Personal, traceable and safe work
From account activation to your own data: This entry not only explains the operation, but also the purpose of the registration and the limits of access.
1. Create an account and activate it
- Open Users → Register and enter username, name, email address, password and language.
- The new account is initially registered, but not yet confirmed. It does not yet receive normal member access.
- dbxapp sends a time-limited confirmation link to the specified address. Only the link confirms that the address is reachable.
- After successful confirmation, the account is unlocked and can log in regularly. If an installation requires an additional organizational release, an administrator takes over.
2. Understand registrations and benefits
Underground Users Login The login works with username or e-mail address and the personal password. After successful testing, dbxapp generates a new session.
Registration is not just an access barrier. It combines each permitted action with a user identity and enables:
- personal language, design, profile and session settings,
- menus, modules and data released only for their own roles,
- secure allocation of own records and processes,
- traceable changes, as far as the respective module trace or logging has activated.
When logging out, the current registration is terminated. On shared devices, the browser should then be closed.
3. Forgetting the password
- On the login page Forgot the password? Select.
- Enter user name or e-mail address. The answer always looks the same and therefore does not reveal whether an account exists.
- Open the one-time link sent by email within 60 minutes.
- Enter a new password twice according to the displayed policy.
The token is not stored in plain text, can only be used once and loses its validity after expiration. Upon successful switching, dbxapp will terminate all previous sessions of this account. Anyone who does not receive an e-mail or no longer has access to the stored address will contact an administrator.
4. Own data and owner principle
Many records have a field owner. When created, dbxapp enters the user ID there. In the case of a DD with owner rights, a user may then only read, modify or delete the records he owns. Administrator rights and explicitly configured group rights are separate, controlled exceptions.
Example: Two customers use the same request form. Both work technically in the same table, but only see their own requests, as long as the DD is available for reading and changing. owner is limited.
In the personal area, users can access their profile data and the own data offered by the shared modules. An export or extinguishing claim is not a blanket automatism: Scope, storage obligations and release depend on the specific operator and the respective domain module.
5. Properly classify protocols, IP and trace
dbxapp can log successful and failed logins, security events, sessions and system messages. Session data may include, inter alia, user ID, time, IP address and technical browser characteristics. For DDs with activated trace, changes to technical data are also traceable.
These functions increase traceability, but do not replace correct rights configuration. Access to protocols shall be limited to authorised administrators; Storage, evaluation and deletion must fit the purpose and data protection requirements of the operator. Normal users do not get blanket insight into other people's security protocols.