Every person who touches iPM should have their own account. It's a small amount of setup that pays off the first time you need to know who actually changed a check or acknowledged an alert — something a single shared admin login can never tell you.
Creating a user
- Go to Administration, then Users.
- Add a new user with their name, email, and an initial password (or an invite, if your setup supports one).
- Assign a role — see Roles & Permissions for what each option actually allows.
- Save. The new user can now log in with their own credentials.
Why not just share the admin login
Beyond the audit trail problem, a shared login means everyone effectively has full administrative access whether they need it or not, and there's no clean way to remove access for one person without changing the password for everyone. Individual accounts avoid both problems.
When someone leaves the team
Deactivate the account rather than deleting it outright, where that option is available. A deactivated user can no longer log in, but the history of what they did — checks they created, alerts they acknowledged — stays intact, which matters if you ever need to look back at who configured something.
Password resets
Users should be able to reset their own password through the standard login flow. As an administrator, you can also reset a user's password directly under Administration if they're locked out, without needing to know their existing one.
Once accounts exist, the next step is making sure each one has the right level of access — covered in Roles & Permissions.