Training guide · Users & Settings

Two ways to log in, one system deciding what you can touch

NiyuSuite has two separate account types — a cloud Business User (email + password, uses a licensed seat) and a local POS User (name + PIN, doesn't) — each with its own fixed role list and its own module/permission grid layered on top. Settings is where the rest of the business gets configured: offices, tax, approval thresholds, warehouse names, and the subscription itself. This guide covers both, plus the audit trail that watches what everyone actually does.

Modules Users & Security, Settings Access needed Owner or Admin (most tabs) or the specific "Manage Users" / "Access Settings" permission Time ~16 minutes

Users & Security

Users & Security

Four tabs: 👤 Users, 🔒 Security Roles & Permissions, 🧭 Security Process, and 📋 Audit Log. Everything about who can log in, what they're called, and what they're allowed to touch lives here.

1

Two account types, not one

Clicking + Add User asks which kind of account you're creating first, because they work differently underneath: a Business User signs in with an email and password from anywhere and consumes one of the tenant's licensed User Seats; a POS User unlocks a till or warehouse screen with a 6-digit PIN, stays local to the workspace, and doesn't use a seat at all. Both get full name, role, and module access — the login method and licensing are what differ.

Users & Security · Users

Business Users — email + password, uses a seat

NameEmailRoleService ModulesLast LoginStatus
Ankit Sutariaankit@harborfresh.comOwnerAll modules31/07/2026 09:14Active
Priya Nairpriya@harborfresh.comAdminAccounting, Reports30/07/2026 16:02Active

POS Users — 6-digit PIN, no seat used

NameUsernameRoleOffice AccessWarehouse AccessStatus
Sam Fletcher (you)sfletcherPOS CashierBNE onlyActive
Wei ZhangwzhangWarehouse OperatorUnrestrictedMain DCActive
No email invite — there's no "send an invitation" step for either kind — you set the password (Business User) or PIN (POS User) directly when creating the account. A brand-new POS user is forced through a "Set Your PIN" screen on first login, with no way to skip it.
2

Roles come from a fixed list, not free text

You pick a role from a dropdown — you can't type a custom title. Business Users choose from just three: Owner, Admin, or Service User ("standard business access — permissions determined by assigned modules"). POS Users choose from ten, built around shop- floor jobs: Admin, Manager, Master Data Editor, POS Cashier, eCommerce Operator, Warehouse Operator, Finance Officer, Production Operator, Reporting & Analytics, and User Administrator.

+ Add Business User
Priya Nair
priya@harborfresh.com
••••••••
Admin

📦 Service Modules — quick template: Finance Officer

Accounting ✓Reports ✓CRMWarehouse eCommercePOSTMSDashboard ✓
+ Create UserCancel
Quick templates — instead of ticking modules one at a time, a template dropdown (CRM/Sales, Finance Officer, Warehouse Supervisor, eCommerce Manager, POS Manager, Logistics Coordinator, Operations Manager, or Full Access) fills in a sensible starting set, which you can still hand-adjust afterward. There's also a standalone "🧾 Expense claims only" toggle for a login restricted purely to the mobile expense portal.
3

Permission overrides sit underneath the role

Role and module access decide the broad shape of an account; a Permission Overrides panel underneath lets you grant or remove individual actions without changing the role itself — the same nine permission groups apply to both account types (Master Data, Transactional/POS, Finance, Administration, and others). Each role applies a sensible default set of these on creation; a ↺ Re-apply from role & modules button resets any manual overrides back to that default if things drift.

Permission Overrides · Finance Officer

Finance

General Ledger & Accounting
Post Manual Journal Entries
View & Record AP Payments
View & Record AR Receipts

Administration

Access Settings / Admin Panel
Manage Users & Roles
View Audit Log
Manage Office Profiles
↺ Re-apply from role & modules💾 Save Changes
Rechecked live, not just at login — a sensitive action like approving a CGT disposal or posting a manual journal isn't just hidden in the menu for the wrong role — the server checks the exact permission flag on the user's record fresh on every single request, so revoking it here takes effect immediately, even on a device that's already logged in.
4

Audit Log and unlocking a locked-out account

📋 Audit Log is a searchable record of who did what and when — search by user, action, or details, filter by action type, and ⬇ Export CSV for a compliance request. Up in the header, 🔓 Unlock Account lists anyone currently locked out (too many failed PIN/password attempts) with a one-click 🔓 Unlock — itself logged as its own audit entry.

Audit Log
🔍 Search user, action, details…All Actions
TimeUserActionDetails
31/07/2026 09:02Priya NairUNLOCKUnlocked account: Sam Fletcher
30/07/2026 17:45Ankit SutariaPERMISSION_CHANGEGranted canPostJournals to Priya Nair
⬇ Export CSV
No user is ever silently deleted — the toggle here is Enable/Disable, not delete — a disabled account keeps its full audit history and can be re-enabled later without losing anything.

Settings

Settings

A left-hand tab list covering everything from company details to the subscription itself. The tabs used day to day are Office Profile, Loyalty, Pricing Tiers, Warehouse, POS Batch Tracking, Office/Sync, Import Center, ERP Controls, and License — a couple of specialist tabs (QuickBooks Transition migration, Messaging branding) exist for specific onboarding needs and aren't covered in depth here.

1

Office Profile: the business itself

Office Profile is where each physical location's legal details live — name, country (AU/US), tax rate, ABN/EIN, address, logo, and an invoice footer message — with one office flagged Set as Primary/Head Office. A separate Default Tax Rate field acts as the AU GST fallback (10%) when an office doesn't override it, and Workspace Branding controls the accent colour and logo shown across the whole app.

Settings · Office Profile
Harbor Fresh — Brisbane
Australia
51 824 753 556
10%

☑ Set as Primary/Head Office

+ Add OfficeSave
2

Loyalty, Pricing Tiers, Warehouse, and POS Batch Tracking

Four smaller, single-purpose tabs sit alongside Office Profile: Loyalty Program (points per dollar, points needed per $1 reward, Silver/Gold thresholds), Pricing Tiers (group-level customer discount tiers), Warehouse (WMS) (warehouse name and named receiving/dispatch docks), and POS Batch Tracking (a single toggle that turns on batch/expiry capture at the till). Each has its own Save … button rather than one global save for the whole screen.

Save Loyalty SettingsSave Pricing Tiers Save WMS SettingsSave POS Settings
Office/Sync tab — also worth knowing about: it shows which office and warehouse you're currently working in, lets you switch or add another, and has a 🔄 Force Sync Now button plus the POS Terminal and Warehouse registries (+ Add Terminal / + Add Warehouse) for multi-device setups.
3

ERP Controls: approval thresholds and costing method

This is where the business sets its own guardrails — dollar/percentage limits above which an action needs a second person's approval, and how inventory is costed. Nothing here changes what a role can do (that's Users & Security) — it changes at what size an otherwise-allowed action needs a second look.

Settings · ERP Controls
Approval ThresholdLimit
Stock adjustments$250.00
Discount %15%
Supplier / customer payments$5,000.00
Credit notes / Debit notes$500.00
Manual journals$1,000.00
Bank reconciliation bypass$50.00

Inventory Costing

Weighted Average
Enabled

☑ Post COGS on sale

4

License: seats and terminal activations

The License tab shows the subscription Plan and Status, how many User Seats are used versus available (this is what a Business User consumes and a POS User doesn't), and every POS terminal that's ever activated against this tenant — each row fingerprinted to a specific device, with the one you're on now flagged THIS DEVICE.

Settings · License
Plan
Growth
Status
Active
User Seats
4 / 10
TerminalDeviceActivatedStatusActions
POS-01Counter iPad THIS DEVICE02/01/2025ActiveDeactivate
POS-02Back Office PC14/03/2025ActiveDeactivate
Freed a seat by mistake? — deactivating a terminal here doesn't touch any User account or its permissions — it only revokes that specific device's activation, so a replaced till can be swapped in without recreating any users.