Under **Employees** your company administrators create user accounts – for your own staff and, as a logistician, also for the staff of your clients. You decide what each user may see and do, either with a [role (permission group)](/company/roles.md) or with individual permissions. The list also shows when a user last logged in and whether two-factor authentication is active.

![Screenshot: Employee overview with columns first name, last name, e-mail address, last login and 2FA](/company/images/employees-overview.png)

## Before you start

- Your user needs the permission *Company Settings › Employees*. To choose a role or open **Manage Roles**, you also need the permission for roles. Ask your administrator.
- Your package must still have room for another active user. Users of your clients count against your package as well. If the limit is reached, contact X-Sitter support.
- If you want to work with roles, create them first under [Roles](/company/roles.md).

## Step by step

### Create an employee

1. Open **Company Settings › Employees** (*Firmen Einstellungen › Mitarbeiter*). You see the **Employee Overview** (*Mitarbeiter Übersicht*).
2. Click **New employee** (*Neuer Mitarbeiter*).
3. Fill in salutation (**Mrs.** / **Mr.**), **First name** (*Vorname*) and **Last name** (*Nachname*).
4. Switch **Status** on, so the user can log in.
5. In **Company** (*Firma*), choose your own company or one of your clients.
6. Enter an **E-mail address** (*E-Mail Adresse*) and/or a **Username for login** (*Benutzername für Login*). At least one of them is required.
7. Leave **Password** (*Passwort*) empty to have a temporary password generated, or enter one yourself.
8. Choose a **Permission group** (*Rechtegruppe*) – or leave it empty and tick the individual **Access rights** (*Zugriffs-Rechte*) in the tree below.
9. Optionally choose a **Dashboard template** (*Dashboard-Vorlage*).
10. Click **Save** (*Speichern*).

If you left the password empty, X-Sitter shows the generated temporary password right after saving: "Saved! Here is the initial password: …". Pass it on to the user. If an e-mail address is entered, the new password is also sent to the user by e-mail – you can adapt this email under [System email templates](/company/mail-templates.md). On the first login, the user follows the steps in [First login](/account/first-login.md).

### Assign permissions

You have two options:

- **Permission group:** choose a role in **Permission group**. The user gets exactly the permissions of this role. Individual access rights are ignored and the rights tree is hidden.
- **Individual access rights:** leave **Permission group** empty and tick the permissions in the **Access rights** tree. Use the search field, **Expand all** / **Collapse all** and **Select all** to work faster.

!!! warning
You can only grant permissions that you have yourself. You cannot change or remove your own permissions – ask another administrator to do that.
!!!

![Screenshot: Access rights tree in the employee form with the search field and some modules expanded and ticked](/company/images/employees-access-rights.png)

### Edit or deactivate an employee

1. In the Employee Overview, click the edit button next to the user.
2. Change the fields you need. To lock a user out, switch **Status** off.
3. To give the user a fresh dashboard, choose a template and tick **Reset dashboard and apply template** (*Dashboard zurücksetzen und Vorlage anwenden*).
4. Click **Save**. You see "The information has been saved".

Changed permissions take effect the next time the user logs in.

## Fields and options

| Field | Meaning |
|---|---|
| **Salutation** | Mrs. (*Frau*) or Mr. (*Herr*). |
| **Status** | On = the user can log in. Off = the account is deactivated. Only active users count against your package. |
| **Company** (*Firma*) | Your own company or one of your clients. A user of a client only sees the data of that client. |
| **Manage employees** (*Mitarbeiter verwalten*) | Only when editing an existing user. Yes = the user is an administrator of the company and may manage employees. |
| **E-mail address** / **Username for login** | Used to log in. At least one must be filled in, and both must be unique in X-Sitter. |
| **Password** | Empty for a new user = a temporary password is generated and shown. Use lower and upper case letters, digits and special characters – at least 6 characters, better more than 10. |
| **Permission group** (*Rechtegruppe*) | Role whose permissions the user gets. If set, individual access rights are ignored. |
| **Dashboard template** (*Dashboard-Vorlage*) | Defines which widgets the user sees when opening the [dashboard](/insights/dashboard.md) for the first time. **Automatically by user role** (*Automatisch nach Benutzerrolle*) is the default; you can also choose one of your own templates. |
| **Reset dashboard and apply template** | Only when editing: replaces the user's current dashboard with the chosen template. |
| **Access rights** (*Zugriffs-Rechte*) | Individual permissions, only used without a permission group. |

The list column **Last login** (*Letzter Login*) shows when the user last logged in, **2FA** whether two-factor authentication is set up (see [Login and two-factor authentication](/account/login-and-two-factor.md)).

![Screenshot: Lower part of the employee form with permission group, dashboard template and the reset checkbox](/company/images/employees-dashboard-template.png)

## Good to know / Troubleshooting

| Message | Cause | Solution |
|---|---|---|
| "Please enter an email address or a username." (*Bitte eine E-Mail-Adresse oder einen Benutzernamen angeben.*) | Both fields are empty. | Fill in at least one of them. |
| "That email address already exists in the system." (*Die E-Mail-Adresse existiert bereits im System.*) | Another user already uses this e-mail address. | Use a different e-mail address. |
| "That username already exists in the system." (*Der Benutzername existiert bereits im System.*) | The username is taken. | Choose a different username. |
| "You cannot remove your own permissions" (*Du kannst Dir selbst keine Rechte entfernen*) | You tried to change your own account's permissions. | Ask another administrator. |
| Package limit message for users | The user limit of your package is reached. | Deactivate users you no longer need or contact X-Sitter support. |
| A user does not see a menu item after the change | Permissions are loaded at login. | The user logs out and in again. |
