Overview
User Accounts are the foundation of security in GSK POS. Each person who accesses your system needs their own account with an appropriate role that defines what they can do.
What you'll learn:
- Using the modern user card interface
- Creating and managing user accounts
- Activating and deactivating users
- Understanding roles and permissions
- Editing and deleting users
- Best practices for user management
Why it matters:
- Security - Control who accesses your business data
- Accountability - Know who did what
- Efficiency - Give staff appropriate access
- Audit Trail - Track all user actions
The User Management Interface
GSK POS features a modern split-view interface for managing users:
Left Panel - Add New User
Form to create new user accounts
- Email field
- Password field
- Role selection
- Phone (optional)
Right Panel - User Cards
List of all users as cards
- Avatar icon
- Email/Username
- Role badge
- Status badge
- Action buttons
Status Badges
- ✅ Active (green) - User can log in and use the system
- 🚫 Inactive (red) - User cannot log in (account suspended)
- 🛡️ Protected - Admin account - cannot be modified
Statistics Header
At the top of the user list, you'll see:
- Total Users - Count of all accounts
- Active Users - Count of users who can log in
What Are User Accounts?
A user account represents an individual person who can log into GSK POS. Each account consists of:
Required Information:
- Username - Unique login identifier (e.g., "john", "mary", "cashier1")
- Password - Secure authentication credential
- Role - Defines permissions and access level
Optional Information:
- Email - For notifications and password resets
- Phone - Contact information
What Are Roles?
A role defines what a user can do in the system. Think of roles as job titles with specific permissions attached.
**Common Roles**
Admin 👑
- Full system access
- Can manage users and permissions
- Access all features and reports
- Use for: Business owner, IT manager
Manager 👔
- Most business operations
- Process sales and purchases
- View reports
- Manage customers and suppliers
- Cannot manage users or change critical settings
- Use for: Shop managers, supervisors
Cashier 💰
- Sales processing only
- Add customers
- View stock levels
- Cannot access reports or settings
- Use for: Front desk staff, sales clerks
Stock Clerk 📦
- Inventory management
- Process purchases
- Adjust stock
- Manage suppliers
- Cannot process sales
- Use for: Warehouse staff, inventory managers
Accountant 📊
- Read-only access to reports
- View financial data
- Export reports
- Cannot modify transactions
- Use for: Accountants, auditors
Creating a New User
**Prerequisites**
- ✅ You must be Admin or have "User Management" permission
- ✅ Decide username, temporary password, and appropriate role
**Step-by-Step Process**
Step 1: Access User Management
- Log into GSK POS
- Click "User Accounts" in the sidebar menu
- User registration form appears
Step 2: Enter User Information
Username (Required)
- Any name you prefer
- Must be unique in your system
- No special format required
- Examples:
john, mary_smith, cashier1, manager_kampala
- Tips:
- Use first names for small teams
- Add numbers for multiple people with same name
- Use role-based names for generic accounts
Password (Required)
- Any length accepted (8+ characters recommended)
- User should change after first login
- Make it memorable but secure
- Examples:
Welcome123, TempPass2024
- Tips:
- Don't use the same password for everyone
- Include numbers and symbols
- Avoid common words
Role (Required)
- Select from dropdown menu
- Choose based on job responsibilities
- Available roles:
- Admin (full access)
- Manager (most features)
- Cashier (sales only)
- Stock Clerk (inventory only)
- Accountant (reports only)
- Custom roles (if configured)
Email (Optional)
- Valid email format required if provided
- User receives welcome email with login details
- Example:
john@example.com
- Benefits:
- Automatic welcome email
- Password reset capability
- System notifications
Phone (Optional)
- Any format accepted
- For contact purposes only
- Examples:
+256700123456, 0700123456
Step 3: Create Account
- Review all information
- Click "Create User" button
- System validates:
- Username doesn't already exist
- Email format is correct (if provided)
- All required fields completed
- Success message appears
- If email provided, welcome email sent automatically
Step 4: Welcome Email Sent
The new user receives an email with:
- Welcome message
- Their username
- Their temporary password
- Link to login at gskpos.com
- Instructions to change password
- Link to video tutorials
Step 5: Inform the User
- Give them username and password (if no email)
- Tell them to change password on first login
- Show them how to access the system
- Explain their role and what they can do
- Provide link to documentation
Viewing All Users
**Access User List**
Method 1: View All Users Button
- Go to User Accounts menu
- Click "View All Users" button
- Complete user list displays
Method 2: After Creating User
- List automatically shows after user creation
- Refresh to see latest changes
**Information Displayed**
The user list shows:
| Column | Description |
| Username | Login identifier |
| Email | Contact email (or "N/A" if not provided) |
| Phone | Contact number (or "N/A" if not provided) |
| Role | Current role with dropdown to change |
| Actions | Edit and Delete buttons |
Special Cases:
- "admin" user - Cannot be edited or deleted (system protection)
- Your own account - Cannot delete yourself
- Inactive users - Show normally (no separate inactive status)
Editing an Existing User
**What Can Be Changed**
- ✅ Email address - Update contact information
- ✅ Phone number - Update contact information
- ✅ Role - Change user's permissions
- ❌ Username - Cannot change (permanent identifier)
- ❌ Password - Users change their own passwords
**How to Edit**
Step 1: Open User List
- Go to User Accounts
- Click "View All Users"
- Locate user to edit
Step 2: Make Changes
Edit Email:
- Click in email field
- Type new email address
- Press Enter or click outside field
- Changes save automatically
Edit Phone:
- Click in phone field
- Type new phone number
- Press Enter or click outside field
- Changes save automatically
Change Role:
- Click role dropdown
- Select new role
- Changes apply immediately
- User's permissions update automatically
Step 3: Finalize
- Click "Edit" button to save all changes
- Or changes save automatically on field exit
- Confirmation message appears
- User list updates
**Role Change Impacts**
⚠️ Consider before changing roles:
Promoting (More Access):
- Cashier → Manager
- Gains: Report access, settings, more features
- Can now see financial data
- Stock Clerk → Manager
- Gains: Sales processing, reports
- Can now interact with customers
- Any → Admin
- Gains: Full system access
- Very powerful - be careful!
Demoting (Less Access):
- Manager → Cashier
- Loses: Reports, settings, some features
- May lose access to current work
- Admin → Manager
- Loses: User management, critical settings
- Consider implications carefully
- Manager → Stock Clerk
- Loses: Sales, reports
- Limited to inventory only
Best Practice: Inform user before changing their role so they understand what changes.
Activating & Deactivating Users
Instead of deleting users, you can deactivate them temporarily. This is useful when:
- Employee is on leave
- Temporary suspension needed
- Want to keep their history but prevent access
How to Toggle User Status
To Deactivate (Active → Inactive)
- Find user card (green "Active" badge)
- Click Toggle button (circle icon)
- Confirm the action
- Badge changes to red "Inactive"
- User can no longer log in
To Reactivate (Inactive → Active)
- Find user card (red "Inactive" badge)
- Click Toggle button (check icon)
- Confirm the action
- Badge changes to green "Active"
- User can log in again
Benefits Over Deleting:
- Can be undone - Reactivate anytime
- History preserved - All records remain
- Quick to reactivate - No need to recreate account
- Safer choice - Use for temporary changes
Deleting a User Account
**When to Delete**
- ✅ Delete when:
- Employee permanently leaves company
- Account created by mistake
- Temporary account no longer needed
- Security breach requires recreation
- ❌ Don't delete if:
- Employee on temporary leave (consider disabling instead)
- You need historical activity records
- Unsure - ask first!
**Important Warnings**
- 🚨 Deletion is permanent and cannot be undone!
What happens when you delete:
- User immediately cannot log in
- Account removed from user list
- Historical activity logs remain (for audit)
- Username can be reused for new account
- All past transactions still show their username
What doesn't happen:
- Past sales/purchases are NOT deleted
- Reports still show their name
- Activity logs remain intact
System Protections:
- Cannot delete "admin" account
- Cannot delete your own account
- Must have proper permissions to delete
**How to Delete**
Step 1: Confirm Decision
- Are you sure?
- Have you informed management?
- Is there a better alternative?
Step 2: Access User List
- Go to User Accounts
- Click "View All Users"
- Find user to delete
Step 3: Delete User
- Click "Delete" button next to username
- Confirmation dialog appears:
- "Are you sure you want to delete [username]?"
- "This action cannot be undone"
- Click "Yes, Delete" to proceed
- Click "Cancel" to abort
Step 4: Verify Deletion
- Success message: "User deleted successfully"
- User disappears from list immediately
- They cannot log in anymore
- Refresh page to confirm
Step 5: Post-Deletion Tasks
- Inform relevant staff
- Update contact lists
- Reassign responsibilities
- Document reason for deletion (for records)
Best Practices
**Security Best Practices**
- 🔐 One Account Per Person
- Never share accounts
- Each person needs unique username
- Enables accountability
- Required for audit trail
- 🔐 Appropriate Roles
- Match role to job function
- Don't make everyone admin
- Use least privilege principle
- Review roles quarterly
- 🔐 Immediate Offboarding
- Delete account on employee's last day
- Don't wait "just in case"
- Change shared passwords if they had access
- Review their recent activity
- 🔐 Strong Passwords
- Enforce minimum 8 characters
- Require mix of letters/numbers
- Change every 90 days
- Never reuse old passwords
- 🔐 Limited Admin Accounts
- Only 2-3 admins maximum
- Business owner should be one
- IT/tech manager can be another
- Review admin list monthly
**Operational Best Practices**
- ✅ Consistent Naming
- Use standard username format
- Examples:
- First name:
john, mary
- Role + number:
cashier1, cashier2
- Location:
kampala_john, jinja_mary
- Easier to manage as you grow
- Create account day before start
- Send welcome email
- Personal walkthrough on first day
- Show password change process
- Explain role and permissions
- Provide documentation link
- Check in after one week
- ✅ Regular Audits
- Monthly: Review user list
- Remove departed employees
- Check roles still appropriate
- Look for unused accounts
- Document any changes
- ✅ Documentation
- Keep list of all users
- Document role assignments
- Note why each role chosen
- Record changes and dates
- Maintain offboarding records
**Training Best Practices**
- 📚 Initial Training
- Show them their accessible features
- Explain what they can/cannot do
- Demonstrate password change
- Provide documentation
- Assign mentor for questions
- 📚 Ongoing Support
- Regular check-ins
- Additional training as needed
- Update on system changes
- Encourage questions
- Share tips and tricks
- 📚 Role-Specific Training
- Cashiers: Focus on POS
- Stock clerks: Focus on inventory
- Managers: Comprehensive overview
- Admins: Full system training
Troubleshooting
**Cannot Create User - Username Exists**
Error: "Username already exists. Please choose a different one."
Cause: Another user (current or past) already has that username
Solutions:
- Add number:
john → john2
- Add location:
john → john_kampala
- Use different format:
john → j.smith
- Try variations until unique found
**Cannot Create User - Email Exists**
Error: "Email already exists"
Cause: That email is registered to another account
Solutions:
- Use different email
- Leave email blank (optional field)
- Check if person has multiple accounts
- Remove email from old account first
**User Cannot Login After Creation**
Possible Causes:
Wrong Password
- User typing incorrectly
- Caps lock enabled
- Password contains special characters they're missing
Wrong Username
- Username may be case-sensitive
- Extra spaces
- Typo
Account Not Created
- Check user list to verify
- Try creating again
Browser Issues
- Clear cache
- Try different browser
- Use incognito mode
**Cannot Delete User**
"admin" User
- Protected system account
- Cannot be deleted
- This is intentional
Your Own Account
- Cannot delete yourself
- Another admin must do it
- Security feature
No Permission
- You need admin or user management permission
- Ask admin to delete
**Role Change Not Working**
User Can't See New Features
- User needs to log out and back in
- Or refresh page
- Permissions update on new session
Changes Don't Save
- Check internet connection
- Try again
- Contact support if persists
Wrong Role Selected
- Verify correct role in dropdown
- Check role has expected permissions
- Role configuration may need adjustment
Summary
User Accounts & Roles are the foundation of GSK POS security:
- ✅ Create accounts - One per person, appropriate role
- ✅ Manage carefully - Edit when needed, delete when necessary
- ✅ Follow best practices - Security first, accountability always
- ✅ Regular audits - Monthly reviews keep system clean
Key Takeaways:
- Every person needs their own account
- Roles define what users can do
- Admin role is most powerful - limit carefully
- Delete departed employees immediately
- Document everything for audit trail
What's Next?
Continue learning about user management:
- Permissions System - Understanding how access control works
- Change Password - Keeping accounts secure
- User Activity Tracking - Monitoring system usage
Next: Sales & Purchase Reports
Learn how to generate detailed and summary reports for all your sales and purchase transactions.
Next: Sales & Purchase Reports →