, especially on computers used by multiple people.
IP Check
Under Settings → Privacy → General → Admin Session IP Verification, set the value to “true” to end the session as soon as the IP address changes significantly—for example, when switching from office Wi-Fi to a mobile network or when enabling a VPN. The store tolerates minor changes within the same connection. This check is disabled by default. Leave it disabled if your team works on the go or across different networks.
Session duration and backend IP verification can be found under Privacy → General, along with the help text explaining the time values in seconds. Click to enlarge.
Other reasons for logging out
| What happened | Why | Solution |
|---|---|---|
| Message: “Your session has expired for security reasons.” | The set duration without a click has elapsed. | Extend the duration. After logging in, you’ll be redirected to the page you were on. Any unsaved entries will be lost. |
| Message: “… because your IP address has changed.” | IP verification is enabled, and you’ve switched networks. | Turn off IP verification or stay on the same network |
| Logged out without a message while someone else is using the same account | If the number of employee accounts in your plan is limited, an account is valid in only one browser at a time. Logging in from another location ends the previous session. | One account per person; do not work in two browsers at the same time |
| Everyone logged out at once | Someone has saved permissions or locked or deleted an account. | Log in again; make such changes during quiet times |
| Logged out on other devices | You saved this under " My Account." This ends your logins on other devices. | Sign in again there |
| Logged out after closing the browser | Your session remains active only as long as the browser is open. | Log in again |
If the store continues to log you out prematurely despite extended sessions, please contact us. We’ll then check the server settings as well.
If you can’t log in
The login page usually explains exactly what the problem is. This table will help you figure it out.
| You’ll see | Meaning | Solution |
|---|---|---|
| “Incorrect username, email address, or password!” | The username or password is incorrect. | Log in using the account’s email address; the username can only be used if “Admin Login Alias” is enabled. Otherwise, reset your password. |
| “User account locked!” | The account is locked. | A colleague with the “Lock User Account” permission can unlock it; see Locking. |
| “Invalid one-time code,” “Missing one-time code” | The code from the app is missing or does not match. | See “Code does not match” |
| A blank white page instead of the backend | After several failed attempts, the store blocks login attempts from your IP address for a short time—up to ten minutes. This affects everyone using the same network connection, such as the entire office. | Wait, then log in with the correct information. Each additional failed attempt will extend the duration of the next lockout. |
| “Invalid security token. Please reload the page and log in again.” | For example, the login page was left open for too long. | Reload the page and log in again |
| “This account is currently being used on another device or in another browser.” | The account is logged in elsewhere. If you log in, the session there will end. | Confirm if that’s you; otherwise, change your password |
| “Connection to the XONIC authentication server failed.” after logging in | A verification check with our server failed. You are still logged in. | Continue working. If this message persists, please contact us. |
After changing your login credentials
If you’ve changed your email address, log in with the new one. Replace any old password saved in your browser. If you enabled two-factor authentication when saving your information under “My Account,” you’ll now need the code from the app.
Login Takes a Very Long Time
After logging in, the store clears old history data and regularly optimizes the database—by default, every 30 days. This login process takes longer. Set Settings → General → Maintenance → Archive Data Deletion on Login - Number of Days to 1 or higher: If set to 0, the store clears data every time you log in, and for large stores, this can cause the login process to time out.
Absence and Substitute
Enter vacation, sick leave, or parental leave in the ticket system, not in the user account. The account remains active.
Under Tools → Tickets & Tasks → Absence & Vacation Mode, you can set the time period and designate a substitute. If a ticket is assigned to an absent person, the shop will automatically enter the substitute’s information and, if requested, notify the customer. Details are available under Tickets & Tasks.
If someone leaves the company, simply marking them as absent is not enough: Lock the account; see Locking.
Who made what changes?
With individual accounts, you can track who did what. You can see this for yourself in these locations.
| What | Where |
|---|---|
| Who is currently logged in, when someone was last online, and how often they’ve logged in | Settings → Administrators → User Accounts, columns showing online status and “Logins” |
| When your account was created and last modified | My Account, at the bottom: “Account Created,” “Logins,” and “Last Modified” |
| Who set a status or wrote a comment on an order | Order history, with name and date/time for each entry |
| Who replied to a ticket or changed the assigned person | Ticket history |
| Who changed which fields for products, settings, or orders, and when | The store saves these changes along with the user who made them and the time. Our support team will analyze this data for you. |
| Logins, failed login attempts, and logouts, including the time and IP address | Security log on the server. If any suspicious activity is detected, our support team will analyze it. |
The store automatically deletes log files on the server after the retention period expires; by default, this is one month.
Data Protection and Responsibility
Your employees can view your customers’ names, addresses, and orders in the backend. Who is allowed to see what is therefore also a matter of data protection.
As little as necessary
Grant each group only the pages they need. A temporary shipping assistant needs access to orders, but not to customer exports or settings. Review permissions whenever tasks change.
Separate Accounts, Two-Factor Authentication
A shared account for multiple people obscures who did what and cannot be locked down for a single person. Set up two-factor authentication for every account, starting with the “Admins” group.
External Service Providers
If an agency, tax firm, or freelancer works in the backend, create a separate account for them with its own group and deactivate it after the job is complete. If service providers view your customers’ personal data, you generally need a data processing agreement under Article 28 of the GDPR. Please consult your data protection advisor for details.
Checklist for Hiring and Termination
New Employee
- Appropriate user group selected or created
- Separate account created with a unique email address
- The group has “Page Access/Read” and “Edit” permissions for “My Account”
- Password changed upon first login
- Two-factor authentication set up and tested
- Created signatures and, if used, “Sender (Avatar)” in the ticket system
Employee is leaving the company
- Lock the account on the employee’s last day of work
- Remove the account’s trusted devices
- Reassign open tickets and tasks
- Change any login credentials the person knew, such as those for directory protection under Settings → Administrators → .htaccess Protection
- Delete the account once these steps are complete
Frequently Asked Questions
How do I create a new user for the backend?
How do I grant a staff member full admin rights?
How do I restrict an employee to orders and quotes?
A new employee is missing a feature. Why is that?
Most often, their group lacks permission for that page. Go to Settings → Administrators → User Groups, open the group’s “Access Rights,” search for the page (including under “Additional Areas (without menu item)”), and grant “Page Access/Read” along with the necessary additional permissions. Also check whether the account is assigned to a group at all and whether someone has hidden the menu item.
If a group is allowed to edit orders or items but does not have access to the corresponding editor, Tools → Server Info & Health Check will report this and offer to restore the permissions.from 4.9.24
Can I grant the delete permission only for package labels?
Can I hide individual fields from employees?
How do I give third parties access to customer notes without granting them full permissions?
How do I reset another user’s two-factor authentication?
The code from the app is no longer accepted. What should I do?
How do I reset my password for the backend?
Why can’t I access the backend anymore?
How do I reactivate a locked account?
Where do I set the time after which the backend automatically logs me out?
I can’t log in after changing my login credentials. Why?
How do I keep the “Tickets” tile and the menu permanently expanded in the dashboard?
Can I see who made a change?
Additional Guides
We provide assistance with permissions and access
We work with you to set up user groups for your team, help if someone can no longer access the backend, and analyze the logs in case of suspected issues.
Contact Support Now