ANTE User Manual

Settings & Administration FAQ

Common questions from the people who set ANTE up and keep it running β€” giving colleagues access, deciding what each of them can do, recording your company and its locations, connecting outside services, and checking afterwards who changed what. Each answer points to the page where the work is actually done.

Users & Access

How do I give a new person access to ANTE?

Two ways, and they end in the same place. On Users you can open Actions β†’ Add User and fill in the account yourself, including the first password β€” the person is then forced to replace that password the first time they sign in. Or, on User Invitations, you click Invite User and ANTE emails them a link so they set up their own account. Either way you must choose a Role, because that is what decides everything the person can see and do.

When should I invite someone instead of creating the account myself?

Invite when the person is available to finish the setup themselves β€” it saves you from handling a temporary password, and they choose their own from the start. Create the account directly when you need it to exist immediately, or when the person can't act on an email right away. Invitations are valid for 7 days; while one is still pending you can Resend or Cancel it from the invitations list, and once it's accepted the person disappears from that list and appears on Users instead.

Why can't I see a user or a role that I know exists?

Because visibility follows the role hierarchy. Every role sits at a Level (0 is the highest authority), and you only see users and roles at your own level or below β€” anything above you is hidden from the list, from search, and from the org chart, as though it weren't there. You can only edit or delete roles strictly below your level; a role at your own level is visible but read-only, except that a level-0 role may manage its own peers. Two administrators at different levels will therefore see different lists for the same company. The full rules are on Roles.

Someone left the company β€” how do I remove their access?

Open their record on Users, click Delete, and optionally record a reason. Despite the name this isn't permanent: the account moves to Inactive Users, where it can be brought back with Restore. There is no permanent-delete action anywhere in Settings, so the history stays intact.

Tip

A restored account comes back with exactly the role and access it had before. Check the Role column before restoring anyone who has been away a while.

How do I reset a password, and what does a password have to contain?

Open the user on Users and click Change Password β€” the edit form deliberately has no password fields. Whatever you set there is a temporary hand-off credential β€” any non-empty value is accepted, no complexity required β€” because the person is required to choose their own new password at their next sign-in, and that one does have to meet the policy: at least 8 characters, mixing uppercase and lowercase letters, a number, and a special character, and not resembling the username or email or a common word or keyboard pattern. Users change their own password from My Profile β€” Security.

Roles, Permissions & Departments

How do permissions actually work?

In three layers. A User Level is a named bundle of permissions for one module β€” an HR bundle, a Treasury bundle, and so on. A Role is assigned one or more of those bundles and therefore grants their combined permissions. A user is then given a role. Nobody is granted permissions individually, which is why changing what somebody can do means changing their role β€” or changing what that role is built from. Ticking Full Access on a role short-circuits all of it and grants every permission in the system, so reserve it for genuine administrators.

A colleague can't open a screen they need β€” what do I change?

Work backwards through the three layers. First check which role they hold on Users. Then open that role and look at its assigned user levels: if the module they need isn't represented, add a user level for it. If the right module is there but the specific screen isn't, edit that User Level and select the missing permission. Changes take effect for everyone holding the role, so prefer adjusting the bundle over inventing a one-person role.

Tip

A role's detail page shows only the permissions you personally hold, with a note such as "2 outside your permissions" for the rest. A short list doesn't necessarily mean the role is weak β€” it may mean you can't see all of it.

What is a department, and how is it different from a role?

A Department is a container for roles, not for people. Every role must belong to one, and each employee inherits their department from the role they hold β€” which is why the department shown on HR screens follows the role rather than being set on the person. Departments marked Global (Shared) are built in and read-only; the ones your organization creates are fully editable. Deleting a department moves its roles to a default department rather than deleting them.

Company Setup

Which company details matter most, and where do they show up?

Company Information is the default Settings page and carries the details that flow everywhere else: company name, code, business type, industry, registration and TIN numbers, main currency, timezone, address, and the logo. These appear on document headers such as invoices and purchase orders, on system emails, on the login screen, and across reports. Main currency and timezone deserve particular care, since accounting and timekeeping both depend on them.

How do I record our offices, stores, or sites?

On Branches. Each branch has a code, a name, and a location (the address record, which you can create without leaving the branch form), and can optionally be nested under a parent branch and linked to a main warehouse for inventory. If you're setting up many at once, use Import to load them from the downloadable Excel template β€” it validates the file and shows you the errors and warnings before anything is created.

How do I tighten sign-in security for everyone?

The Login Security panel on Company Information sets company-wide policy: email verification when someone signs in from a new device, one-session-at-a-time enforcement, password expiry and how far ahead to warn, how many old passwords to block from reuse, automatic sign-out after idle time, deactivation of accounts that haven't been used in N days, and a notice shown on the sign-in screen. The two toggles save the moment you flip them; the numeric fields and the notice are saved together with Save Changes.

Warning

The panel is visible only to full-access (Super Admin) accounts. The developer flag alone doesn't reveal it β€” if you can't find it, you need a full-access account rather than a different page.

Integrations, Workflows & Oversight

How do I connect our AI provider or our email server?

Both live on Cloud Credentials, each on its own tab alongside the Multibook ERP connection. Tick Enable in the card header to unlock the fields, fill them in, use Test Connection before committing, then Save. A green check mark next to a tab name means that service is live. Only one AI provider can be active at a time, and you never pick a model β€” each feature selects its own tier automatically. Object storage is no longer configured here; the whole installation now shares one bucket.

A key I already saved is asking to be entered again β€” is something broken?

Almost certainly not. Saved secrets are never displayed back to you, so a blank field showing a masked example (like sk-a***wxyz) is normal and your value is still in place. But if the field shows a plain generic example instead and has become required again, ANTE can no longer read the stored credential β€” which typically happens after this company's data was restored or copied in from another environment. Re-enter the value and Save; the service won't work until you do.

How do we get ANTE notifications in Slack?

It's a two-step setup. An administrator installs the bot once per company from Slack Integration using Add to Slack, and can pause everything later with the Slack delivery toggle without uninstalling. Then each person links their own Slack account under My Profile β€” Connections β€” that link is the opt-in for their direct messages, and without it they simply keep getting in-app notifications. Push notifications to a device are separate again, and each person controls those from their own Preferences tab.

How do I change an approval workflow?

It depends which one. Purchase Request, Delivery Status, and Liquidation share the older stage-and-connection editor: open the workflow β€” for example Purchase Request Workflow β€” click Flow Chart, add stages, and drag between them to create the transitions, each carrying the button a user clicks to advance the request. Start and end stages are worked out automatically from which stages have no incoming or outgoing connection. The RFP Workflow is different: it doesn't build stages at all, it picks which process template drives Treasury's maker β†’ approve β†’ release flow.

Tip

Changing the RFP flow only affects requests filed afterwards. Anything already in progress keeps running on the flow it started with.

How do I find out who changed a record?

The Audit Trail answers exactly that. It opens on the last 7 days, so widen the date range first if the change is older β€” that is the most common reason an event looks missing. Use More filters to narrow by module, action, actor, entity type, or an exact record id, then click any row: the Diff tab shows each changed field with its old and new value, hiding everything that stayed the same. The record is append-only and can't be edited, and you can export whatever you've filtered to CSV.

Still Stuck?

If a Settings page or whole section simply isn't in your sidebar, that is permissions rather than a fault β€” ask an administrator to widen the user level behind your role. When you need to raise something with support, take your version and build details from About first; they identify your installation precisely. Administrators who need developer-only tools request them for their own account on Developer Promotion, which is confirmed by a one-time password, and companies connected to Multibook configure how ANTE behaves with it on Multibook.