Manage users & roles
This guide covers the core admin flow: inviting a user to a project and giving them the right roles, which control what they can do in MaxTrax.
Before you start
Section titled “Before you start”- You need a Corporate Administrator role or higher.
Invite a user
Section titled “Invite a user”- Open Users from the admin navigation, then select New user.
- Enter the user name and email (both required — email is how the new user redeems their invite). Display name is optional.
- Check the roles to grant (see Understanding roles below) — you can leave this blank and set roles later.
- Choose project scope: leave All projects checked, or uncheck it and select one or more projects by name from your authorized list.
- Select Create & invite.
MaxTrax shows a one-time invite token right after creation, with a clear warning that it’s shown once and can’t be retrieved again. There’s a Copy token button, and below it a ready-to-use redeem link with its own Copy link button — send either one to the new user through your own out-of-band channel (chat, in person, and so on); the link just saves them a step. Select Done once you’ve saved it — it won’t be shown again.
The new user sets their password
Section titled “The new user sets their password”The invited user opens the link you sent them, which takes them to a Set your password page. They enter and confirm a new password and submit — MaxTrax confirms their password is set and tells them to sign in with the username your admin panel showed you. If the link has already been used, or has expired, the page tells them to ask you for a new invite.
Understanding roles
Section titled “Understanding roles”The Roles you check on a user are the actual permissions MaxTrax enforces. They describe what a person can do — broader than the four task guides in this help center (inspector, NDT technician, welder, admin). Roles are cumulative (each role includes everything the roles below it can do), so most users need just one; a user can hold more than one, and their most powerful role wins.
- Reader — view-only access, no changes.
- NDE Inspector — records inspection and NDT results (the tasks in Record an inspection result and Record a film interval result).
- Weld Associate — day-to-day weld data entry: create and update welds, complete welds, and everything a Reader and NDE Inspector can do.
- Project Associate — broader project-level access for coordination roles (engineering, document control).
- Project Administrator — administers a single project’s setup.
- Corporate Administrator — full administrative access across projects: users, roles, project and global settings, custom fields and reports, and the audit log. Managing users and roles needs this role or higher.
- System Administrator — reserved for CSDS operator use; you won’t normally assign this to a project user.
For the full picture — a capability matrix of exactly what each role can do, and how roles combine with project scope — see Roles & capabilities.
If someone tries to reach a screen their roles don’t cover, MaxTrax shows an Access required message naming what’s needed (for example, “You need a Corporate Administrator role or higher to manage users”).
Change or remove access
Section titled “Change or remove access”On the Users list, each row’s Manage menu offers:
- Edit roles & scope — opens a drawer with two independent sections, Roles and Project scope, each with its own save button. Changes take effect the next time that user signs in.
- Lock / Unlock — locking blocks sign-in without changing roles or scope.
- Deactivate / Reactivate — deactivating removes the user from active use; reactivating restores it.
Grant facility party-admin
Section titled “Grant facility party-admin”A facility party-admin administers a facility — its projects’ administrative metadata and, in time, who else administers it. You grant and revoke this seat from the same Edit roles & scope drawer, in its Facility party-admin section.
- You can only grant facilities you administer yourself. The facility picker lists exactly those facilities — if you administer none, the control is disabled and says so. This is deliberate: you can never hand someone authority over a facility you don’t hold yourself.
- To grant: pick a facility and select Grant. The user gains the facility party-admin seat for that facility.
- To revoke: select Revoke next to a facility in the user’s current list, then Confirm — revoke removes administrative authority, so it asks first.
A facility party-admin seat is enforced only inside the admin surface; it never changes what the user can do in day-to-day project work. Every grant and revoke is recorded in the audit log.
Two-factor authentication for administrators
Section titled “Two-factor authentication for administrators”Your organization can require every administrator to use two-factor authentication. When that requirement is on, an administrator who signs in with a MaxTrax password and hasn’t set up an authenticator app yet doesn’t reach MaxTrax at all — they land on Set up two-factor authentication and can go no further until they finish it.
The administrator completes the setup themselves, in that same sign-in — no one has to unlock anything for them:
- Scan the code shown with an authenticator app, or use Or enter this key manually.
- Type the app’s 6-digit code into Authenticator code and select Verify and finish.
- On Save your recovery codes, select Copy codes or Download .txt, select I have saved my recovery codes, then select Continue. The codes can’t be shown again, and Continue stays unavailable until you select that checkbox.
From the next sign-in on, that administrator is asked for their authenticator code as normal.
If setup is interrupted before step 2 finishes, nothing is lost — sign in again and it restarts.
Keep access aligned
Section titled “Keep access aligned”Roles and project scope are how MaxTrax keeps each person’s access focused on what their job needs. Review them periodically so access matches who is actually on the job.
Related
Section titled “Related”- Roles & capabilities — what each role can do, in full.
- Admin overview
- Welder qualifications settings
- Getting started — roles and vocabulary.