User Management & Invitations
Summary
The Users module is where Super Admins manage the full lifecycle of platform access for their organization. Covers: What User Management Does, Navigating the Users Module, Inviting a New User.
What User Management Does
- Inviting new users.
- Assigning and updating roles.
- Viewing all users and their roles in one place.
- Removing users.
Effective user management is both an operational and a security responsibility.
Roles in GC Surge
You assign a role to every user when you invite them, and a Super Admin can change it later from the Edit User dialog. Two roles are available:
- Super Admin — full access: site creation, user management, NOVA99x configuration, and subscription/billing.
- Operator — scoped to operational work only: Alarm Center and Operator Performance. From within Alarm Center, Operators can open ZenMode and Video Search. An Operator cannot open My Subscription, see invoices or per-camera cost figures — those are Super Admin-only. NOVA99x is always active and cannot be disabled by any user.
By least privilege, default new users to Operator — it covers everyone who handles alarms — and reserve Super Admin for people who genuinely need administrative control. If unsure, invite as Operator and promote later.
Navigating the Users Module
- Open the Users section from the sidebar navigation.
- The main view displays a table of all users associated with your account, including: Avatar, name, and email address.GC Surge Role.Shift — a dropdown to assign the user to one of the configured shifts (Default, or any shift created via Configure shifts).Actions: Edit User and Remove User buttons appear directly on each row.
Above the user table, a Search field lets you filter users by name or email. The + Invite New User button (top right) opens the invitation form.
Inviting a New User
- Navigate to the Users module.
- Click + Invite New User.
- Fill in the invitation form: First name and last name (both required).Email address.Country code and phone number (optional).Most accounts use email-based invitation and recovery, so phone is nice-to-have. It matters mainly if the user is also an on-site contact whose Site Key is sent over WhatsApp. Desk-bound operators can usually skip it.GC Surge Role — select from the dropdown. Default to Operator unless the person needs administrative control; you can promote to Super Admin later.Shift — appears only once Operator is selected, pre-filled with Default (Default). Pick any shift created in Configure shifts. Super Admins have no Shift field, and show “—” in the Shift column of the User List.Profile photo (optional) — purely cosmetic and skippable. New users can upload their own on first sign-in; only set it here when pre-populating the directory for a large team. The uploader recommends a square image, at least 200×200px.
- Click Send Invitation. A User invited successfully confirmation appears at the top of the screen and the user count in the User List increases immediately.
What the invited user receives.
- Check your inbox for an email from noreply@nxgen.io containing a link to set your password.
- Open the email and click Set Password & Verify Email.
- The Reset your password page opens. Set a password that meets these requirements:8+ charactersUppercase letter (A–Z)Lowercase letter (a–z)Number (0–9)Symbol (e.g. !@#$%^&*)
- Confirm your password. No separate sign-in or confirmation screen appears — you go straight to the Account Setup Wizard.
- After setting the password, you are redirected directly to the 3-step Account Setup Wizard: Welcome (review your Operator role and select your language), Your profile (confirm your display name and optionally Add photo), and Your sites (the locations you will be monitoring). An All set screen then confirms sites and alerts are routed to your queue. Click Enter Surge to land on the Operator Dashboard.
You will also receive an account verification email.
Cancel discards the invite form without sending anything — no email goes out, no user is created, and nothing is saved as a draft. If you cancel by mistake, re-open Invite New User and re-fill. CSV-based bulk invitations are on the roadmap; today each user is invited individually.
Editing a User
- Locate the user in the Users table.
- Click the pencil (edit) icon in the Actions column of their row.
- Choose the new role from the GC Surge Role dropdown (under Account Settings).
- Click Update User. The user’s permissions update immediately.
What you can change. Editable fields: first name, last name, phone number, GC Surge role, profile photo. The email address is locked — it’s the user’s account identity. To change an email you invite a new user with the new address, transfer their role and entity assignments, then deactivate the old account once the new one is verified. Audit history doesn’t carry over, by design, since audit entries point to the account that performed them.
How a role change applies. After you click Update User, the user is not signed out; on their next page navigation or login their sidebar updates — a downgrade hides modules they no longer have, an upgrade reveals new ones. The change is recorded in the audit trail with who made it, when, and a before/after diff of the fields. There’s no notification email by default, so let the user know out-of-band if the change affects their workflow.
Removing a User
Removing a user is a soft delete: it deactivates the account rather than erasing it. Access is revoked immediately — all active sessions end and any in-progress alarms the user was handling are released back to the queue — but their historical actions remain in the audit trail under their name and account ID for traceability. A Super Admin can reactivate them later from the Users list, restoring their role and entity assignments. Use this when a team member leaves or changes responsibilities. For a hard delete (GDPR data removal), contact GC Surge support.
- Open the Users module from the sidebar.
- Locate the user in the table.
- Click the Remove User button (trash icon) in the Actions column of their row. Access is revoked immediately.
Best Practices
- Remove access promptly when a team member leaves or changes responsibilities.
- Invitations expire after 72 hours. If a recipient did not receive the email, re-invite them rather than waiting for the link to expire.
- Limit the number of Super Admin accounts — roughly two or three for a small monitoring station, five or six for a larger one. Every Super Admin account is a potential attack surface: if one is compromised, the attacker gains every administrative power on the platform. Operators who only need event access should be invited as Operator, not promoted for convenience. Audit the Super Admin list at least quarterly and downgrade or deactivate anyone who no longer needs it.
- Use business email addresses. Personal email addresses make account recovery harder and create risk if a user leaves but retains access to their personal email.
Account Settings
Settings is the personal configuration area in GC Surge. Click Settings in the bottom-left sidebar to open the modal. It contains four sections: Personal Information, Change password, Report schedule, and Delete tenant. To switch between sections, click the section name in the left panel.
Personal Information
Available to all users. Displays your account details. Only USER NAME is editable — all other fields are read-only. A Language selector (flag dropdown) appears at the top of the profile card and lets you switch the platform interface language between English (ENG) and Deutsch (DE).
- USER NAME — your display name shown to other users and in Top Performers. Click the pencil icon to edit. Changes take effect immediately.
- EMAIL — the email address linked to your account. Read-only. To change it, contact your Super Admin.
- ROLE — your assigned role (Super Admin or Operator). Read-only. Role changes must be made by a Super Admin from the Users screen.
- USER ID — your unique system identifier. Read-only. Referenced in audit trail entries.
Report Schedule
Super Admin only. Choose when the CPO/APT report email should be sent for this account.
- Hourly — a report is sent every hour.
- Daily — a report is sent once per day.
- Weekly — a report is sent once per week.
- Monthly — a report is sent once per month.
Time zone — select the time zone used to calculate when each reporting period starts and ends. Time of day — select the hour when the report email is sent. Day of week — for weekly reports. Day of month — for monthly reports (1–31).
Click Save Schedule to apply.
Change Password
Available to all users. Lets you update your account password without leaving the platform.
- Enter your Current password.
- Enter your New password.
- Enter Confirm new password (must match).
- Click Update Password.
Delete Tenant
Super Admin only. Permanently deletes your entire GC Surge organization — all sites, devices, users, alarms, and configuration. This action is permanent and cannot be undone.
To delete the tenant: open Settings → Delete tenant → click the red Delete Tenant button and confirm.