← Business

User Management for banks

Finances are often managed by different people at a business, all with various levels of responsibility. When an organization leader needs to give account access to their employees, there are a wealth of entitlements and settings available to manage their permissions. With Banno Business’s User management, organization admins can add new organization users, edit details, and assign roles in Banno Online. They can also manage the overall permissions of organization users, allow access to specific accounts, and control an organization user’s permissions on an account-by-account basis.

  • User profile menu
  • Settings
  • User management

In User management, organization admins also manage entitlements and feature entitlements for members directly in the app, including:

  • ACH
  • ARP/Positive Pay
  • Card management
  • Stop payments
  • Transfers
  • Wires

Enable and disable entitlement

In Banno People, your institution manages the User management entitlement for both the organization and members of an organization. You should ensure the entitlement is enabled for the organization, as well as for organization users who need access to Banno People.

Organization

Banno People

  • Users
  • organization profile
  • Permissions

Your institution enables and disables User management in the organization’s profile. For members of an organization that need access to the entitlement, you’ll need to enable it for the individual.

If the User management entitlement is disabled, User management is prevented from displaying in the app and its functionality is unaccessible. Organization admins and viewers can’t view or manage organization user profiles and permissions, but organization users can still perform their day-to-day duties using features such as ACH, Wires, Transfers etc.

Member of an organization

Banno Online

  • Settings
  • User management
  • User profile
  • Set permissions
  • User management

An organization admin can enable and disable User management in the member of an organization’s profile. This permission should always remain disabled for organizations users in a User role. If User management is enabled by mistake for an organization users with a User role, our security measures will still prevent them from accessing user management functionality. They can see and click User management in their Settings, but the screen remains blank.

Organization users with an Admin or Viewer role need User management enabled. User management and its functionality won’t display in the app until the entitlement is enabled.

Banno People

  • Users
  • organization user profile
  • Permissions
  • Organization user permissions

Your institution can enable and disables User management in the member of an organization’s profile. This permission should always remain disabled for organizations users in a User role. If User management is enabled by mistake for an organization users with a User role, our security measures will still prevent them from accessing user management functionality. They can see and click User management in their Settings, but the screen remains blank.

Organization users with an Admin or Viewer role need User management enabled. User management and its functionality won’t display in the app until the entitlement is enabled.

Organizations

Create

Creating a new organization in Banno People is not currently available.

Organization users

Profile

Banno Online

A list of all members of an organization—including their name, role, and status—display on the User management dashboard. When a specific organization user is selected, their profile information displays on a new screen and includes the following details:

Avatar
A profile image uploaded by the organization user.
Name
The organization user’s name is a maximum of 40 characters and editable by an organization admin.
Username
The username is the name that a member of an organization uses to login to the app.
Role
Roles only apply to what an organization user can do within User management. The member of an organization has an assigned role of Admin, Viewer, or User. An organization user’s role can be changed by an organization admin.
Admin
The Admin role gives an organization user access to view or modify entitlements, set permissions for all organization users, and manage organization users (create, delete, etc.). They can also edit an organization user’s profile details. Organization admins cannot change their own roles; however, they can update a fellow admin’s role. User management must be enabled for each organization admin.
Viewer  
The Viewer role gives an organization user access to view information in User management. They have the same access as an an organization admin, but they can’t edit entitlements or set permissions. This role is ideal for auditors your institution works with. User management must be enabled for each organization viewer.
User
The User role is for organization members whose jobs involve performing day-to-day banking activities that don’t require user management rights. They can move money based on their entitlements and permissions, but they don’t have access to use or view the User management screen .
Status
An organization user’s status can be Active, Pending, Disabled, or Locked. Excluding the Pending status, authorized institution personnel can manage an organization user’s status in NetTeller BackOffice.
Active
The organization user successfully joins the organization by completing the app login process.
Pending
The organization user has yet to successfully complete the app login process and join the organization. An organization admin submitted the organization user’s details—first and last name, email, and role—when they created the new organization user. The organization user may or may not have accounts enabled. They may or not have already been invited to complete the app login process, but they must create their login credentials and log in to the app in order to change from a Pending status to an Active one—logging in to the app is required to change their status.
Disabled
The organization user can’t log in to the app, and their account can’t be re-enabled.
Locked
The organization user incorrectly entered their login credentials three or more times, and the account needs to be unlocked before the organization user can successfully login.
Email
The organization user’s email is a maximum of 80 characters and editable by an organization admin.
Organization details
The organization’s business name, address, phone number, and email. This information matches the details listed in the organization’s profile.

Profile settings

Banno Online

  • User management
  • click organization user
  • settings
  • Edit user

In the organization user’s settings, an organization admin can update or manage the following:

  • Edit the organization user’s details including name, user role, and email.
  • Hold the organization user’s account access.
  • Send a link for the organization user to reset their password.
  • Delete the organization user.

Banno People

  • Users
  • click organization user
  • settings

In the organization user’s settings, an admin user can access the following:

  • Edit the organization user’s preferred name. Currently, we strongly recommend against adding or using a preferred name.
  • View support cases related to the organization user.

Role comparison

An organization user’s role can be updated in their profile settings. The following table helps familiarize organization users with the available roles in user management:

Admin Viewer User
Move funds (create wire, upload ACH, etc.)          Y           Y         Y          
View users               Y           Y                      
Create users             Y            
Delete users             Y                                
Unlock users             Y                                
Reset password           Y                                
Hold account             Y                                
View user profiles   Y           Y                      
Edit user profiles     Y                                  
View user permissions    Y           Y              
Edit user permissions    Y                           
View user account permissions Y   Y        
Edit user account permissions  Y            

Permissions can be enabled so that an organization user only views select money movement and user management functionality in the Banno app.

Create

Depending on an organization user’s role, a newly created member of the organization might need access to User management. If so, an institution employee needs to enable the User management entitlement for the member of the organization.

Banno Online

  • User management
  • Manage users
  • + Create user

An organization admin creates a new organization user by selecting + Create user in the Manage users window. Then, the organization admin provides the following details in the Create user screen:

First name
The new organization user’s first name.
Last name
The new organization user’s last name.
Email
The new organization user’s email. A Banno-generated email with a magic link sends to this email address so that the new organization user can create their account credentials and log in to the Banno app.
User role
The user role determines what an organization user can do within User management.
Default permissions set on the host are automatically assigned to new organization users. To modify permissions, an organization admin can update them at any time in the organization user profile with User management.

After providing the new organization user’s details, the organization admin selects Create user and completes a high risk authorization by entering their Banno app password. If there are three incorrect attempts, the organization user is logged out of the app and their account locks. Their account will need to be unlocked.

Following a successful high risk authorization, the Enable accounts window displays. At this point, the new organization user is yet to be informed of a created profile, has no credentials, and can’t to log in to the app. In the Enable accounts window, the new organization user’s avatar, name, role, Pending status, and option to Enabled accounts display. By default, no accounts are automatically enabled, and the organization admin needs to manually enable at least one account for the new organization user.

To enable one or more accounts, the organization admin clicks Select and the Account access window displays the organization’s accounts to select from. The organization admin can search accounts by account name and quickly enable or disable permissions to all accounts. After enabling one or more account and selecting Done, the organization admin automatically navigates back to the Enable accounts window where it’s updated to display the number of enabled accounts (ex. 4 accounts, 12 accounts, All accounts, etc.). Although the account access displays as enabled, know that the accounts still won’t display as enabled in the new organization user’s profile.

With the organization admin still on the Enable accounts screen, they click the Enable Accounts button. A success message appears, and the organization admin selects from one of the three following buttons:

Send email invite
If the organization user’s account or user permissions don’t need updating, the organization admin should send an email inviting the new organization user to enroll in the Banno Digital Platform. After clicking the button, the organization admin automatically returns to the Manage users screen where the new organization user displays in a Pending state.
Edit permissions
If the organization user’s account or user permissions need to be updated before they’re invited to enroll in the Banno Digital Platform, the organization admin should click Edit permissions. This automatically navigates the organization admin to the new organization user’s profile where permissions can be updated and then invited. The new organization user displays in a Pending state.
Done
Clicking Done returns the organization admin to the Manage users screen where the new organization user displays in a Pending state. An email invite doesn’t send to the new organization user.

Once the success message appears, the selected accounts display as enabled in the new organization user’s profile.

If after the organization admin selects Create user and the organization’s accounts fail to load, the Enable accounts window doesn’t appear. Instead, the error message Accounts failed to load displays. The organization admin can click View profile to enable accounts from the organization user’s profile, or they can click Done and automatically navigate to to the Manage users screen where the new organization user displays in a Pending state.

Banno People

Creating a new organization in Banno People is not currently available to banks.

NetTeller

An organization admin can create a new organization user in NetTeller. For additional information, please refer to NetTeller documentation.

NetTeller BackOffice

In NetTeller BackOffice, an institution can create a member of an organization. For additional information, please refer to NetTeller documentation.

Default permissions

Default permissions are automatically assigned to new organization users and can be updated on an individual basis with User management in the Banno app. Default permissions themselves can be managed by an institution on the host, and an institution can refer to NetTeller documentation for more information.

Invite

An organization admin needs to invite newly created organization users and organization users with a Pending status to create their credentials so that they can log in to the Banno app. The invitation is an automated email generated by Banno and includes a link that takes the organization user to a screen where they create their Banno username and password.

Banno Online

The organization admin can send the invite in one of two ways:

  • When they successfully create a new organization user, select Send an email invite.
  • The organization admin emails an invite from the organization user’s profile by selecting Invite at the top of the profile.

In the new organization user’s profile, a notification banner displays at the top of the screen: [Organization user’s first and last name] account is pending. Invite them to complete set-up of their account. An organization admin can only invite the new organization user if one or more account is enabled. If no account is enabled, the error message Unable to invite user displays when clicking Invite. To enable one or more accounts for the new organization user, an account’s Access permission needs to be selected. After enabling one one or more account, the organization admin can refresh the page to ensure the screen updates. Then, they can successfully select Invite to send an email notifying the new organization user to enroll in the Banno Digital Platform.

The name of the organization admin who sent the invite and the option to click Join display in the email. After clicking the link, the organization user automatically navigates to the app enrollment window and creates their username and password. After successfully creating their credentials, they view a Successfully created account message and click the Sign in button to navigate to the Banno Online login screen. If the organization user unsuccessfully creates their username and password, they view an error message and should retry creating their credentials.

If an organization admin sends multiple email invites to the same organization user, only the most recent email with the link works for the organization user to use. The organization user has up to seven days to enroll in the Banno Digital Platform before the link expires, and the link can only be clicked on once. When the link is clicked, the token is redeemed and refreshing the page results in an error—a new invite needs to be sent and clicked. If the organization clicks an older, expired, or redeemed link, the message Invitation link failed displays and they need to click on the latest or newest link.

Banno People

An institution admin can view the organization user’s Pending status, but they are unable to send an invite.

NetTeller

An organization admin can invite an organization user from NetTeller. The invitation from NetTeller contains a link to a NetTeller webpage–rather than Banno webpage–where the organization user creates their NetTeller & Banno credentials (the same as they do today). Once they create their credentials and log in, they can use the existing SSO to navigate to Banno. To log in to Banno, they’ll use the same credentials they used to log into NetTeller.

There may be a delay for displaying an organization user in User management, because it can take time as the Banno platform automatically seeds the organization user.

NetTeller BackOffice

In NetTeller BackOffice, an institution can invite a member of an organization. For additional information, please refer to NetTeller documentation.

Unlock

Banno Online

  • User management
  • click organization user
  • Unlock

When an organization user incorrectly enters their login credentials three or more times, their profile status is Locked. An organization admin needs to unlock the account before the organization user can successfully log in. At the top of the organization’s user profile, a notification banner displays at the top of the screen: [Organization user first and last name]’s account access is locked due to multiple incorrect login attempts.

While an organization user is immediately unable to log in to their account when it’s locked, it can take up to approximately five minutes for the account to display as Locked in User management.

An organization admin successfully unlocks an organization user’s account by selecting the Unlock button in the banner. This changes the organization user’s status from Locked to Active, and the organization admin can select I’m done or Send password reset link in the User successfully unlocked message that displays. If I’m done is clicked, the organization user can immediately log in to the app. If Send password reset link is clicked, the organization user follows emailed instructions so that they can reset their password and log in to the app.

Banno People

  • Users
  • click organization user
  • Unlock

When an organization user’s account is locked, a notification banner displays at the top of each page in the organization user’s profile in Users: [Organization user first and last name]’s account access is locked due to multiple incorrect login attempts. An institution admin can successfully unlock the organization user’s account by selecting the Unlock button in the banner. This changes the organization user’s status from Locked to Active, and the institution admin can select I’m done or Send password reset link in the User successfully unlocked message that displays. If Send password reset link is clicked, the organization user follows emailed instructions so that they can reset their password and log in to the app.

Edit

Banno Online

  • User management
  • click organization user
  • settings
  • Edit user

In an organization user’s settings, an organization admin can edit an organization user’s details, including name, role, and email.

Banno People

Currently, we strongly recommend against adding or using a preferred name because it creates inconsistencies between User management and Conversations for Business.
  • Users
  • click organization user
  • settings
  • Edit preferred name

In the organization user’s settings, an admin user can add a preferred name.

Hold

The held status for a member of an organization isn’t visible to the individual, and it disables the organization user from logging into the app. For example, the held state could apply to an organization user on a short-term leave. If a member of an organization needs their app login access temporarily disabled, an organization admin can change it in the app, or an institution employee can change it in NetTeller.

Banno Online

  • click organization user
  • settings
  • Hold account status
  • Hold

An organization admin can hold an organization user’s account, preventing the organization user from logging in to the app. After it is successfully on hold, a notification banner displays across the top of the organization user’s profile: [Organization user first and last name]’s account access is temporarily on hold. The hold status doesn’t change the organization user’s status (active, locked, etc.) in their profile.

If an organization user has a hold on their account, additional messaging displays in the overall Manage users page: Account access on hold.

To remove a hold on an account, an organization admin selects the Remove button that displays in the notification banner at the top of the organization user’s profile. Removing a hold is immediate, and the notification banner no longer displays. A success also toast displays when the hold is successfully removed from the organization user.

If an organization user’s account is both locked and held, the held notification displays above the locked notification. In either order, both of the locked and held states must be resolved before the organization user can log in.

Banno People

  • Users
  • click organization user
  • Overview and Security pages

When an organization user’s account is on hold, institution admins can’t remove the hold status from an organization user’s account. A notification banner displays at the top of the Overview and Security pages in the organization user’s profile in Users: [Organization user first and last name]’s account access is temporarily on hold. Only an admin at their organization can remove the hold on their account.

Reset password

An organization admin or institution admin resets an organization user’s password when they unlock the profile or use the profile’s settings. This prompts the app to send an email with the password reset link and instructions to the organization user.

Banno Online

An organization admin unlocks an organization user’s profile by sending a password reset link in User management.

  • click organization user
  • Unlock
  • Send password reset link
  • Email

After the organization admin unlocks a profile, they can also reset the password by selecting the Send password reset link button instead of the I’m done button in the success message that displays.

  • click organization user
  • settings
  • Send password reset link
  • Email

If the organization user forgets their password or needs it reset, an organization admin assists by selecting Send password reset link in the organization user’s settings. The organization admin then clicks Email that prompts the app to send the password reset link to the organization user’s email. The organization user must click the link provided in the email and follow the instructions to create a new password.

Banno People

An admin user can unlock an organization user’s profile by sending a password reset link from Banno People.

  • Users
  • click organization user
  • Security
  • Password reset
  • Send link

If the organization user forgets their password or needs it reset, an admin user assists by clicking Send link in the Password reset section of the organization user’s Security page. The organization admin then clicks Email, which prompts the app to send the password reset link to the organization user’s email. Once the password reset link sends successfully, a success toast displays. The organization user must click the link provided in the email and follow the instructions to create a new password.

Delete

Banno Online

  • User management
  • click organization user
  • Delete user

Within the member of the organization’s profile, an organization admin can delete the organization user. Deleting an organization user removes the profile from User management and Banno People. The organization user is deleted from the core, as well as NetTeller BackOffice, and is unrecoverable.

Banno People

The functionality to delete an organization user currently exists in Banno Online only.

History events

Changes made in user management (updating a permission, modifying an organization user profile, etc.) by an admin user or organization admin create history events in Banno Admin. History events display in the organization user’s Activity and can be sorted using the Permissions filter under User. History events for high risk authorization that are requested, failed, or passed by the organization user are captured but do not yet display.

Banno Activity also records history events and can be sorted using the Permissions filter under People Users.

If changes occur on core or in NetTeller BackOffice, history events won’t display in Banno Admin.

Banno Business FAQ


What are the differences in each user role? Can we create a partial admin?
Organization admins can do everything, including edit, as well as delete and create once available. Viewers can see all details about a user, like an auditor, and viewers can also access user management. The user role is a standard user within the organization and cannot access user management. This role comparison table can help familiarize organization users with the available roles in user management.

There is not currently a partial admin role.

Why can an organization user with a viewer role move funds?
The viewer role only applies to what the user can do in user management. It doesn’t apply to the permissions that the user can be granted for other parts of the application, but they can be permission’ed so that they only have view-only access.