Cargolake
Help & Guides/Account & access

Adding and managing users

Create user accounts, edit their details, reset passwords, and assign or revoke their roles.

Admin → Users lists everyone in your legal entity. From here you create accounts, edit them, change passwords and control what each person can do.

Creating a user

Users → New user. Five fields, all required:

FieldNotes
NameThe person's display name, shown throughout the app.
EmailTheir login. Must be unique.
New passwordThe initial password. Tell them to change it after first sign-in.
CountryChosen from the country list. Pick this before the phone field appears.
PhoneOnly appears once a country is chosen, and must start with that country's dialling code — choose Egypt and the number has to begin +20.

A newly created user has no roles and therefore no permissions. They can sign in, but their sidebar will be nearly empty until you assign a role. That is the next step, not an error.

If you would rather the person set their own password, invite them instead — see Inviting people to your company.

The user detail page

Opening a user shows their name and email, the roles they hold (each a link to the role), and when the record was created and last changed. The actions available from here are edit, change password, assign a role and revoke a role.

Editing a user

Update user changes name, email, country and phone. It does not touch the password — that is a separate action, so an ordinary detail edit can never reset someone's credentials by accident.

Passwords

There are two different password screens, and which one you get depends on whose password it is:

  • Your own (Settings → Update Password) asks for your old password and the new one.
  • Someone else's (from their detail page, as an administrator) asks only for the new password.

Set the new password, then tell the user out of band — the system does not email it.

Assigning and revoking roles

Roles are what actually grant permission; the user record itself grants nothing.

  • Assign adds a role to the user. Roles stack — a user with two roles can do everything either role allows. There is no way for one role to take away what another grants.
  • Revoke removes a role.

Both are permissioned actions in their own right, so not every administrator can perform them. Beyond the permission, a seniority check applies: you can only assign or revoke roles at or below your own level. See Building roles.

A role change does not take effect until the user signs out and back in. Their permission list is cached in the browser at sign-in. This catches people out constantly: the change was saved, the user simply has not picked it up yet.

Deleting a user

Deleting removes the account and with it the ability to sign in. Records the person created — shipments, quotations, invoices — remain; the system does not unwind their work.

Where someone has simply left the team, consider revoking their roles instead. That leaves an inert account behind with a clear history rather than a gap.

Common problems

SymptomCause
"Phone must start with +XX"The phone number does not match the selected country's dialling code.
The phone field will not appearNo country selected yet.
The new user sees an empty sidebarNo roles assigned.
A role was assigned but nothing changedThe user needs to sign out and back in.
User already existsAnother account already uses that email.
New password must be different from old passwordReusing the current password is refused.
Old password is incorrectOn a self-service password change.
You can only assign roles with lower privilege levels than your ownThe role is more senior than yours.
User already belongs to a legal entityA user belongs to exactly one company; they cannot be added to a second.
Seat limit reachedThe subscription is full — see Your company.

Last updated 13 September 2026