Users & roles
Under Administration → Users you control who works with Contrixt — and what each person can see and change.
What you need
- The Administrator role
- Name and email address of the person to invite
- Optional: configured email delivery so invitations are delivered automatically
Inviting team members
New accounts are created via invitation — for security reasons administrators set no password:
- Open Administration → Users and fill in the Invite a new team member card: name, email and role.
- Click Send invitation. The invitee receives an email and sets their password themselves via the activation link.
- Until activation the user list shows the status Invited; the account cannot sign in yet.
- The activation link is valid for 7 days and can be used only once.
- Resend invitation creates a new link and invalidates the old one.
- If no SMTP is configured, Contrixt shows the activation link directly — pass it on through a secure channel.
How to verify it works: Once the person has set their password, the Invited status disappears from the user list and they can sign in.
Plan user limit
The number of active users depends on your plan; user management shows the current usage. Once the limit is reached, deactivate a user or upgrade your plan — deactivated users do not count.
Roles
| Role | Typical use |
|---|---|
| Administrator | IT leadership, system owners — full access incl. administration |
| Controlling | Controlling — read/write all business data, no administration |
| Budget owner | Team leads — write within their cost centers |
| Read-only | Management, audit — see everything, change nothing |
Change roles directly in the user list. To prevent lockouts: your own role cannot be changed and your own account cannot be deactivated.
Cost center access (scoping)
For budget owners, access can be limited to selected cost centers (including their subtree): assign cost centers in the user list and confirm with Save assignment. No selection means access to all cost centers. Each team sees and edits only its own area.
Deactivating
Deactivate blocks sign-in immediately; the account's data and history remain. Activate restores access at any time.
Resetting 2FA
If a user has lost access to their authenticator app, passkey and recovery codes, reset their two-factor authentication in the user list — they set it up again at their next sign-in. Setup details under Sign-in & account.
Automated management
With a connected identity provider, SSO & SCIM take over authentication and provisioning — SCIM-managed accounts are not activated via invitation but controlled by the identity provider.