Skip to content

Users and access ​

This page is for the administrator, except for Change your own password, which is for everyone.

Every person who uses the installation has their own user. A user signs in to the management page, connects their own accounts and creates their own tokens.

Add a user ​

  1. Open Users.
  2. Under Add a user, type a Username and a Password of at least 8 characters.
  3. Tick Administrator if this person will help run the installation.
  4. Tick May write if this person may make changes on the platforms.
  5. Press Create user.

Give the person their username and password, and ask them to change the password on Account when they first sign in.

What each setting allows ​

The table under Who can sign in has three tick boxes for each user. A change is saved as soon as you tick or untick a box.

SettingWhat it means
AdminThe user sees the Administration pages: Users, All activity, the three platform app pages, Safety limits, Notification delivery, Lead delivery and Server.
May writeThe user may make changes on the platforms: publish posts, change budgets and bids, create and pause campaigns, reply to comments.
DisabledThe user cannot sign in, and their tokens stop working. Nothing of theirs is deleted.

The bottom of the menu shows each person which they are: Administrator, May write or Read only.

A user without write access ​

A user without May write can read: reports, figures, lists of campaigns and posts. When they ask their AI client for a change, the server refuses and says why:

Refused: writing is not enabled for 'sara', so ... is unavailable. An administrator can turn
on write access for your account in the management page.

Reading leads and sending customer records to a platform also need May write, although they change nothing: see Leads.

Administrator and write access are separate ​

Admin is about the installation. May write is about the platforms. An administrator without May write can change every setting and still cannot publish a post. The first account, created at install, has both.

When the whole server is read-only ​

Safety limits has a switch, Refuse every change, under Read-only server. With it on, no one can make a change, whatever their own settings say. See Server settings.

Each person connects their own accounts ​

An administrator sets up one app for each platform, for everyone. After that every user connects their own Google, Meta and LinkedIn login, on Google connection, Meta connection and LinkedIn connection. No one can connect an account for someone else.

The tools then reach what that person's login can reach. Two users can see different ad accounts and different Pages.

The Users table has a column for each platform, so you can see who is connected. It also marks a connection that needs attention:

  • A Meta connection ends by itself after about 60 days. The column says expires soon before it does, and the person reconnects.
  • A LinkedIn connection renews itself, but only for a year after the person signed in. The column says sign in again soon before that year ends.

Disable or delete a user ​

Disable someone who should stop for now. Tick Disabled in their row. They are signed out everywhere, they cannot sign in, and their tokens are refused. Untick it and everything works again.

Delete someone who has left. Press Delete in their row and confirm. Their tokens, their connections to the platforms, their uploaded media, their queued posts, their alert rules and their scheduled reports go with them. This cannot be undone. Their rows in the activity log stay.

You cannot delete the account you are signed in as.

The last administrator ​

An installation always keeps one working administrator. If you try to untick Admin for the only administrator, to disable them or to delete them, the page refuses:

This is the only administrator; promote someone else first.

Make another user an administrator first.

Reset someone's password ​

Press Reset password in the user's row and type the new password. The user is signed out everywhere and signs in again with the new one. Their tokens keep working.

Change your own password ​

  1. Open Account.
  2. Under Change your password, type your Current password and a New password of at least 8 characters.
  3. Press Change password.

This is your password for the management page only. It is not your Google, Meta or LinkedIn password, which this server never sees.

Account also shows your username, your role, whether you may make changes, and when you last signed in.

Sign-ins and tokens ​

  • A sign-in to the management page lasts 7 days, then the page asks you to sign in again. Sign out, at the bottom of the menu, ends it sooner.
  • A token does not end by itself. It works until it is revoked, or until its user is disabled or deleted. Each user manages their own on MCP tokens: see Connect an AI client.

Who did what ​

Everything a user's tokens did is in the activity log: each user sees their own on My activity, and an administrator sees everyone's on All activity. See The activity log.