# Create a user and verify access

Create a user from Manage Users only with the appropriate administrator access. First check whether the person already has an account. Choose New User, enter the full name and unique login, and keep the account inactive while configuring it. This saved example is Morgan Training. Active is No. Hide in Dropdowns is a separate setting: hiding an active user from selectors does not disable their login. Save and reopen the user before adding the required scope and permissions.

Set the Agency and Company memberships deliberately. In CMA, an empty Agency list permits all Agencies, and an empty Company list permits all Companies. Empty does not mean no access. Add the intended memberships using their Add controls, then reopen the user and verify each saved row. Morgan's example is limited to Agency two and Company four. Confirm that those are the intended organizational boundaries before moving on to permission groups.

Choose permission groups for the person's actual role. This example uses LMARep. Exclusive role groups are alternatives, so do not stack LMARep and LMAQARep to create a broader role. Add extra permissions only when the job requires them. Next, complete the approved password and multi-factor authentication setup. If passkeys are available in your deployment, follow its enrollment procedure. Morgan remains inactive here, with authentication enrollment unfinished; the demonstration does not establish a successful login.

Before activation, compare the saved Agency, Company, and role with the approved access request. Then verify representative tasks using the new user's access: the intended work should be available, while unrelated client records and administrator functions should remain restricted. Review missing access through the relevant permission, rather than granting administrator rights to make an error disappear. Activate only after the checks and required enrollment are complete. When access should end, disable the account through the offboarding procedure; do not rely on Hide in Dropdowns.