31.1 Staff Members Overview

Staff Members allow an organization to provide individual users with access to the AIUNIFY Leads management workspace.

Instead of sharing one administrative account, each team member can have an individual record with their own identifying information, account status, login setting, and applicable Role.

Security principle: Use individual Staff Member accounts instead of shared credentials so access can be changed for one person without affecting the rest of the team.

31.2 Staff Member Permissions

Staff management is permission-controlled. The permission structure includes:

Permission Purpose
staff_members_view Allows access to the Staff Members workspace and records.
staff_members_create Allows creation of Staff Members.
staff_members_edit Allows editing Staff Members.
staff_members_delete Allows deletion of Staff Members.
assign_role Controls whether a user can assign login access and Roles through the Staff Member workflow.

Administrative access can also provide applicable capabilities.

31.3 Information Stored for Staff Members

The confirmed Staff Members interface works with information including:

  1. Name.
  2. Email.
  3. Profile Image.
  4. Phone.
  5. Address.
  6. Status.
  7. Role.
  8. Allow Login.
  9. Created date/time.

31.4 Creating a Staff Member

When creating a Staff Member, Name, Email, and Status are required by the confirmed server validation.

The Email must be valid and must not duplicate another applicable Staff Member or Super Administrator account.

31.5 Phone Number Format

The standard Staff Member form accepts Phone as an optional value.

When supplied, the confirmed validation requires the number to include the country code and the leading + sign.

For example:

+15551234567

31.6 Staff Member Status

Status is stored independently from the Allow Login setting.

The normal Staff Member status options are:

  1. Active.
  2. Inactive.

Review both Status and Allow Login when changing a person's access.

31.7 Allow Login

Allow Login determines whether the Staff Member is permitted to authenticate into AIUNIFY Leads.

If a Staff Member attempts to sign in while Allow Login is disabled, the confirmed application response is:

You are not allowed to login. Please contact administrator.

31.8 Role and Password Requirements

For users authorized to assign Roles, enabling Allow Login introduces additional requirements.

When a new Staff Member is allowed to log in:

  1. A Role is required.
  2. A Password is required.
  3. The Password must contain at least 8 characters.

When editing an existing Staff Member, a new Password is only required in the circumstances defined by the account state—for example, when login is being enabled for an account that does not yet have a Password.

31.9 Assign Role Permission

The confirmed Staff Member workflow specifically limits changes to Allow Login and Role assignment to users with the assign_role capability or administrative authority.

A user without that authority cannot use the Staff Member form to grant login access or assign a Role.

31.10 Role Attachment

When an authorized user assigns a Role to a Staff Member with login enabled, AIUNIFY Leads associates that Role with the Staff Member.

If login is disabled, the standard Staff Member update logic does not keep an active Role assignment for that login workflow.

31.11 Protecting Administrative Access

The user-management logic includes safeguards intended to prevent an organization from accidentally removing its only administrator's Role.

Use additional care when modifying administrative Staff Members.

Best practice: Before changing an administrator's Role or access, verify that another authorized administrator can still manage users and permissions.

31.12 Viewing Staff Member Details

The Staff Member detail presentation can display information such as:

  1. Name.
  2. Email.
  3. Phone.
  4. Role.
  5. Created date/time.
  6. Address when available.

31.13 Editing Staff Members

When editing a Staff Member:

  1. Confirm you opened the intended person.
  2. Review Name and Email.
  3. Review Phone and Address if used.
  4. Review Active or Inactive Status.
  5. If authorized, review Allow Login.
  6. If login is allowed, verify the correct Role.
  7. Only enter a new Password when it should actually be changed or is required to enable login.
  8. Save and verify the resulting access.

31.14 Deleting Staff Members

Deletion should be used only when the Staff Member record should be removed.

For temporary access restrictions, changing the account's Status or disabling login may be more appropriate than deleting the record.

31.15 Recommended Staff Access Workflow

  1. Create a separate Staff Member for each person.
  2. Use the person's correct business Email.
  3. Decide whether the person needs workspace login access.
  4. If login is needed, assign the minimum Role required for their responsibilities.
  5. Use a secure Password of at least the required length.
  6. Review Staff Member access whenever responsibilities change.
  7. Disable access promptly when it is no longer required.
Write Your Comment