April 12, 2026 | 6 min read

This article covers back-office users (Managers), roles, permissions, and security settings. It is written for Company Admins and Security Admins.

The navigation paths below start from Users in the sidebar. The menu refers to the three-dot action menu located at the top right of the Users page.

Adding a Manager

Go to Users and click Add Manager. Fill in:

Tip: Check Send login details by email to deliver credentials directly to the new manager upon saving.

Deactivating or Removing a Manager

Open Users and select the manager's profile:

Roles and Permissions

Roles determine what a manager can do. Event and module permissions determine where they can do it. A manager can hold more than one role simultaneously.

Role Name Scope & Responsibilities
Company Admin Full access to all company settings, accounts, and events.
Security Admin Manages manager accounts, security policies, account unlocks, and security alerts.
Director Oversight role; receives daily summary emails from the Eventact Agent regarding company performance.
Projects Admin Manages event-level settings, modules, and configurations.
Operator Day-to-day operational access (registrations, attendees, check-in).
Bookkeeper Access restricted strictly to financial data and accounting.

Event and Module Permissions

A manager's access can be scoped to specific events and specific modules within them (such as Registration, Abstracts, Website, or Meetings). Use this to keep staff working on one client's project isolated from another client's data.

To assign: Go to Users, open the manager's profile, navigate to the Permissions section, and select the designated events and modules.

External Access for Customers and Contractors

Individuals who only need to view data without managing operations should not receive a back-office account. Provide them with access through the External Reporting Portal, which supplies real-time reports without granting access to internal management tools.

Multi-Factor & Risk-Based Authentication (RBA)

At minimum, a second factor is required for every new or unrecognized device. Based on company security policy and risk signals (such as an unfamiliar network or location), verification can be required on every session.

Four delivery methods are supported: Authenticator App, WhatsApp, SMS, and Email.

Why Use Authenticator Apps for On-Site Staff

WhatsApp, SMS, and Email rely on carrier reception and active connections. Authenticator apps (such as Google Authenticator, Microsoft Authenticator, or Apple Passwords) generate codes locally on the device using standard TOTP algorithms. They work completely offline with zero latency - ideal for venue basements or international travel.

Setting Up an Authenticator App

  1. Open the avatar menu (top right) → My Account.
  2. In the Authenticator App card, click Set Up Authenticator App.
  3. Scan the QR code with the authenticator app.
  4. Enter the 6-digit verification code.
  5. Click Verify and Enable.

If a manager loses their authentication device, a Security Admin can reset their MFA from the manager's profile under Users.

Security Options

Back-office security options in Eventact
Company-wide security options

All company-wide security policies are centrally managed under Users → ⋮ → Security Options (accessible to Security Admins and Company Admins):

Monitoring and Auditing

Security Notifications

Security Admins automatically receive email alerts for high-risk or notable activity, such as repeated failed logins or exports of sensitive financial data.

Login History

Navigate to Users → ⋮ → Logins to inspect sign-in activity (displayed in your company's timezone):

Column Details Recorded
Manager & Time Who attempted to sign in and the timestamp.
Technical Details IP address, country of origin, OS, and browser.
Result Success status or failure reason (e.g., wrong password, account locked).

Handling Lockouts at a Live Event

Unlocking a Manager Account

If a manager is locked out after repeated failed login attempts or extended inactivity, a Security Admin can navigate to Users, open the manager's profile, and click Unlock.

Unblocking an IP Address

If shared venue Wi-Fi is temporarily blocked due to repeated failed attempts across staff devices:

  1. Go to Users → ⋮ → Blocked IPs.
  2. Locate the blocked address.
  3. Confirm the prompt to unblock the address immediately.

Quick Reference: Who Can Do What?

Administrative Action Navigation Path Required Role
Add or Edit a Manager Users Security Admin or Company Admin
Delete or Deactivate a Manager Users Security Admin
Assign Event & Module Permissions Users → Manager Profile Company Admin
Unlock an Account Users → Manager Profile Security Admin or Company Admin
Update Security Options Users → ⋮ → Security Options Security Admin
Unblock an IP Address Users → ⋮ → Blocked IPs Security Admin
Review Login History Users → ⋮ → Logins Security Admin or Company Admin
Receive Daily Summaries Automated Email Director

Compliance Mapping

Customers who answer security questionnaires or hold their own certifications can use these features as evidence for common access-control requirements.

Feature ISO 27001 (Annex A, 2022) SOC 2 Trust Services Criteria GDPR
Roles and event/module permissions A.5.15 Access control, A.5.18 Access rights CC6.1, CC6.3 Art. 32
Two-factor authentication A.5.17 Authentication information CC6.1 Art. 32
Login history A.8.15 Logging CC7.2 Art. 32, Art. 30
Inactivity lockout, IP blocking A.5.18, A.8.5 Secure authentication CC6.1, CC6.6 Art. 32
Security notifications A.5.24 Incident management planning CC7.2, CC7.3 Art. 33
External reporting app (separation) A.5.15 CC6.1 Art. 25, Art. 32

These features are controls you configure. Your own policy, review cadence, and documentation are still required for certification.

Recommendations

Read more