Registering & Managing Users Overview — Accounts in NSCAT Every person who works in NSCAT needs an account, and accounts are created by an administrator — there is no self-service sign-up. This page covers both halves of the job: creating an account with Register a User, and changing or disabling one afterwards with Manage User. Both live under Administration in the left sidebar, which is visible to COG Admins and Utility Admins. The life of an account 1.      Registered — you create it with an email, a name, a starting password, an organization, and its roles. 2.      Active — the person signs in and works in whatever activities they are assigned to. 3.      Adjusted — you change their organization, add or remove an admin role, or reset a forgotten password. 4.      Disabled — you untick Account Enabled. The account and its history stay, but the person can no longer sign in. GOOD TO KNOW  There is no delete for a user. Disabling is the intended way to remove someone's access — it keeps the audit trail on every activity, response, and observation they touched intact. Registering a User Open Administration → Register a User. The Register a User form. The fields Field What to enter email The person's work email. This is their username — they sign in with it, and password-reset mail goes here. It must be a valid address and must not already be in use. First Name Required. Shown on responses, observations, and the activity feed. Last Name Required. Password A starting password (see the policy below). Confirm Password Must match Password exactly. Organization The utility this person belongs to, chosen from the list of utilities. This drives what they can see. COG Admin Tick for cross-organization administration — ISF, utilities, activity locking. Utility Admin Tick for utility administration — question pool, themes, training, cross-activity reports. The password policy A password must have all of the following: ·        At least 6 characters ·        At least one uppercase letter ·        At least one lowercase letter ·        At least one number ·        At least one special character from @ $ ! % * ? & HEADS UP  Only the special characters @ $ ! % * ? & are accepted. Other symbols — #, -, _, . — will fail validation even though the field looks filled in correctly. If a password is rejected and you cannot see why, that is usually the reason.   PRO TIP  Set a throwaway starting password and tell the person to change it on first sign-in from Profile, or to use Forgot Password on the login screen to set their own. You never need to know their working password.   Choosing the roles The two role checkboxes are independent, and neither implies the other. Pick from what the person actually needs to do: The person… COG Admin Utility Admin Runs assessments; leads a team — — Curates questions and themes; runs trending and CPRO reports — Tick Maintains the ISF; creates utilities; locks activities Tick — Is the day-to-day administrator for the whole system Tick Tick   HEADS UP  COG Admin is not a superset of Utility Admin. An account with only COG Admin ticked has no access to Question Composer, Theme Management, Training Management, the Trending Report, the CPRO Report, the Report Builder, or Lessons Learned Review. If you are creating an account for someone who administers day to day, tick both.   GOOD TO KNOW  Neither admin role grants access to an individual activity's contents. Activity access comes from being assigned as a Team Lead or Team Member on that activity — see Roles & Access Control.   When the form is valid, submit it. The account is usable immediately. Managing an Existing User Open Administration → Manage User. Unlike the registration form, this page starts empty — you pick a person first, and the form fills in with their current details. The Manage User form with a user selected. Selecting the user User Email is a searchable list of every account. Start typing a name or address to narrow it. Choosing an entry loads that person's First Name, Last Name, Organization, role checkboxes, and current enabled state. PRO TIP  The list searches on the whole address, so typing a domain fragment is a quick way to see everyone from one organization.   Enabling and disabling an account The checkbox at the top of the form is the account's on/off switch, and its label reflects the current state — Account Enabled when ticked, Account Disabled when not. Untick it and save to revoke access. The person can no longer sign in; everything they created stays where it is. HEADS UP  While the account is disabled, every other field on the form is greyed out. You cannot correct a name or change an organization on a disabled account. Re-enable it, make the change, save, then disable it again if that is what you want.   GOOD TO KNOW  Disabling an account does not remove that person from the activities they are assigned to. Their name stays on the team list. If someone has genuinely left, unassign them from their activities as well — otherwise the team list keeps showing a person who cannot sign in.   Changing names, organization, and roles With the account enabled, First Name, Last Name, Organization, COG Admin, and Utility Admin are all editable. Save to apply. HEADS UP  Changing Organization moves the person to a different utility and changes what they can see — including which activities appear on their dashboard. Confirm it is really a transfer and not a mis-click before saving.   GOOD TO KNOW  A role change takes effect on the person's next sign-in, because the sidebar is built from the roles in their current session token. If someone says a newly granted menu is missing, have them sign out and back in. Resetting a password Passwords are only editable when you ask for it. Tick Changing Password? and the Password and Confirm Password fields become available. The same policy applies as at registration: minimum 6 characters, with an uppercase letter, a lowercase letter, a number, and one of @ $ ! % * ? &. PRO TIP  For a routine forgotten password, point the person at Forgot Password on the login screen instead — it emails them a reset link and no one has to hand a password around. Use Changing Password? for accounts that cannot receive the mail.   GOOD TO KNOW  Leave Changing Password? unticked and the existing password is untouched. Editing a name or a role never resets it. Common Problems What you see What it means Registration rejected, email flagged as invalid The address failed format validation, or an account already exists on it. Search for it in Manage User before creating a new one. Password rejected but it looks strong Almost always an unsupported special character. Only @ $ ! % * ? & count. Fields greyed out in Manage User The account is disabled. Tick Account Enabled to edit anything. User says a menu is missing after you granted a role They are on an old session. Sign out and back in. User sees Access Restricted on an activity An account role is not activity access. Add them as a Team Member or Team Lead on that activity. New admin cannot see Question Composer or Theme Management They have COG Admin but not Utility Admin. Tick Utility Admin as well.