# Users and Permissions

# Users and Access

# Users and Access

<h2 id="bkmrk-overview">Purpose and security boundary</h2>

Use user records to give one person an identifiable Brisk sign-in and only the access required for that person's work. User administration is restricted setup work. Never copy passwords, recovery codes, API tokens, or customer information into documentation or support notes.

<h2 id="bkmrk-list">Review users</h2>

<figure class="brisk-doc-media"><img src="https://help.brisksystems.us/uploads/images/gallery/2026-08/article-modelsetupuser-list-users.png" alt="Brisk Users and Access list screen displayed with fictional documentation-demo data." loading="lazy" style="max-width:100%;height:auto;"><figcaption>The Users and Access list screen in the Brisk documentation demo.</figcaption></figure>

Open **Setup → Users** and review active accounts regularly. Investigate accounts that no longer have an owner or need. Use the user's detail page to review their profile before changing access.

<h2 id="bkmrk-create">Create a user</h2>

<figure class="brisk-doc-media"><img src="https://help.brisksystems.us/uploads/images/gallery/2026-08/article-modelsetupuser-create-user-create.png" alt="Brisk Users and Access create screen displayed with fictional documentation-demo data." loading="lazy" style="max-width:100%;height:auto;"><figcaption>The Users and Access create screen in the Brisk documentation demo.</figcaption></figure>

1. Create a distinct account for the person; do not share a generic sign-in.
2. Enter the required identity and sign-in fields.
3. Assign only reviewed groups and permissions for the person's job.
4. Set an initial password through the protected password workflow, then have the user configure account security.
5. Test a representative task as that role without exposing another user's session or credentials.

<h2 id="bkmrk-detail">View a user</h2>

The detail page is the starting point for profile, access, preference, and password administration. Treat staff and superuser flags as elevated access, not convenience settings.

<h2 id="bkmrk-update">Update a user</h2>

Change identity or access only with authorization. Removing access can interrupt current work; adding broad access can expose financial or administrative functions. Record the business reason using your organization's access-review process.

<h2 id="bkmrk-preferences">Manage another user's settings</h2>

User preference pages change account-specific Brisk behavior. Adjust only the relevant section, and distinguish user preferences from system-wide settings before saving. See the [User Preferences Reference](https://help.brisksystems.us/link/2964#bkmrk-overview) for every preference grouped by its screen section.

<h2 id="bkmrk-password">Change a user's password</h2>

Use the dedicated password action. Do not transmit a reusable password through ordinary notes or documentation. Follow the organization's identity-verification and secure-delivery procedure.

<h2 id="bkmrk-delete">Remove or disable access</h2>

Historical records may refer to a user, so deletion can be inappropriate or blocked. Prefer the approved deactivation process where audit history must remain attributable.

<nav class="brisk-doc-navigation" aria-label="Related Brisk documentation">
<h2>Navigation</h2>
<h3>In this module</h3>
<ul>
<li><a href="https://help.brisksystems.us/link/2765">Return to setup and administration</a></li>
</ul>
</nav>