April 12, 2026 | 6 min read
This article covers back-office users (Managers), roles, permissions, and security settings. It is written for Company Admins and Security Admins.
The navigation paths below start from Users in the sidebar. The ⋮ menu refers to the three-dot action menu located at the top right of the Users page.
Go to Users and click Add Manager. Fill in:
Tip: Check Send login details by email to deliver credentials directly to the new manager upon saving.
Open Users and select the manager's profile:
Roles determine what a manager can do. Event and module permissions determine where they can do it. A manager can hold more than one role simultaneously.
| Role Name | Scope & Responsibilities |
|---|---|
| Company Admin | Full access to all company settings, accounts, and events. |
| Security Admin | Manages manager accounts, security policies, account unlocks, and security alerts. |
| Director | Oversight role; receives daily summary emails from the Eventact Agent regarding company performance. |
| Projects Admin | Manages event-level settings, modules, and configurations. |
| Operator | Day-to-day operational access (registrations, attendees, check-in). |
| Bookkeeper | Access restricted strictly to financial data and accounting. |
A manager's access can be scoped to specific events and specific modules within them (such as Registration, Abstracts, Website, or Meetings). Use this to keep staff working on one client's project isolated from another client's data.
To assign: Go to Users, open the manager's profile, navigate to the Permissions section, and select the designated events and modules.
Individuals who only need to view data without managing operations should not receive a back-office account. Provide them with access through the External Reporting Portal, which supplies real-time reports without granting access to internal management tools.
At minimum, a second factor is required for every new or unrecognized device. Based on company security policy and risk signals (such as an unfamiliar network or location), verification can be required on every session.
Four delivery methods are supported: Authenticator App, WhatsApp, SMS, and Email.
WhatsApp, SMS, and Email rely on carrier reception and active connections. Authenticator apps (such as Google Authenticator, Microsoft Authenticator, or Apple Passwords) generate codes locally on the device using standard TOTP algorithms. They work completely offline with zero latency - ideal for venue basements or international travel.
If a manager loses their authentication device, a Security Admin can reset their MFA from the manager's profile under Users.
All company-wide security policies are centrally managed under Users → ⋮ → Security Options (accessible to Security Admins and Company Admins):
Security Admins automatically receive email alerts for high-risk or notable activity, such as repeated failed logins or exports of sensitive financial data.
Navigate to Users → ⋮ → Logins to inspect sign-in activity (displayed in your company's timezone):
| Column | Details Recorded |
|---|---|
| Manager & Time | Who attempted to sign in and the timestamp. |
| Technical Details | IP address, country of origin, OS, and browser. |
| Result | Success status or failure reason (e.g., wrong password, account locked). |
If a manager is locked out after repeated failed login attempts or extended inactivity, a Security Admin can navigate to Users, open the manager's profile, and click Unlock.
If shared venue Wi-Fi is temporarily blocked due to repeated failed attempts across staff devices:
| Administrative Action | Navigation Path | Required Role |
|---|---|---|
| Add or Edit a Manager | Users | Security Admin or Company Admin |
| Delete or Deactivate a Manager | Users | Security Admin |
| Assign Event & Module Permissions | Users → Manager Profile | Company Admin |
| Unlock an Account | Users → Manager Profile | Security Admin or Company Admin |
| Update Security Options | Users → ⋮ → Security Options | Security Admin |
| Unblock an IP Address | Users → ⋮ → Blocked IPs | Security Admin |
| Review Login History | Users → ⋮ → Logins | Security Admin or Company Admin |
| Receive Daily Summaries | Automated Email | Director |
Customers who answer security questionnaires or hold their own certifications can use these features as evidence for common access-control requirements.
| Feature | ISO 27001 (Annex A, 2022) | SOC 2 Trust Services Criteria | GDPR |
|---|---|---|---|
| Roles and event/module permissions | A.5.15 Access control, A.5.18 Access rights | CC6.1, CC6.3 | Art. 32 |
| Two-factor authentication | A.5.17 Authentication information | CC6.1 | Art. 32 |
| Login history | A.8.15 Logging | CC7.2 | Art. 32, Art. 30 |
| Inactivity lockout, IP blocking | A.5.18, A.8.5 Secure authentication | CC6.1, CC6.6 | Art. 32 |
| Security notifications | A.5.24 Incident management planning | CC7.2, CC7.3 | Art. 33 |
| External reporting app (separation) | A.5.15 | CC6.1 | Art. 25, Art. 32 |
These features are controls you configure. Your own policy, review cadence, and documentation are still required for certification.