A new recruiter starts today and has to get to work straight away. Someone else leaves the company and must lose access immediately. A colleague calls to say they have lost their password, on exactly the day a campaign has to go live. None of that should turn into a ticket you wait a day for.
In Booston you arrange it yourself, in one place: Users & Permissions. A user is a login account for the dashboard, with its own email address, its own password and one role. That role determines what someone sees and is allowed to do. If you work with a connected ATS, colleagues come in from there without a separate login (SSO) — and you manage those accounts in the same overview.
The end goal: granting or removing access yourself within a few minutes, without losing jobs, candidates or content, and without waiting for the helpdesk.
By the end of this article you will be able to create a user and pick the right role, set someone to inactive temporarily, solve a password problem, understand what happens when a user is deleted, and see why a colleague who comes in from your ATS is sometimes not allowed in yet.
Before you start
- You need the Manager role. With the Recruiter role you only see your own account and can only change your own profile and password.
- Every user has their own, unique email address. A shared account for several people is not possible.
- Booston manages a few things for you: permanently deleting users, the setting for automatically activating SSO users, and role permissions beyond the standard sets. What exactly that covers and how to request it is in What you cannot arrange yourself.
Reading and filtering the user overview
At the top of the screen you will find Roles & Permissions, where you set per role which modules are visible and active. Below it is Users, the overview with every account and the Create User button. This chapter is about that overview — you use it to see who has access and to find someone quickly.
For every user you see:
| Column | What you see |
|---|---|
| Status | A toggle. On means the user can sign in, off means no access. |
| Name | The name of the user. You can sort and search on this. |
| The email address used to sign in. You can search on this. | |
| Role | Manager or Recruiter, as a coloured label. You can filter on this. |
A few more things worth knowing:
- Active users are always listed first, whichever column you sort on. Anyone without access drops to the bottom.
- Above the table you see the number of users found, with a summary of your filters — for example Users found for: Role: Recruiter. Clear filters resets everything at once.
- Behind every row there is a pencil to edit the user. You only see a bin when deleting is allowed.
- Technical accounts that Booston uses for integrations and automation never appear in the list, so you cannot change them by accident either.
The roles: Manager and Recruiter
You pick one role per user. That choice determines both what someone sees in the dashboard and what they may decide about other users.
| Role | Who it is for | What this role can do |
|---|---|---|
| Manager | Responsible for the environment: recruitment marketer, team lead or application manager | Sees every Manager and Recruiter. Creates users, edits them, sets them to active or inactive and manages the permissions per role. |
| Recruiter | Day-to-day work on jobs and candidates | Only sees their own account. Edits their own profile and password. Cannot create users, cannot activate or deactivate anyone and cannot change their own role. |
Two rules always apply:
- You can never hand out a role higher than your own. As a Manager you therefore choose between Manager and Recruiter.
- A Manager does not edit another Manager's details. A Manager can change a fellow Manager's status. If a Manager's details need to change, let that person do it in their own account.
Creating a new user
You fill in three blocks and the colleague then receives an email to choose a password. So you never have to pass on a password.
- Go to Settings → Users & Permissions.
- Click Create User above the table, on the right. A panel slides open.
- Fill in the User Settings, Personal Information and Access blocks.
- Click Save & close.
User Settings
- User is active — on by default. Switch it off if you want to prepare the account now while the colleague may only sign in later, for example because of a later start date.
- User role (required) — Manager or Recruiter, see The roles: Manager and Recruiter.
- Team members — only appears for the Recruiter role. Here you link team members. The user then sees and edits the jobs and candidates belonging to those team members. If you link none, the recruiter only works with their own jobs and candidates.
- Show recruitment entities without an owner such as open applications — Recruiter only. Switch this on if the colleague also has to see open applications and other items without an owner.
- Show content entities not created by this user such as pages or files & images — Recruiter only. Switch this on if the colleague also has to be able to use pages, files and images created by others.
Personal Information
- Name (required) — first and last name. You see this name in the overview and on everything this user creates.
- Email (required) — used to sign in. Must be unique within your environment.
- Function — the job title, for example Corporate Recruiter.
- Portrait — the portrait photo. Pick an existing file or upload a new image.
Access
- Password (required when creating) — at least 8 characters.
- Retype password — the same password again.
- Email reset password link — switch this on to send the colleague an email straight away with which they set their own password.
How the new colleague sets their own password
Right after you create an active user, the colleague receives an email from noreply@booston.io with a link to choose a password. What they do:
- Open the link from the email.
- Enter a new password twice, at least 8 characters.
- Go to the sign-in page and sign in with the email address and the new password.
Editing a user
You use the same panel as when creating, now titled Edit user.
- Click the pencil behind the user in the overview.
- Change what needs changing.
- Click Save & close.
What to watch out for:
- Leave the password fields empty if the password does not have to change. If you do enter something, the user is signed out everywhere immediately and has to sign in again.
- If you change the role from Recruiter to Manager, the linked team members are dropped. A Manager sees everything by default.
- With the Recruiter role you edit your own name, email address, function, photo and password. Your own role is fixed.
Temporarily setting a user to inactive
Is someone leaving the company, going on long-term leave, or does access have to stop for a while? Then set the user to inactive instead of having them deleted. All jobs, candidates and content stay linked to that person, and you can undo it with one click.
- Switch off the toggle in the Status column in the overview.
- Confirm in the Deactivate User window with Deactivate.
What happens immediately:
- The user can no longer sign in.
- Running sessions end immediately, even if someone is working in the dashboard at that moment.
- Outstanding password links expire.
You give access back by switching the toggle on. The colleague then automatically receives a new email with a password link and can continue right away.
Deleting a user and reassigning the content
Deleting is permanent and cannot be undone. That is why it is reserved for Booston in the dashboard: you do not see the bin in your own account. Email support@booston.io with the name and email address of the user and the colleague the content should go to.
So that you know what happens, this is the sequence:
- At Reassign content to a colleague is picked, or Unassigned if there does not have to be an owner.
- The second window, Confirm Deletion, states who the content goes to. After confirming, the user is gone.
Everything attached to the user moves along: jobs and job content, pages and page elements, menu items, candidate feedback, campaigns, locations, team members, reports, iframes and the activity log. So you do not lose any work — it ends up under a different name. What is not possible: deleting Booston accounts and technical accounts, or assigning the content to the very user you are deleting.
Forgotten password or unable to sign in
There are two routes: the colleague arranges it themselves, or you send a new link as a Manager. Both produce the same email.
The colleague does it themselves like this:
- Go to the sign-in page of the dashboard.
- Click Forgot password? below the sign-in form.
- Enter the email address and submit.
- Open the email from noreply@booston.io and click the link.
- Enter a new password twice and save.
As a Manager you send a new link like this:
- Open the user via the pencil.
- In the Access block, switch on Email reset password link.
- Click Save & close.
SSO: working from your ATS without a separate login
If you use Booston together with a connected ATS, your colleagues do not have to sign in twice. With Carerix, Booston opens as a tab inside Carerix itself; with ForceFlow you click through from ForceFlow to Booston and are signed in straight away. We arrange the technical setup of such a connection together with your ATS supplier — that is outside the scope of this article. What matters here is what happens to users.
When someone comes in through the ATS for the first time, Booston first looks for an existing user for this person: on the SSO identity, and otherwise on email address. If there is no user yet, Booston automatically creates one with the Manager role. Whether that new user can get to work right away depends on one setting.
Auto-activate iFrame / SSO users on or off
On Settings → Users & Permissions you will find the iFrame / SSO user activation card with the Auto-activate iFrame / SSO users toggle. This is the switch that decides whether SSO works by itself.
| Position | What happens with a new SSO user | When you want this |
|---|---|---|
| On | The user is created active straight away and can get to work immediately. There is no intermediate step. | Everyone allowed to work in your ATS is also allowed to work in Booston. |
| Off (default) | The user is created inactive and sees the message User has been paused. Please contact a Booston manager. Someone with the Manager role has to set the user to active first. | You want to decide yourself who gets access, even if that person is known in the ATS. |
What this means for you:
- Is the setting off and does a colleague report that SSO "does not work"? Usually nothing is broken. Find the colleague in the overview and switch on the toggle at Status. After that they come straight in through the ATS. Activating also sends out a password link, so they can sign in to Booston directly later if they want to.
- With the setting on, your user list grows along with your ATS automatically. Go through the overview now and then and set accounts you do not need to inactive.
Users created through SSO
SSO users sit in the overview among the other accounts. You can change their role, link team members, complete their profile and set them to inactive — just like a user you created yourself.
Two things you may come across:
- An email address that looks like carerix+…@booston.io. If the ATS could not supply an email address, Booston fills in an internal address temporarily. You replace it with the real address in the edit panel.
- An error message instead of access. For security reasons Booston never links an SSO login to an existing account whose email address the ATS has not confirmed, and never to an account already linked to a different SSO identity. In that case, email support@booston.io and we will work out which account should be linked.
What you cannot arrange yourself
A few things deliberately go through us: they cannot be undone, or they affect the security of your whole environment.
- Permanently deleting a user — cannot be undone and it changes the owner of jobs, candidates and content. Email support@booston.io with the name, the email address and the colleague the content should go to.
- Switching Auto-activate iFrame / SSO users on or off — this decides who comes in through your ATS. Email support@booston.io with the position you want.
- Granting the highest administrator role — that is reserved for Booston staff for support and management. You do not need it for your own environment: the Manager role gives you everything.
- Refining the permissions per role beyond the standard sets — those are matched to your subscription. Email support@booston.io with what you want to achieve.
- Using an email address that is already taken — every address can belong to one user. Search for the address in the overview first; if you find nothing, it belongs to a hidden account and we will help you further.
Solving problems
No password email arrives
The account is inactive; Booston does not send a password link for a blocked user. Set the user to active first — that sends the email automatically. If it still does not arrive, check the spam folder and whether the email address in the overview is correct, and have your IT department allow noreply@booston.io.
The message "User has been paused. Please contact a Booston manager."
The user is inactive. That is also what a new SSO user sees as long as Auto-activate iFrame / SSO users is off. Switch on the toggle at Status in the overview.
The message that too many attempts have been made
A protection against abuse has temporarily blocked signing in or requesting a password link. Wait a minute and try again.
The message "A user with this email already exists"
The email address already belongs to a user, possibly an inactive one. Search the overview for the address and set that user to active again instead of creating a new one.
The right colleague is not in the list when reassigning content
That list uses the users from the overview as it stands at that moment. Search or filter for the right colleague first and then open the window again.
Frequently asked questions
A new colleague sees fewer modules than expected. How can that be?
What someone sees depends on the role, not on the person. Check at Roles & Permissions what is set for that role, or give the colleague the Manager role.
A recruiter sees no jobs or candidates. What do I have to set?
Open the user and look at Team members. A recruiter sees their own items plus those of the linked team members. If they also have to see items without an owner, switch on Show recruitment entities without an owner such as open applications.
A colleague is leaving: set to inactive or have them deleted?
Set to inactive. Access stops immediately, you keep the history intact and you can do it yourself. Deleting is only necessary if the account really has to disappear.
I do not see the Create User button. Why not?
That button belongs to the Manager role. If you have the Recruiter role, ask a fellow Manager to create the user.
Does someone stay signed in after I set them to inactive?
No. On deactivation all active sessions end immediately. If someone still sees a page, that is an old tab; on their next action they are signed out.
Coming soon
- Guided setup for new environments. During onboarding Booston prepares the first settings and the first users together with you and then hands the environment over to you; the new users automatically receive their sign-in details. As soon as this is live, we will update this article.
- A more uniform screen for creating and editing. The panel for a user will look and work the same as the other screens in Booston. As soon as this is live, we will update this article.
Need help?
Are you stuck, or do you not know which role suits a colleague? Email support@booston.io or call 085 0044 215 and mention:
- the name of your environment;
- what you want to achieve;
- the message you see, if there is an error message.
Would you rather go through the settings together? Book a free 30-minute online demo — then we will go through it together. Job Done!