Skip to main content
Entity Team lists everyone who has access to the company you are signed in to. Use it for day-to-day access work: invite a person, change what they can do here, restrict them to certain locations, send a password reset code, deactivate someone who is away, or take a person out of this company. Entity Team works on one company at a time. To invite a person to several companies at once, or to remove someone from the whole organization, use Organization Users. For the larger picture, see User Management.

Before You Start

  • The breadcrumb reads Settings > Team & Roles > Entity Team. You can also search for Entity Team in the command palette, or choose the link on the Settings > Users hand-off card.
  • You need the users.view permission to open the page and see the list.
  • Each action has its own permission. Invite User needs users.create. Editing a person, setting or resetting a PIN, sending a password reset code, marking an email verified, resetting MFA, and deactivating or reactivating need users.edit. Remove from entity needs users.delete. A button you cannot use is hidden, or disabled with a reason, depending on the action. The server refuses the action anyway when the permission is missing.
  • The location list in the edit dialog comes from your company settings, so it needs settings.view. Without it the location checklist is empty.
  • Only an owner can change an owner. Your own row is protected from the actions that could lock you out.
  • Confirm the company in the entity selector before you change anything. Every change here applies to the company that is selected.

Read The Team List

The page title is Entity Team, with the note “Manage roles, PINs, and permissions for users in this entity”. Under it, Manage org-wide invitations and user access opens Organization Users. The table has these columns. The column menu lets you hide or reorder every column except User and the actions column, and reset to the default. Search matches name, email, role and custom role name. With no match the table says “No users match your search” and “Try a different search term.” With nobody in the company it says “No users yet” and “Invite team members to this entity to get started.” If the list cannot load, the page says “Failed to load users”.

Invite A User

  1. Choose Invite User. The button is disabled with a reason when you lack users.create.
  2. Enter the Email Address.
  3. Choose the starting role. Owner is offered only to an owner.
  4. Check the companies the person should join. The company you are in is already checked.
  5. Optionally open the restriction to specific warehouses (“Restrict to Warehouses”). Leave it unset to inherit the role’s defaults.
  6. Optionally open custom permissions for advanced overrides.
  7. Choose Send Invitation.
The dialog explains that the invitee enters their own name when they accept. Arcus confirms with “Invitation sent to” and the address. If your plan’s seat limit is reached, the server refuses with a message that names your plan and the limit. Pending invitations are managed on Organization Users, where you can resend or revoke them.

Manage A Person

Choose the menu on a person’s row. The menu lists only what your permissions allow.

Edit

Edit opens Manage User Access, pinned to this company, with a disclosure labeled Manage access in all entities if you also want to see their other companies. In the dialog:
  • First Name and Last Name. You cannot change your own name here.
  • Email is shown but cannot be edited. A sign-in email changes only when its owner confirms a code sent to the new address, from their own Profile.
  • PIN Lock turns the lock screen on or off. It locks the screen after 15 minutes of inactivity.
  • Entity Access shows this company’s role, location access and custom permissions. Leaving every location unchecked means unrestricted: the person sees every location in the company.
  • A menu of account actions: Reset MFA, Send password reset code, Mark email verified, Deactivate user or Reactivate user, and Remove from organization.
Save changes stays disabled with the reason “No unsaved changes” until you change something, and a name must be filled in. Arcus confirms with “Changes saved”. If one section fails, the page says “Failed to save” followed by the section and the reason. The organization’s owner can grant themselves owner access to a company they are not in, through Grant Yourself Access. It asks for a reason of at least 10 characters and records the self-grant in the Audit Log. Anyone else is told to ask the organization’s owner. You cannot remove your own access.

Set Or Reset A PIN

Set PIN and Reset PIN are enabled on your own row. On another person’s row they are disabled with this reason: “Unavailable for now: setting another person’s PIN changes your own PIN instead (being repaired). They can set their PIN from their Profile page.” Ask the person to set their own PIN from their profile. On your own row, Set PIN opens a dialog that asks you to enter a 4 to 6 digit PIN, used to unlock the screen after inactivity. Arcus confirms with “PIN set for” and your first name, or says “PIN must be 4-6 digits”. Reset PIN clears the PIN and says “PIN cleared for” and your first name.

Fix A Sign-In Problem

Send password reset code and Mark email verified open a dialog that first reads the person’s sign-in status, then offers a single button that is enabled only when the action can run. The status shows:
  • Email: Verified, Not verified, or No sign-in yet.
  • Sign-in: Allowed, Blocked: user deactivated, Blocked: sign-in disabled, or No sign-in yet.
  • Account setup: Password set, Temporary password, never changed, Invitation not finished, Password reset required, or Signs in through another provider.
  • Two-step sign-in: the factors they have, such as Authenticator app, Email code or passkeys, or None set up.
  • Lockout: always “Cannot be read. A lock from wrong passwords ends on its own within about 15 minutes”. Arcus cannot lift a lockout early, so there is no unlock button.
Send password reset code (confirm with Send code) emails a 6-digit code to the person’s address. The code expires in 10 minutes, and the person enters it on the Forgot password page to choose a new password. Once it is sent you can copy a link to that page. Mark email verified (confirm with Mark verified) marks the sign-in address as verified. Use it only when you know the address is theirs, for example because their invitation reached it. No email is sent and the password does not change. An action may be unavailable for a reason the dialog states: the address is already verified, the person has no sign-in yet or has not finished accepting their invitation (resend the invitation instead), or the user is deactivated. On your own row the actions are disabled with “This is your own account. Use your Profile page.” On an owner’s row, unless you are an owner, they are disabled with “Only an owner can change an owner’s sign-in.” On a deactivated person they are disabled with “Reactivate this user first. A deactivated user cannot sign in.” Reset MFA in the edit dialog clears the person’s authenticator app, recovery codes and passkeys, so they must enroll again at their next sign-in. You must type the confirmation phrase shown and give a reason of at least 5 characters. Arcus confirms with “MFA reset for” the person’s name followed by “No email was sent; let them know.” Tell the person yourself. You cannot reset your own MFA here.

Deactivate Or Reactivate

Deactivate opens a confirmation. The person is signed out and blocked from signing in, but their access and login are kept, and the change is reversible. Arcus confirms with “Deactivated” and the name. Reactivate restores access and lets them sign in again, with “Reactivated” and the name.
  • You cannot deactivate your own account. The menu item says so, and the page says “You cannot deactivate your own account”.
  • Only an owner can change an owner, and the page says “Only owners can deactivate owner accounts”.
  • The last owner of a company, or the organization’s only owner, cannot be deactivated. The server asks you to assign another owner first.

Remove From This Company

Remove from entity opens Remove User from Entity. The person loses access to this company only. Their account is not deleted and they keep any other companies, and their location assignments for this company are cleared. Arcus confirms with the person’s first name followed by “removed from entity”. The action is hidden on your own row and disabled on an owner’s row unless you are an owner. To delete a person’s login from the whole organization, use Remove from organization in the edit dialog or Organization Users. That deletes their login, and they must be invited again to return.

Upload A Photo

Choose the photo control on a person’s row to upload a profile picture used in lists and on operational screens. You can always change your own photo; changing another person’s needs users.edit. Arcus confirms with “Profile photo updated” or says “Upload failed”.

Statuses

Messages You May See

What Happens When You Act

  • Access: a role, location or permission change takes effect for the person without anything else to turn on. Deactivating signs them out at once.
  • Email: an invitation email goes to the invitee, and a password reset code goes to the person you choose. Nothing is emailed for Mark email verified or Reset MFA.
  • Audit: invitations, edits, location changes, membership changes, removals, MFA resets and self-grants are recorded in the Audit Log.
  • Other screens: the list refreshes for other signed-in administrators without a reload.
  • Accounting and inventory: none. A person’s access does not change any posted record.

Common Blocks

  • Invite User is disabled: your role lacks users.create.
  • No row menu appears: your role has neither users.edit nor users.delete.
  • Edit is disabled on a row: it is an owner and you are not.
  • Set PIN is disabled on another person: see the reason above. Ask the person to set it from their Profile.
  • A person cannot see inventory or fulfillment work: check their location access in the edit dialog.
  • A person cannot sign in: open Send password reset code and read the status first. A lockout from wrong passwords ends on its own.

User Management

Invite across companies, manage organization access and reset MFA from Organization Users.

Roles and Permissions

Review system roles, build custom roles and choose exact permissions.

Profile and Security

Set your own PIN, password and two-step sign-in.

Audit Log and Compliance

Review access changes after the fact.