Before You Start
- The breadcrumb reads Settings > Team & Roles > Entity Team. You can also search for Entity Team in the command palette, or choose the link on the Settings > Users hand-off card.
- You need the users.view permission to open the page and see the list.
- Each action has its own permission. Invite User needs users.create. Editing a person, setting or resetting a PIN, sending a password reset code, marking an email verified, resetting MFA, and deactivating or reactivating need users.edit. Remove from entity needs users.delete. A button you cannot use is hidden, or disabled with a reason, depending on the action. The server refuses the action anyway when the permission is missing.
- The location list in the edit dialog comes from your company settings, so it needs settings.view. Without it the location checklist is empty.
- Only an owner can change an owner. Your own row is protected from the actions that could lock you out.
- Confirm the company in the entity selector before you change anything. Every change here applies to the company that is selected.
Read The Team List
The page title is Entity Team, with the note “Manage roles, PINs, and permissions for users in this entity”. Under it, Manage org-wide invitations and user access opens Organization Users. The table has these columns. The column menu lets you hide or reorder every column except User and the actions column, and reset to the default.
Search matches name, email, role and custom role name. With no match the table says “No users match your search” and “Try a different search term.” With nobody in the company it says “No users yet” and “Invite team members to this entity to get started.” If the list cannot load, the page says “Failed to load users”.
Invite A User
- Choose Invite User. The button is disabled with a reason when you lack users.create.
- Enter the Email Address.
- Choose the starting role. Owner is offered only to an owner.
- Check the companies the person should join. The company you are in is already checked.
- Optionally open the restriction to specific warehouses (“Restrict to Warehouses”). Leave it unset to inherit the role’s defaults.
- Optionally open custom permissions for advanced overrides.
- Choose Send Invitation.
Manage A Person
Choose the menu on a person’s row. The menu lists only what your permissions allow.Edit
Edit opens Manage User Access, pinned to this company, with a disclosure labeled Manage access in all entities if you also want to see their other companies. In the dialog:- First Name and Last Name. You cannot change your own name here.
- Email is shown but cannot be edited. A sign-in email changes only when its owner confirms a code sent to the new address, from their own Profile.
- PIN Lock turns the lock screen on or off. It locks the screen after 15 minutes of inactivity.
- Entity Access shows this company’s role, location access and custom permissions. Leaving every location unchecked means unrestricted: the person sees every location in the company.
- A menu of account actions: Reset MFA, Send password reset code, Mark email verified, Deactivate user or Reactivate user, and Remove from organization.
Set Or Reset A PIN
Set PIN and Reset PIN are enabled on your own row. On another person’s row they are disabled with this reason: “Unavailable for now: setting another person’s PIN changes your own PIN instead (being repaired). They can set their PIN from their Profile page.” Ask the person to set their own PIN from their profile. On your own row, Set PIN opens a dialog that asks you to enter a 4 to 6 digit PIN, used to unlock the screen after inactivity. Arcus confirms with “PIN set for” and your first name, or says “PIN must be 4-6 digits”. Reset PIN clears the PIN and says “PIN cleared for” and your first name.Fix A Sign-In Problem
Send password reset code and Mark email verified open a dialog that first reads the person’s sign-in status, then offers a single button that is enabled only when the action can run. The status shows:- Email: Verified, Not verified, or No sign-in yet.
- Sign-in: Allowed, Blocked: user deactivated, Blocked: sign-in disabled, or No sign-in yet.
- Account setup: Password set, Temporary password, never changed, Invitation not finished, Password reset required, or Signs in through another provider.
- Two-step sign-in: the factors they have, such as Authenticator app, Email code or passkeys, or None set up.
- Lockout: always “Cannot be read. A lock from wrong passwords ends on its own within about 15 minutes”. Arcus cannot lift a lockout early, so there is no unlock button.
Deactivate Or Reactivate
Deactivate opens a confirmation. The person is signed out and blocked from signing in, but their access and login are kept, and the change is reversible. Arcus confirms with “Deactivated” and the name. Reactivate restores access and lets them sign in again, with “Reactivated” and the name.- You cannot deactivate your own account. The menu item says so, and the page says “You cannot deactivate your own account”.
- Only an owner can change an owner, and the page says “Only owners can deactivate owner accounts”.
- The last owner of a company, or the organization’s only owner, cannot be deactivated. The server asks you to assign another owner first.
Remove From This Company
Remove from entity opens Remove User from Entity. The person loses access to this company only. Their account is not deleted and they keep any other companies, and their location assignments for this company are cleared. Arcus confirms with the person’s first name followed by “removed from entity”. The action is hidden on your own row and disabled on an owner’s row unless you are an owner. To delete a person’s login from the whole organization, use Remove from organization in the edit dialog or Organization Users. That deletes their login, and they must be invited again to return.Upload A Photo
Choose the photo control on a person’s row to upload a profile picture used in lists and on operational screens. You can always change your own photo; changing another person’s needs users.edit. Arcus confirms with “Profile photo updated” or says “Upload failed”.Statuses
Messages You May See
What Happens When You Act
- Access: a role, location or permission change takes effect for the person without anything else to turn on. Deactivating signs them out at once.
- Email: an invitation email goes to the invitee, and a password reset code goes to the person you choose. Nothing is emailed for Mark email verified or Reset MFA.
- Audit: invitations, edits, location changes, membership changes, removals, MFA resets and self-grants are recorded in the Audit Log.
- Other screens: the list refreshes for other signed-in administrators without a reload.
- Accounting and inventory: none. A person’s access does not change any posted record.
Common Blocks
- Invite User is disabled: your role lacks users.create.
- No row menu appears: your role has neither users.edit nor users.delete.
- Edit is disabled on a row: it is an owner and you are not.
- Set PIN is disabled on another person: see the reason above. Ask the person to set it from their Profile.
- A person cannot see inventory or fulfillment work: check their location access in the edit dialog.
- A person cannot sign in: open Send password reset code and read the status first. A lockout from wrong passwords ends on its own.
Related Articles
User Management
Invite across companies, manage organization access and reset MFA from Organization Users.
Roles and Permissions
Review system roles, build custom roles and choose exact permissions.
Profile and Security
Set your own PIN, password and two-step sign-in.
Audit Log and Compliance
Review access changes after the fact.

