---
title: "User Management"
source: /gcxone/admin-guide/user-management
locale: en
updated: 2026-09-14
---
## **What User Management Does**

User Management in GCXONE controls who can access the platform, what they can see, and which entities they can interact with. Every user is scoped to a tenant and inherits access from their assigned role — with the option to override or extend that access per user without modifying the shared role.

## **Why It Matters**

Without properly configured users, operators may see entities they shouldn't, or be blocked entirely. User Management ensures the right people have the right access — and that access is immediately revocable when needed.

## **How It Works**

**Prerequisites:** Complete your role structure before inviting users. See Roles & Permissions.

### Inviting a New User

Open **Settings** (the gear icon at the bottom of the left-hand sidebar) → **Users** → **\+ Invite New User.**

The invite form has three sections:

- **Personal Information** — optional photo upload, First Name\*, Last Name\*, Email Address\*, Phone Number.
- **Address Information** — Street Name, Building Number, Zip Code, City, Country (all optional).
- **Account Settings** — **Genesis Role\*** and **GCXONE Role\*** (two separate required role dropdowns — a user needs both), Customer Group, Session Timeout in minutes (default 30, range 30–1440), **Enable Partner Login** toggle, **Enable Multi-Factor Authentication** toggle.

![Invite New User](/api/media/file/Screenshot-2026-09-07-154026-edited-c2b2658f.png?prefix=media)

Click **Send Invitation.**

What email the invited address gets depends on whether it already has an NXGEN account: a **new email address** gets two emails ("Email Verification GCX One Application" to confirm the address, then "Reset Password Link for the nxgen Application" to set a password), while an email that **already has an NXGEN account** (e.g. an existing user added to a second tenant) gets a single "Welcome to NXGEN – Access to \[Tenant\] Granted!" email telling them to sign in with their existing password. Either way, the user's status shows **Active** immediately.

Entity access (which customers/sites/devices the user can see) is not set on this form — configure it after the user exists, in **Configuring Entity Access Per User** below.

### Configuring Entity Access Per User

A user inherits entity access from their assigned role. You can override or extend this per user without modifying the shared role.

Navigation: **Settings → Users → \[User\] → Actions (⋮) → Edit User Entities**

- **Override** — Replaces the user's role-inherited entity access entirely. Example: Operator role grants Customer A. Override with Customer B → user can only see Customer B.
- **Merge** — Adds entity access on top of what the role grants. Example: Operator role grants Customer A. Merge in Customer B → user can see both. Use for temporary cross-coverage or one-off access.

Enable **Include Children** on a parent entity to automatically include all of its current and future sub-entities, instead of selecting them one by one.

The dialog also has a **Select Entity Group** dropdown to apply a saved group of entities in one step instead of hand-picking them in the tree view — entity groups are managed separately under **Settings → Entity Groups.**

![1](/api/media/file/Screenshot-2026-09-08-104210-edited-acfc4d0d.png?prefix=media)

**Best Practice:** Prefer Merge over creating a new role when the access requirement is temporary or user-specific. Use Override only when you need to fully restrict to a different entity set.

### Editing an Existing User

1. Navigate to **Settings → Users.**
2. On the user's row, open **Actions (⋮) → Edit User.**
3. The same fields as the invite form open pre-filled: photo, name, email, phone, address, Genesis Role, GCXONE Role, Customer Group, Session Timeout, Partner Login, and MFA.
4. Click **Update User.** Changes take effect immediately — the user's next action reflects the new access.

![0](/api/media/file/Screenshot-2026-09-08-104501-edited-3568eb60.png?prefix=media)

### Multi-Factor Authentication Setup

When **Enable Multi-Factor Authentication** is toggled on for a user — whether at invite or via Edit User — that user is prompted to set up MFA the next time they log in. The **Secure Your Account** screen asks them to scan a QR code with their preferred authenticator app, then enter the resulting one-time code to continue.

![Invite New User dialog with Enable Multi-Factor Authentication toggle highlighted](/api/media/file/Screenshot-2026-09-14-132303-edited-1f7f342f.png?prefix=media)

![Secure Your Account QR code setup screen](/api/media/file/image-1--edited-84c290d3.png?prefix=media)

### Remove User

1. **Settings → Users → \[User\] → Actions (⋮) → Remove User.** This runs immediately with no confirmation step — the user disappears from the User List as soon as you click it. Double-check you have the right row selected first.

## **Key Capabilities**

### User Status Reference

The Status column in the User List shows **Active** (green) for most users, or **Inactive** (red) for a user blocked from logging in. A newly invited user shows Active immediately, even before they've verified their email or set a password.

### Multi-Tenant User Management

Users are scoped per tenant. A user in Tenant A has no visibility into Tenant B unless a separate account is created in Tenant B.

To switch tenants as an admin: **Settings → Switch Tenant.**

![11](/api/media/file/Screenshot-2026-09-08-110932-edited-5e36826b-1.png?prefix=media)

## **Real-World Use Cases**

- A new operator joins the team — admin invites them, assigns the Operator role, and they're operational within minutes.
- An Operator needs temporary access to a second site during staff shortage — admin uses Merge instead of creating a new role.
- A departed employee's access is revoked instantly via Remove User.

## **Best Practices**

- Always complete role configuration before inviting users — a user with no role lands on a blocked screen.
- Use **Merge** for temporary or user-specific access rather than creating one-off roles.
- Remove User has no confirmation step — confirm you have the right row before clicking it.