Add a User and Set Permissions
Giving someone access to ANTE is really two decisions: who they are, and what they are allowed to see. This walkthrough covers both β checking the role that carries the permissions, creating or inviting the account, and deactivating access cleanly when the person leaves.Before you start
Everything in this tutorial lives under Settings β Users & Access. Two things are worth knowing before you begin:
- Permissions come from the role, never from the user β you do not tick permissions on a person. You assign them a Role, and the role carries the access.
- You only see your own level and below β the Users list, the Roles list, and the org chart all hide anything above your position in the hierarchy, so two administrators at different levels legitimately see different lists.
Reference pages: Users, User Invitations, User Levels, and Departments.
Go to Settings β Users & Access β Users. The table lists everyone you are allowed to see, with their Name, Email, Username, Role, and who they Report To.
Search by name, email, or username, or filter by role. The Actions menu is where the rest of this tutorial starts β it holds Add User, Organizational Chart, AI Users, Inactive Users, and Export (a spreadsheet of every account with role, department, status, and sign-in dates β useful for an access review).
- 1Actions β Add User, Inactive Users, Org Chart, Export
- 2Role β where every permission the user holds comes from
- 3Reports To β the supervisor set on the account
A user cannot be created without a role, so confirm the right one exists at Settings β Users & Access β Roles. If it does not, click Add Role and fill in:
- Name and Department (both required).
- Level (required) β the rank in the hierarchy, where 0 is the highest authority. You cannot create a role above your own level; the field starts one below yours and tells you the highest you are allowed.
- Parent Role β who this role reports to. Roles that would not work as a parent are greyed out with the reason.
- Position rank β Executive, Director, Manager, Senior, or Staff. This is a job-title rank used when picking assignees, separate from the authority Level.
- Full Access β grants every permission in the system. Leave it unchecked for anyone who should be scoped.
Then choose the role's Permissions and click Create Role.
- 1Add Role β create the role before you create the user
- 2Level β 0 is the highest authority in the hierarchy
- 3Full Access β Yes means the role bypasses per-module permissions
Roles do not carry individual view/create/edit/delete checkboxes. They are assembled from user levels β named permission packs, each scoped to a single system module (an HR pack, a Treasury pack, and so on). A role grants the combined permissions of every user level assigned to it, and Full Access overrides the lot.
So to give someone access across several modules, assign their role one user level per module rather than building a new pack each time. Manage the packs themselves at Settings β Users & Access β User Levels, where Add User Level asks for a Label, a System Module, and at least one permission.
You only see a user level if you personally hold at least one of the permissions it grants, and the permission counts shown are narrowed to what you hold β so the same user level can read differently for two administrators.
Every role belongs to a department, and every employee inherits their department from the role they hold β which is what makes department show up correctly across the HR and employee screens.
Open Settings β Users & Access β Departments to review them. To add one, open Actions β Add Role Group, give it a Name and an optional Description, and click Create Department. Departments marked Global are shared and read-only; the ones marked Company are yours to edit.
Back on Users, open Actions β Add User. The form has four sections β Personal Information, Contact Information, Address, and Account Settings. The required fields are First Name, Last Name, Email, Username, Role, Temporary Password, and Confirm Password.
Supervisor only becomes selectable once you have chosen a role, and the list of possible supervisors is filtered by that role. The temporary password can be any non-empty value β it's just a hand-off credential, so it doesn't have to meet the company's password policy. The person sets their own real password, which does have to meet policy, the first time they log in.
Click Create User. You land on the new user's detail page, and the person will be required to change the password you set the first time they log in.
If you would rather the person set up their own account, go to Settings β Users & Access β User Invite and click Invite User. Enter their First Name, Last Name, Email Address, and the Role they will hold, optionally pick a Supervisor, then click Send Invitation.
They receive a link, register themselves, and become a regular user with the role you chose β at which point the invitation drops off this list. Invitations stay Pending for 7 days and then read Expired. Use Resend on a row that has not expired, or Cancel to withdraw it.
- 1Invite User β sends the self-setup email
- 2Pending β still valid and waiting to be accepted
- 3Cancel β withdraws the invitation permanently
When a person changes jobs, change their role rather than hunting for individual permissions. Open the user, click Edit, and in Account Settings pick the new Role and, if needed, a new Supervisor. Click Save Changes.
If instead the whole job function needs different access, edit the role: permission changes there take effect for everyone holding it. Note that the Edit form has no password fields β use Change Password on the user's detail page for that, and the user will be required to set their own password at the next login.
Open the user's detail page and click Delete. You can record a Reason for deletion, then confirm.
This is not permanent: the account moves to the Inactive Users list, reachable from Actions β Inactive Users or at Settings β Users & Access β Inactive Users. Click Restore on their row and confirm to bring the account back.
For a periodic access review, use Actions β Export on the Users page. The spreadsheet covers active, inactive, and deactivated accounts with their role, department, status, and sign-in dates.
Where to go next
- Permissions Model β how user levels combine into a role's access.
- Visibility & Permissions β exactly which roles you can see, edit, and delete at your own level.
- Inactive Users β the deactivated accounts list and how restoring works.
- Company Information β Login Security β the company-wide password policy, idle timeout, and sign-in settings.
- AI Users β the separate list of AI accounts in your workspace.
- Settings FAQ β quick answers on users, roles, and access.