Skip to content

Manage operator users

Create and manage the login-capable staff who work in the Backoffice — operators, agents, and managers — and control how each one signs in and what they can reach.

Operator users are the people at your firm who sign in to the Backoffice to work leads, accounts, and trading operations. They are entirely separate from the customers who trade through the WebTrader: a customer trading account is not an operator user, and creating one here never gives a customer Backoffice access.

Prerequisites

Open the user list

In the left sidebar, open System users. The page lists the operator users in your active workspace, one row each, showing the login email, the groups assigned, and whether the user is enabled.

Add a user

  1. Click Add system user.
  2. In Name, enter the display name your team will recognize.
  3. In Login username (email), enter the email address the user will type on the sign-in screen. This is the login identity and is fixed once the user is created.
  4. Under Login method, choose how the user signs in:
  5. Username / password — you set an initial password below.
  6. Google (social) or Microsoft (social) — the user signs in with that provider; no password is set here.
  7. If you chose username and password, set an Initial password.
  8. Under Permission groups, choose the one group that sets the user's role and account reach. See Manage permission groups for what a group grants.
  9. Under Home business unit, choose the user's single position in the workspace tree. What the user can reach is their home business unit plus their permission group — this step sets that position.
  10. (Optional) In VOIP extension, enter the user's dialer extension. This stores the extension for use by a connected telephony system, if one is configured.
  11. Leave Enabled on to let the user sign in immediately, or turn it off to create the user in a disabled state.
  12. Click Save.

Note

If the login email already belongs to an existing person, the new user is added to this firm under that existing login and no new password is needed.

Edit, enable, or disable a user

Click a user's row to open its editor. You can update the name, permission group, home business unit, VOIP extension, and the Enabled toggle. The login identity itself cannot be changed here.

Turning Enabled off is the reversible way to stop someone from signing in while keeping the accounts and history they own intact — prefer it to deletion for anyone who owns data.

Reset a user's password

For a username-and-password user, open the editor and use Reset password to set a new login password. The change takes effect immediately.

Reset a user's two-factor enrollment

If a user has lost access to their authenticator app and their recovery codes, you can clear their two-factor enrollment so they set it up fresh on their next sign-in. Open the user's editor and use the two-factor reset action, then confirm.

Warning

Resetting two-factor enrollment removes the user's current second factor. The user is prompted to enroll again at their next sign-in; if the workspace policy requires two-factor authentication, they must complete setup before they can reach the rest of the Backoffice.