Skip to main content

Purpose

Allows authorized creditor administrators to create, invite, manage, and remove users within their organization.

Quick Summary

  • Administrators can create new users.
  • Users are invited through secure email invitations.
  • Users create their own passwords.
  • Email verification occurs during setup.
  • Access is controlled by assigned permissions.
  • Users are limited to their creditor organization.

User Creation Workflow

User Information

Each user may contain:
  • First Name
  • Last Name
  • Email Address
  • Role
  • Permissions
  • Status
  • Date Created
  • Last Login

Invitation & Password Setup

When a user is invited:
  1. A secure invitation email is sent.
  2. The user opens the setup link.
  3. The user creates and confirms a password.
  4. The email address is verified.
  5. The user gains access to the portal.

Key Rule

Invitation links must be:
  • Secure
  • Single-use
  • User-specific
  • Time-limited

Permission Management

Administrators may assign permissions that control access to:
  • Accounts
  • Negotiations
  • Communications
  • Dashboards
  • Reports
  • User Management
  • Administrative Functions

Key Rule

Users may only access functions granted through assigned permissions.

User Statuses

Active User has access to the portal. Pending Invitation sent but setup not completed. Disabled̐̐̐ User account exists but login access is suspended.

How It Should Work

  • Allow authorized administrators to create users.
  • Send secure invitation links.
  • Verify user email addresses.
  • Apply assigned permissions.
  • Restrict access to the creditor organization.
  • Support user activation and deactivation.

How It Should Not Work

  • Allow users to access another creditor’s data.
  • Allow expired invitation links.
  • Allow password setup using another user’s invitation.
  • Grant permissions not assigned by an administrator.
  • Allow unauthorized user management actions.

Developer Notes

  • User ownership must remain tied to the creditor organization.
  • Invitations must be single-use.
  • Email verification must complete before access is granted.
  • Authorization checks must be enforced throughout the portal.
  • Permission changes should take effect immediately after update.
Last modified on June 1, 2026