10 min readOwners, managers, system administrators, and implementation leads.

Invite a staff user

Invite a staff member, let them choose a password, then complete branch and permission setup.

Before sending the invitation

Create one account for each real person. Do not share reception, finance, technician, carrier, or manager credentials. Kashef records changes by user, so shared accounts make releases, price changes, approvals, and configuration changes difficult to audit.

Confirm the person's real name, unique email address, intended job role, primary branch, extra branch coverage, and expected access role before starting.

1. Open Users

In the Lab Panel, go to Admin > Users. The list shows people connected to the lab company through their primary branch or assigned branches.

Search for the email first. If the account already exists, edit it instead of sending another invitation. If it was removed, use the deleted-users filter and restore the original account.

2. Send the invitation

Select Invite team member and complete:

  • Member name: the real name used in assignments and audit history.
  • Email address: the unique login and password-reset address.
  • Primary Branch: the location where the account starts after acceptance.
  • Assigned Branches: every additional branch the person can access.
  • Job Role: Manager, Operations, Technician, or Receptionist.

Select Send invitation. Kashef emails a signed link that expires after seven days. The account is not created yet.

Open the Pending invitations tab if you need to confirm the invite is still waiting for acceptance. Cancel the pending invite before sending a corrected one when the email, role, primary branch, or assigned branches were entered incorrectly.

If several invitations or password reset messages fail to arrive, first check spam and the entered address. When no staff member receives system emails, ask a system administrator to review transactional mail delivery instead of sending more invitations.

3. Staff member accepts

The recipient opens the signed link and:

  • Confirms or corrects their name.
  • Optionally uploads a JPEG, PNG, or WebP avatar up to 2 MB and 2048 by 2048 pixels.
  • Chooses and confirms a password.

The invitation email is locked. After successful acceptance, Kashef verifies the email, creates the account, assigns the selected primary branch and branch coverage, and signs the new user in.

If the invitation expires, send a new one. A new invitation supersedes an earlier pending invitation for the same lab company.

4. Complete access setup

Return to Admin > Users, open the accepted account, and select Edit.

Review the job role, then attach the smallest access-role set that supports the person's work. Add direct permission grants only for approved exceptions.

Set Primary Branch to the main location and use Assigned Branches for additional locations. Only branches from the active lab company are available.

5. Configure carrier access when required

Enable Tagged As Carrier only when the person handles pickup or delivery work and should enter the Carrier Portal with the same credentials.

The linked carrier profile receives only the person's branches from the same lab company. Turning the option off suspends carrier access.

6. Verify the account

Ask the staff member to select the correct branch and confirm the expected pages and actions. Check:

  • Active branch and assigned branches.
  • Job role and access roles.
  • Direct permission grants or denies.
  • Subscription feature availability.
  • Carrier Portal access, when enabled.

Do this before the first live shift.

Reset or remove access later

Use Send password reset when the person cannot sign in. Confirm your own manager password; Kashef sends a secure reset link without exposing or replacing the current password.

Use Remove panel access when the person leaves. This soft-deletes the account and suspends linked carrier access while preserving historical attribution. You cannot remove your own account or the lab company's final manager.

For a returning employee, filter the list to deleted users and select Restore staff access. This reactivates the existing identity and its saved access instead of splitting history across two accounts.