Which User Page Should I Use?
Arcus has two user surfaces because organization access and entity access are different jobs.- Settings > Users: a handoff card that sends you to the dedicated User Management area.
- Organization Users (Organization > Users): invite users, assign them to one or more entities, edit entity memberships, resend or revoke pending invitations, send a password reset code, mark an email verified, deactivate or remove users, and reset another user’s MFA.
- Entity Team (Settings > Team & Roles > Entity Team): manage users already inside the active entity, edit their role in that entity, set or reset PIN lock, limit location access, upload photos, tune custom permissions, and use the same account access actions.
- Roles and Permissions (Settings > Team & Roles > Roles & Permissions): review system roles, duplicate a role, create custom roles, and choose exact permission keys.
- Role Coverage Report: audit effective permissions across active users.

Organization Users is the best place to invite people and manage multi-entity access.
Invite a User
- In the deck, choose Organization, then Users.
- Select Invite User. The button needs the Create Users permission: without it the button is disabled and says why.
- Review the page: the tiles show Total Users, Active, Pending Invites, and Deactivated, and the tabs All, Active, Pending Invites, and Deactivated filter the table.
- In the Invite User window, enter the user’s email address.
- Choose the starting role.
- Select every entity the user should access.
- Optionally expand Location Access to restrict the user to specific warehouses.
- Optionally expand Custom Permissions for advanced overrides.
- Select Send Invitation. You see “Invitation sent to” the address.

Invites can assign one role across selected entities and can optionally restrict locations or override role defaults.
- Email Address is required.
- Role is required. Owner is hidden unless your own access allows assigning Owner.
- Entities is required. At least one entity must be selected.
- Location Access is optional. Leave it unset for unrestricted location access.
- Custom Permissions is optional and advanced. Leave it closed to inherit role defaults.
- The invitee enters their own first name, last name, and password when accepting the invitation.
Pending Invitations
Pending invitations stay visible on the Organization Users page, on the Pending Invites tab, until they are accepted, revoked, or expired. The table shows the email, role, entity access, status, when it was sent, and when it expires. Use it when someone says they did not receive the invite or when the wrong role or entity was selected.- Resend: sends the invite again without creating a duplicate user, with a fresh expiry date. You see “Invitation resent”. Only an organization owner can resend an owner-role invitation.
- Revoke: asks “Revoke the invitation to” the address, and explains that the link in their email stops working and you can send a new invitation later. Confirm with Revoke and you see “Invitation to” the address “revoked”.
- Expired: the status reads expired. An expired invitation keeps both Resend and Revoke, so you can send it again with a new expiry or clear it.
- Both buttons need the Create Users permission and are hidden without it. Sending an invitation to an address that already has a pending one is refused with “A pending invitation already exists for this email”.
Change a User’s Entity Role
A user can have different roles in different entities. For example, a person may be an admin in a sandbox entity and a viewer in production.- Open Organization Users.
- Find the user.
- In the Entities column, click the role next to the entity code.
- Select the new role.
- Save the inline edit. Only users allowed to assign owner-level access can choose the Owner role. If you do not see Owner as an option, your own access does not allow that assignment.
Manage Access Across Entities
Use Manage Access on Organization Users when a person already has an account and you need to add or remove entity memberships after the original invitation.- Add gives the user access to another entity with the Staff role by default.
- Role changes save immediately for the selected entity.
- Locations opens a per-entity location picker. Leave all unchecked for unrestricted access.
- Remove removes that entity membership and clears that entity’s location assignments.
- Self-edits are limited so admins do not lock themselves out. Ask another owner or admin to edit your own role, entity membership, or location access.
- Organization owner self-grant may appear for the organization owner on entities they do not yet belong to. It requires a reason and is audit-logged as a high-trust action.
Use Entity Team for Day-to-Day Access Changes
Entity Team focuses on the active entity. Use it when the person is already a member of the entity and you need to edit their day-to-day access or shared-workstation setup.
Entity Team is where admins manage role, PIN, photo, active status, and entity-specific access for current members.
- Edit: update the user’s name, role, location access, and custom permissions in the active entity.
- PIN: set or reset a 4 to 6 digit lock-screen PIN for shared workstation use.
- Active: deactivate or reactivate the user’s access in the active entity.
- Remove: remove the user from the active entity without deleting their organization account.
- Photo: upload a profile photo used in user lists and operational surfaces.

The Edit User modal is where role defaults can be narrowed by location access or tuned with custom permissions.
- Email is shown in the edit modal but is not editable there. A sign-in email changes only when its owner confirms a code sent to the new address, from their own Profile, then Change email. An edit that sends a different address is refused with “A sign-in email changes only when its owner confirms a code sent to the new address (Profile, Change email).” Repeating the address it already has is treated as no change.
- Only owners can modify other owners.
- You cannot deactivate your own account.
- Non-owners cannot deactivate owner accounts.
- Location assignment changes are skipped when you are editing yourself.
Location Access
Location access limits where a user can work. It is useful for warehouse, fulfillment, inventory, receiving, and location-specific operations.- Leave location access unset when the user should see all locations in the entity.
- Select locations when the user should only work from certain warehouses or stores.
- Review location restrictions after adding a new warehouse or changing a user’s job.
- If a user cannot see expected inventory or fulfillment work, check their location access before assuming the record is missing.
Custom Permissions
Roles provide defaults. Custom permissions override those defaults for edge cases. Use them sparingly because one-off overrides are harder to audit than standard roles.- Use custom permissions to grant one specific ability without upgrading the whole role.
- Remove custom overrides when the user moves into a standard job role.
- Review high-risk permissions for accounting, settings, users, roles, audit, payments, returns overrides, and inventory overrides.
- Use the Role Coverage Report when you need to inspect effective permissions across users.
Roles and Permissions
Standard system roles are locked. If a system role is close but not exact, duplicate it and create a custom role instead of editing the system role.
System roles are locked. Duplicate a system role when you need a custom version for your business.
- In the deck, choose Settings, then Team & Roles, then Roles & Permissions.
- Review the role list, permission count, and assigned users.
- Choose Duplicate on a system role or Create custom role.
- Name the role clearly, such as Shipping Lead or AP Clerk.
- Select only the permission groups required for that job.
- Save the role, then assign it from Organization Users or Entity Team.

The role editor groups permissions so admins can build a role around the work the user actually performs.
Role Coverage Report
The Role Coverage Report shows effective permissions per active user. Use it during onboarding reviews, offboarding checks, and security audits.
Role Coverage helps admins inspect who has each permission after role defaults and overrides are applied.
Help Someone Who Cannot Sign In
When a teammate cannot sign in, open the actions menu (the three dots) on their row in Organization Users or Entity Team. Two actions sit beside Reset MFA. Both need the Edit Users permission and are hidden without it. Each one opens a window that first shows what the sign-in service says about that person right now: Email (verified or not), Sign-in (allowed or blocked), Account setup, Two-step sign-in, and Lockout. The confirm button works only when the service says the action is available.- Send password reset code: emails a 6-digit code to the person’s address. The code expires in 10 minutes, and the person enters it on the Forgot password page to choose a new password. After it is sent you can copy a link that opens that page with their address filled in. Their current password keeps working until they change it. You see “Password reset code sent to” the address, with how many minutes it lasts. If the address is a test or unsubscribed address, Arcus does not send the email and tells you nothing was delivered.
- Mark email verified: marks the person’s sign-in email as verified. Use it only when you know the address is theirs, for example because their invitation reached it. No email is sent and the password does not change. You see the address “is now verified for” their name.
- It is your own row: “This is your own account. Use your Profile page.”
- It is an owner’s row and you are not an owner: “Only an owner can change an owner’s sign-in.”
- The person is deactivated: “Reactivate this user first. A deactivated user cannot sign in.”
Reset a User’s MFA
Organization admins can reset another user’s MFA when the user has lost access to their authenticator or recovery codes. This clears their authenticator app, all recovery codes, and every passkey or security key. If your organization requires two-step sign-in, they are asked to set up a new factor.- Open Organization Users.
- Find the active user.
- Choose Reset MFA from the actions menu. It needs the Edit Users permission and is not offered on your own row.
- Read the warning carefully.
- Type the required confirmation phrase exactly: “I am resetting MFA for” the person’s name.
- Enter the reason, at least 5 characters.
- Confirm the reset.
Remove or Deactivate Access
Choose the smallest removal that matches the situation.- Deactivate (Organization Users and Entity Team): asks “Deactivate” the person first. They are signed out and blocked from signing in, but their entity access and login are preserved, and you can reactivate them at any time. A deactivated person shows Reactivate instead. You cannot deactivate your own account, and the last owner of an entity cannot be deactivated.
- Remove from entity: removes one entity membership but keeps the user in the organization.
- Remove from organization: needs the Delete Users permission. It deletes their login and revokes all entity access, so they must be re-invited to return. You cannot remove your own account, or the last owner of an entity. A removed person shows Re-invite in place of Reactivate.
- Revoke pending invite: cancels access before the user accepts the invite, after you confirm.
Common Blocks
- User did not receive invite: confirm the email address, resend once, then check mailbox filtering or security quarantine.
- Owner role is not available: only users with owner-level authority can assign owner access.
- User cannot see a location: review Entity Team location access.
- User cannot perform an action: check their role, custom permission overrides, and the Role Coverage Report.
- User cannot sign in after MFA reset: have them complete the required MFA enrollment flow at next sign-in.
- User cannot sign in at all: open their row actions and read the status in Send password reset code or Mark email verified. A person who has not finished their invitation needs the invitation resent. A lock from too many wrong passwords ends on its own.
- A row action is missing or disabled: actions follow your permissions (Edit Users, Create Users, Delete Users), and an action on your own row or an owner’s row can be disabled with the reason shown on hover.
- Admin cannot edit another owner: owner-level users must be changed by another owner.

