The Users page lists the people who can sign in to CoolFocus for your organization.
A user is different from a client, donor, volunteer, or contact. A user is a staff member or team member who needs a login.
Open Settings, then go to Security and choose Users.
You may see views such as All Users or segment views that help you review certain groups of users.
Use the Users page to:
• Review who has access.
• Open a user's profile.
• Check which user group someone is assigned to (each person gets one group — see below).
• Turn Administrator on or off for someone who should have full access to licensed modules.
• Update access when someone's role changes.
• Rename a user's login username.
• Update a user's email address.
• Deactivate or delete a login when someone leaves your team.
• Link the login to a People record using the Linked Person field.
• If you are an administrator, view and change another user's notification settings.
Each user can belong to only one user group at a time. You cannot stack two groups on the same login (for example, both “Staff” and “Volunteer”).
Why CoolFocus works this way
If one person had several groups, those groups could disagree. One group might allow Care and clients; another might deny clients or hide a module. CoolFocus would then have to guess which rule wins — and different combinations would be hard to explain, hard to audit, and easy to get wrong.
So access is intentionally simple:
• One login → one user group → one clear set of permissions for what that person can open and change.
• Administrators are the exception for full access: turning Administrator on gives access to every module your organization is licensed for. User group module checkboxes are not what drive the sidebar for administrators.
How to set this up in practice
Think of each user group as a role profile or access policy for your organization — not as a pile of overlapping labels you attach to one person.
• Build groups that match real jobs or levels of trust (for example Finance, Client services, Events, Volunteer front desk).
• Put each person in the single group that best matches the access they should have.
• If someone’s job truly sits between two roles, create a third group that combines only what they need — do not try to assign both original groups.
• You can still create a narrow group for an unusual role, but start from the high-level policies of “who should see what,” not from stacking every possible group on one account.
• When someone’s role changes, switch their user group on their profile. That replaces the previous group; it does not add a second one.
For how groups control areas, pages, and module settings, see User Groups: What Staff Can Open and Change.
• Administrator — Can open all modules your organization is licensed for. Does not rely on user-group module checkboxes for sidebar access.
• Not an administrator — Sidebar modules come from the user's one user group module permissions. Assign a group and ensure that group allows the modules they need.
Turning on Administrator for someone does not clear their user group field. CoolFocus keeps that assignment because organizations still signed in to CoolFocus 3 use it to control what that person can do there, and administrators are no exception on the CoolFocus 3 side. The User group field stays open for editing on an administrator's profile, so you can still change it if needed.
If someone already has a user group assigned and you turn Administrator off for them, choose a user group before saving. CoolFocus blocks the save and asks you to pick one, so a demoted administrator is never left without any group. If the person never had a user group assigned in the first place, you can turn Administrator off without picking one.
Open a user's profile and edit the Login Username field, then select Save. Usernames can be up to 64 characters and must be unique across your organization.
Renaming the username updates the sign-in name on that person's existing account. It does not create a new user, and it does not change the display name, user group, linked person, access history, or other account settings. CoolFocus saves the change first and then syncs the new username to the sign-in system, so allow a short time before the person can sign in with it.
Every user needs a username. If you save a profile with the Login Username field blank or with only spaces, CoolFocus keeps that person's current username instead of clearing it, so a blank field on save can never accidentally lock someone out. The one exception is a user who has no username on file yet: saving the profile without entering one there returns an error asking you to set a username first.
If the username you want is already taken, or the change does not take effect after a short wait, contact CoolFocus Support.
If a staff member already has a user account, rename that account instead of creating a second one. A duplicate account can split their linked record, permissions, and activity history across two logins. Create a new user only when the person has no existing account in your organization.
An administrator can update the email address on a user's account.
Open the user's profile from the Users page.
Edit the Email field.
Select Save.
This only changes the email address on that login. It does not touch anything else on the account:
The user's Active status stays the same, so this cannot activate or deactivate someone.
Their user group stays the same.
The Linked Person record stays connected, so scheduler and Home views keep working as before.
Their notification settings stay as they were configured.
Their access history and activity log stay intact, nothing is reset or split into a second record.
Changing the email does not change the Login Username used to sign in. If the person also needs a new sign-in name, update the Login Username field separately, as described above.
Saving changes on a user's profile, like a new name, email, or user group, only changes the fields you actually touched. It does not read or reset that person's Active status.
That means:
• A routine edit to an active user's profile cannot accidentally deactivate them.
• A routine edit to an already-deactivated user's profile cannot accidentally reactivate them or restore their CoolFocus access.
To turn someone's access on or off, use the Active toggle on their profile directly.
Open a user's profile, open the Actions menu, and choose Delete User. This is available whether the user is active or already deactivated, you no longer need to deactivate someone first.
If the user is still active when you delete them, CoolFocus turns off their sign-in (deactivates them) in the same step, then removes their login from the Users page. The confirmation dialog tells you this is about to happen before you confirm.
Deleting a login does not erase the person's record:
• The account is retained for audit history and activity logs.
• The login can no longer be used to sign in.
• If this is the only active administrator in your organization, CoolFocus blocks the deletion so you are never locked out. Turn Administrator on for another active user first, then delete the login.
Open a user's profile and find the Linked Person field. Search by name and select the correct person, volunteer, or staff record to connect the login to it.
• If a person is linked, you will see a View [name] link that jumps straight to that person's record.
• If no one is linked, the field shows No person linked. Without a link, scheduler, Home, and staff features cannot resolve the correct person for that user, so views like My Schedule or Home → Today's Appointments can look empty even when appointments exist.
• Clearing the field removes the link between the login and the People record.
Linked Person search only returns people who already carry the Staff or Volunteer involvement flag. A donor-only record will not appear in the results, even if that is the person you want to link.
If the new user was previously only a donor, keep their existing record instead of creating a new one:
Open their existing person record.
Turn on the Staff or Volunteer involvement flag, whichever fits their new role, and save. See Staff & Volunteers for how these flags work.
Go back to the user's profile and search Linked Person again. The record now appears because it carries the Staff or Volunteer flag.
Two permission settings can keep a record out of the Linked Person search even after the Staff or Volunteer flag is on:
• User group View permissions — under Settings → Security → User Groups, confirm your own user group has View permission for Donors and for Staff/Volunteers. See User Groups: What Staff Can Open and Change.
• Data Access Rules — if your organization uses Data Access Rules to limit which records a group can see, confirm no rule is excluding the record you're trying to link.
Some organizations see Linked Person reject a selection with a "staff not found" or "not valid person" error, even though the record carries the correct Volunteer flag, the right user group has View permission, and no Data Access Rule excludes it. So far this only affects volunteer records; linking a staff record works normally.
This is a confirmed bug, not a setup mistake on your end. Our development team has it and is working on a fix; there is no workaround yet.
If you hit this error:
• Double-check the involvement flag, user group permissions, and Data Access Rules anyway, since those still cause the plain "record doesn't show up" problem described above.
• If the record passes all of those checks and the error still appears, contact CoolFocus Support with the person's name so we can track your case against the fix.
For more on why this link matters and how it connects to positions and schedule views, see Scheduler Views.
From a user's profile, open the Quick Actions menu and choose View activity log to jump to User Logs, pre-filtered to that person. It shows their sign-in activity, clinical record access, and field-level record changes.
Open a user's profile and select the Notifications tab next to Details. Only administrators see this tab.
The tab shows the same system-notification matrix that person sees under their own Your notifications page: events grouped by area, with a switch per channel (In-App, SMS, Email) and a digest option (Immediate, Daily, Weekly) for email. Turning a switch on or off here changes that setting for the user immediately, the same as if they had changed it themselves.
This tab only manages system notifications. Custom notifications (a user's own watch rules) stay under that person's control and are not shown here.
A non-administrator's permissions come from their one user group. If several people need the same access, update the group instead of changing each user separately.
How do I add a second user group to someone? — You cannot. Each person has only one user group. Create or adjust a group that matches the full access they need, then assign that single group on their profile. See One user group per person above.
Cannot sign in — Confirm they accepted their invitation and that their user account is active.
Signed in but a module icon is missing — Confirm Administrator status or user group module access, then see Troubleshooting: A module icon is missing from the sidebar in the administration docs.
Schedule or Home looks empty — Confirm the user's Linked Person field points to their People record.
I can't find someone in the Linked Person search, and they were a donor or already had Staff/Volunteer status — The search only lists people with the Staff or Volunteer flag. Open their existing record, turn on Staff or Volunteer, and search again. If they still don't appear, check your View permission for Donors and Staff/Volunteers under User Groups, and any Data Access Rules that might limit which records you can see.
Linked Person says "staff not found" or "not valid person" when I try to link a volunteer — This is a known bug affecting volunteer records specifically. Staff records are not affected. There is no workaround yet; contact CoolFocus Support so your case is tracked against the fix.
Username already in use, or a rename did not take effect — Contact CoolFocus Support.
Don't see a Notifications tab on a user's profile — Only administrators can view or change another user's notification settings. Confirm your own account has Administrator turned on.
Why can't I save after turning Administrator off for someone? — If that person already has a user group assigned, pick a user group before saving. This keeps them from losing all access the moment they stop being an administrator.
Does changing a user's email change their username? — No. Email and Login Username are separate fields. Update each one on its own.
"Delete User" won't go through — You are trying to delete the only active administrator on the account. Make another active user an administrator first, then delete the login.