Users & Roles
Create users, assign roles, and control exactly who can see and do what.
Role-Based Access Control
DEBMEDIA ERP uses deny-by-default RBAC. A new user with no role assigned cannot see any tab. All access must be explicitly granted via a Role.
Managing Roles
- Open the Roles & Permissions tab.
- Select an existing role or click New.
- The permission matrix shows every module and screen with checkboxes for each action (View, Create, Edit, Post, Cancel, Print, Export).
- Check the actions to allow. Uncheck to deny.
- Save. Users with this role get the new permissions immediately on their next action.
Managing Users
- Open the Users tab → New.
- Enter Username, Full Name, and an initial password.
- Assign one or more Roles.
- Save. The user can log in immediately.
Change the default admin password immediately. The out-of-box password
Admin@123 is documented here. The system forces a change on first login, but verify it was done before going live.Security Features
| Feature | Behaviour |
|---|---|
| Failed login lockout | Locks after 5 consecutive failed attempts |
| Unlock account | Admin opens Users tab → selects user → Unlock Account |
| Force password change | Set "Must Change Password" on the user — they are prompted at next login |
| Change own password | Menu → Account → Change Password... |
Login History
Open the Login History tab. Every login attempt is logged — username, timestamp, success or failure, and the failure reason. Use this to detect unauthorised access attempts.
Audit Log
Open the Audit Log tab. Shows every data change with the user, timestamp, old value, and new value. The audit log is immutable — not even the administrator can delete entries.