Adding a user — create an account or add an existing one
The form checks the email as you type to determine whether you are creating an account or adding someone who already has one. You do not set a password: Noxti generates a temporary one and emails it, so an email address is required.
The Add user button opens a form that changes as you type the email address. This is intentional — the system checks in the background whether the address already exists.
Step by step
- Go to Configuration → Team & Access → User Accounts.
- Click Add user. The Add new user panel slides out from the right.
- Enter Email and wait a moment. After a fraction of a second, the system checks the address and switches the form to one of the three scenarios below.
- If the address is unknown, fill in Full name and Username. There is no password field — a blue message explains that a temporary password will be generated and emailed to this address.
- Choose Roles (this field is shown only if you have create permission for
roles), Departments, and Warehouses. The warehouse list narrows to the selected departments. - Leave the Active switch on — turning it off creates the account but leaves it blocked.
- Click the button at the bottom of the panel: Add user for a new account, or Add to company if the email belongs to someone who already has an account.
- If a window asks for a 2FA code, enter the code from your app. After confirmation, the operation runs automatically, and the system will not ask again for the next 15 minutes (2FA confirmation when changing permissions).
- After saving, you will see User created. Password sent to {address}. You do not need to pass anything else along — the employee receives an email with their username and temporary password.
Three scenarios
Unknown email → create a new account
The form shows all fields: Full name, Username, Roles, Departments, Warehouses, and the Active switch.
Email belongs to an existing account → add them to your company
The form collapses to the email, roles, departments, and warehouses, and the button changes to Add to company. You are not creating a second account — you are giving an existing person access to your company.
That person is not switched to your company automatically. Your company appears in their company list, and they switch to it themselves when they want (My companies — active company and switching context).
Email is already in this company → warning
The form shows a warning and blocks saving.
How a new user gets a password
An administrator never enters someone else’s password. Noxti sends an email from the system mailbox:
- After a new account is saved, the employee receives “Welcome to Noxti — {company}”. It contains their username, a 14-character temporary password (excluding easy-to-confuse characters: 0/O, 1/l/I), and a Log in button.
- The employee signs in with the temporary password and is taken to My account → Security. The Set your own password banner takes them to the password change form — they cannot do anything else until then.
- They enter the temporary password as the current password, choose their own, and from then on only that password works (Changing your own password — requirements and when confirmation is needed). The new password must meet the usual requirements, which the change form checks.
The temporary password is valid for 72 hours after it is sent. If the employee does not set their own password in that time, the temporary password stops working — send a new one using Send new password in user editing (Forgotten password and blocked access — what an administrator can and cannot do).
This email appears in the sent-email log, but the password is masked as “••••••••”.
When an existing account is added to a company, no password is sent — that person already has one.
If the email is not delivered
If Noxti cannot send the email — the system mailbox is not configured or the mail server refuses delivery — the account is not created. You see an error and can try again. This is why an email address is required for a new account.
There is no self-service “Forgot password” option either. Anyone who has forgotten their password must ask an administrator for a new one (Forgotten password and blocked access — what an administrator can and cannot do).
Users without role permission cannot assign roles
The users permission allows you to create an account. Assigning a role requires the roles permission — the server rejects roles submitted by someone who only has users, even if the form let them select roles.
Also, someone who is not a company administrator cannot assign the administrator role, even if they have write access to roles. Only an administrator can create another administrator.
Login and email are case-insensitive
Uniqueness checks ignore letter case, so Jan.Kowalski and jan.kowalski are the same username. Users can sign in with either their username or email address. Leaving the username field blank means they sign in with their email only.
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo