Users
Invite staff, assign branch coverage and access, send password resets, and remove access without losing audit history.
What the Users page controls
The Users page manages staff accounts connected to the lab company. A person appears here when any company branch is their primary branch or one of their assigned branches. This keeps multi-branch staff on one account while preserving clear attribution in assignments, audit logs, and operational history.
Managers do not create passwords for staff. New accounts use a signed invitation so each person chooses their own password before the account is created.
Invite a team member
Select Invite team member, then enter the person's real name, unique email address, primary branch, assigned branches, and operational job role. The invitation remains valid for seven days.
No user account exists until the recipient accepts the invitation. The recipient can confirm their name, optionally upload a JPEG, PNG, or WebP avatar up to 2 MB and 2048 by 2048 pixels, and choose a password. The invitation email address cannot be changed during acceptance.
Open the Pending invitations tab to review invitations that were sent but not accepted yet. Use Cancel invitation when the email, role, or branch coverage was wrong, or when the person should no longer join. Cancelling stops the link and no account is created from that invitation.
If the email already belongs to an active user, or has a pending invitation for another lab company, Kashef rejects the invitation instead of creating a duplicate identity. If it belongs to a removed account, restore that account from the Users page.
If invitations or reset emails do not reach anyone after checking the address and spam folder, ask a system administrator to review transactional mail delivery. Repeated resends will not help while the configured mail provider is rejecting the system.
User information and job role
After acceptance, open the user profile to maintain name, email, phone, and job role. The email is the login identity and password-reset destination, so it must remain unique.
The job role is Manager, Operations, Technician, or Receptionist. It supports dashboards, staffing, and workflow assignment. Access roles and direct permissions still determine the exact Lab Panel capabilities available to that person.
Kashef prevents changing the final manager account to another job role. Assign another manager first so the lab company cannot lose administrative access.
Access control
Use access roles for normal permission bundles. They are company-scoped and are the preferred way to keep staff with similar responsibilities consistent.
Use direct permission grants only for approved exceptions that do not belong in a reusable role. If several people need the same exception, update or create an access role instead.
Branch assignment
Primary Branch is the person's main working location. Assigned Branches adds other locations the person can access after accepting the invitation or after a manager updates the profile.
Both controls only accept branches from the active lab company. A submitted branch from another company is rejected even if a request is manually modified.
The Users table shows staff connected to the current lab company. Use the branch filter when you need to focus on one location.
Carrier access
Tagged As Carrier creates or updates a carrier profile for the same person and lets them use the Carrier Portal with the same credentials. Only branches from the same lab company are linked to that carrier profile.
Turning carrier access off suspends the linked carrier profile and removes its branch assignments. Removing the staff account also suspends carrier login, so deleted panel access cannot remain active through the Carrier Portal.
Use the separate Carriers page to monitor portal status, online availability, synchronized pickup branches, recent activity, and manager-only notes. Carrier identity, credentials, and branch coverage are read-only there; change them from the linked Users profile. There is no standalone carrier creation or deletion flow.
A carrier sets Online or Offline from the Carrier Portal. Offline carriers may review their queue but cannot claim or start a new pickup. Before suspending a carrier from the Carriers page, reassign or complete every claimed or in-transit transfer. Completed transfers remain in history.
Carrier Portal authentication accepts only an active linked staff account that is still tagged as a carrier and assigned to at least one branch in the same lab company. Legacy standalone carrier passwords are not accepted.
Password reset
Select Send password reset, enter your current manager password, and confirm. Kashef sends the standard secure reset link only when both the manager and target user belong to the active branch.
Managers never see or set another person's password. If the recipient does not receive the message, verify the profile email and the configured transactional mail delivery.
Remove access
Removing a user performs a soft delete. The person can no longer sign in, but their historical actions remain attributed to the original account for audit and support.
You cannot remove your own account or the lab company's final manager. Manager accounts are intentionally excluded from bulk removal and must be reviewed one at a time. Bulk removal is available only for eligible non-manager accounts.
Use the deleted-users filter to review removed accounts. Select Restore staff access to reactivate the existing login, saved branch assignments, permission settings, and tagged carrier profile. Restoring is preferred over creating a second identity for a returning employee.
Table and filters
Search by name, email, phone, primary branch, or assigned branch. Filter by job role, a branch from the active lab company, or deleted-account status. The table also shows access roles, carrier status, email verification time, and creation time.
When troubleshooting access, check the active branch, primary branch, assigned branches, job role, access roles, direct grants or denies, subscription entitlements, and the user's current record status.