Team Management
Team Management lets Admins control who has access to AlchemOS Positive, what they can do, and which sites and data they can see.
User roles
| Role | What they can do |
|---|---|
| Admin | Full access: settings, user management, all data, approval workflows |
| Manager | Submit and approve entries, manage calculators, generate reports; cannot change settings |
| Data Entry | Create and submit emission entries, run calculators; cannot approve |
| Read Only | View dashboards, reports and entries; no write access |
| Auditor (external) | View all entries, evidence documents and audit logs; cannot modify any data |
Inviting a new user
- Go to Settings → Team → Invite User
- Enter the user's email address
- Select their role
- Optionally restrict their access to specific sites / locations
- Click Send Invitation
The user receives an email with a secure invitation link valid for 7 days. If they do not accept within 7 days, resend using Actions → Resend Invitation from the user list.
Bulk invite
To invite multiple users at once:
- Settings → Team → Bulk Invite
- Upload a CSV with columns:
email,role,locations(comma-separated) - Preview the list then click Send All Invitations
Managing existing users
Go to Settings → Team to see all users.
| Column | Description |
|---|---|
| Name | Full name (once accepted) |
| Role | Current role assignment |
| Locations | Site access restriction or "All" |
| Last login | Most recent sign-in timestamp |
| Status | Active / Pending / Suspended / Deactivated |
Changing a user's role
Click the user row → Edit → change the Role dropdown → Save.
Role changes take effect on the user's next page load.
Restricting site access
If your organisation has multiple sites, you can limit a user to specific sites:
- Click the user row → Edit
- Under Location Access, uncheck All Locations
- Select the specific locations the user can see
- Save
A user with restricted location access will only see entries, reports and dashboards scoped to their allowed locations.
Suspending users
Suspending prevents login without deleting the user account or their data:
- Click the user row → Actions → Suspend
- Confirm with a reason
Suspended users receive an email notifying them of the suspension. Reactivate at any time from the same menu.
Deactivating users
Deactivation is permanent removal of access while preserving all data the user created (required for audit integrity):
- Click the user row → Actions → Deactivate
- Confirm
Deactivated users cannot log in and do not appear in the active user list. Their entries, reports and evidence uploads remain intact. This is the correct procedure when an employee leaves.
Teams (groups)
Create named teams to manage location restrictions and notification routing across groups of users:
- Settings → Teams → New Team
- Give the team a name (e.g., "UK Operations", "Finance Group")
- Assign members
- Set location restrictions for the team
Individual location overrides take precedence over team settings.
Audit log
A full audit log of all access-control changes is available at Settings → Audit Log:
- User invited / accepted / deactivated
- Role changed
- Location restriction changed
- MFA reset