The Users section is where administrators manage everyone who interacts with OptimiDoc — the people who print, copy, and scan at devices, and the administrators who configure the system. From here you create and edit accounts and their credentials, organise people into departments and groups, assign web-interface roles and device permissions, run bulk operations, and import or synchronise accounts from Active Directory, Azure AD, Google Directory, or CSV files.
How User Management Works
OptimiDoc separates who a person is from what they are allowed to do:
-
User accounts hold identity and credentials. A single account can carry several credentials of each kind — one or more login names, e-mail addresses, PINs, and registered ID cards — so the same person is recognised however they authenticate, whether at a device panel or in the web interface. See Managing Users.
-
Groups carry permissions. A group defines the web-interface role, the device operations (print, copy, scan, colour) its members may perform, and the scan workflows, print connectors, and billing codes they may use. A user receives the combined permissions of every group they belong to. See Groups.
-
Departments describe organisational structure. They drive reporting and cost allocation, scope the Department Manager role, and — when associated with a group — grant that group to everyone in the unit. See Departments.
-
Import and synchronisation keep the account database aligned with an external directory, so larger deployments rarely create accounts by hand. See User Import.
Every user implicitly belongs to the built-in Everyone group, which sets the baseline role and permissions for the whole system. Other group memberships adjust permissions relative to that baseline.
Web Interface Roles
A user's effective role is the highest level among the Everyone group and all the groups they belong to (directly or inherited through their department). The built-in administrator account (user ID 1) always retains administrator access.
|
Role |
Typical use |
|---|---|
|
User |
Standard end user — personal self-service (My Account), own jobs, and reports |
|
Department Manager |
Management limited to the user's own department — its users, jobs, and reports |
|
Manager |
Organisation-wide visibility of users, jobs, and reports without full system administration |
|
Admin |
Full administrative access to the web interface and all configuration |
|
Local Admin |
The highest level in the hierarchy, granting full administrative access |
Roles are assigned on the group, never directly on the user — see Groups for how to set a group's role and how overlapping memberships resolve.
In This Section
|
Section |
Description |
|---|---|
|
Create, edit, and delete user accounts with full control over credentials, departments, groups, and account settings |
|
|
Define permissions, web-interface roles, and allowed device operations through group membership |
|
|
Organise users into departments for reporting, access control, and organisational structure |
|
|
Perform bulk actions on many users at once — PIN generation and delivery, QR codes, and data export |
|
|
User self-service page for changing passwords and PINs and managing an authentication certificate |
|
|
Import and synchronise accounts from Active Directory, Azure AD, Google Directory, or CSV files |
In Summary
-
Accounts store identity and one or more credentials (login, e-mail, PIN, card).
-
Permissions come from groups (role + device operations + access rights); every account belongs to the Everyone group.
-
Departments provide organisational structure and scope the Department Manager role.
-
Use User Import to create and keep accounts in step with Active Directory, Azure AD, Google Directory, or CSV.
Related articles