Skip to main content
Version: Aeon 7.0

Deactivating and Re-activating Staff Accounts

When a staff member stops needing access — a student worker finishes the semester, someone goes on leave, an account needs to be parked while you sort out a problem — you usually don't want to delete them. Deleting throws away the account, its role, and its site assignments, and the only way back is to recreate everything from scratch.

Deactivating is the gentler option. It blocks the person from logging in but leaves the account fully intact: name, role, site assignments, desktop-client settings, and all the tracking history tied to their work stay exactly as they were. When they come back, you flip one checkbox and they're in again.

Aeon 7 has two ways to deactivate an account, both in the Account Status card of a staff member's detail pane on the Staff tab inside the Customization Manager. Account is Locked is the quick pause — it blocks sign-in and leaves the account in the staff list. Account is Inactive is for someone who has left: it blocks sign-in the same way and also hides the account from the default staff list, so departed colleagues stop cluttering it. Either one preserves the role, the site assignments, and the history, and either one can be reversed. This page covers both — locking first, then marking an account inactive.

When you'll use this
  • A staff member leaves temporarily (sabbatical, summer break, parental leave) — deactivate now, reactivate later, no rework.
  • You need to suspend someone's access immediately while you investigate something, without losing their setup.
  • An account locked itself after too many failed login attempts and you need to clear it.
  • Someone is leaving for good — that's a delete, not a deactivate. See Managing Staff Accounts.
Where this lives and who can use it

The Staff tab is part of the Customization Manager's roles-and-permissions area. Working with staff accounts — including deactivating them — requires the Staff configuration capability on your role. If your role doesn't grant it, the Staff tab isn't available to you.

Deactivating an account

  1. Open the Customization Manager and go to the Staff tab.

  2. In the staff list on the left, click the person you want to deactivate — for example, jdoe. Their account opens in the detail pane.

  3. In the Account Status card near the top of the pane (just below User Details), check the Account is Locked checkbox.

  4. Click Save at the top right of the pane (or press Ctrl/Cmd + S).

    The Account Status card in a staff member's detail pane, showing the Account is Locked checkbox selected and the Account is Inactive checkbox below it with its description

That's it. The account is now deactivated.

You can tell at a glance from the staff list: a deactivated account shows a small padlock icon next to its username on its card. The person's role badge and everything else stay visible — only the lock icon is added.

Staff list card showing the padlock icon on a locked account

Account is Locked is account-wide

The Account Status card describes itself as "Account-wide settings that apply to both the web interface and the desktop client" — so locking the account blocks the person from signing in to Aeon 7, not just the old desktop client.

What a deactivated person experiences

A deactivated staff member who tries to sign in is turned away at the login screen. Aeon refuses the login and shows:

Account is locked.

Aeon staff login screen showing the Account is locked message

They can't get a new session, reset their password, or change their password while the account is locked — each of those paths is refused for the same reason. There's nothing they can do on their own; an administrator has to reactivate them.

Deactivating cuts an open session immediately

Locking an account ends its active sessions right away — the person doesn't finish what they're on and doesn't wait for a token to expire. If you need to cut someone off right now, this is the control that does it. Account is Inactive and deleting an account behave the same way.

Reactivating an account

Bringing someone back is the reverse, and just as quick:

  1. On the Staff tab, select the deactivated staff member (their card shows the padlock icon).
  2. In the Account Status card, clear the Account is Locked checkbox.
  3. Click Save.

The padlock icon disappears from their card, and the person can sign in again immediately. Their role, site assignments, and history are exactly as they left them — there's nothing to rebuild.

Reactivating also resets the failed-login counter

When you uncheck Account is Locked and save, Aeon clears the account's record of failed login attempts back to zero. So whether the account was locked by you deliberately or locked itself after repeated bad passwords, unchecking the box and saving handles both — the person gets a clean slate.

When an account locks itself

You won't always be the one who locked an account. Aeon automatically locks a staff account after too many consecutive failed login attempts, as a brute-force protection. The number of allowed attempts is controlled by the StaffLoginAttemptsBeforeLock customization key.

An account that locked itself looks identical to one you deactivated by hand — same padlock icon, same "Account is locked" message at login — and you clear it the same way:

  • Uncheck Account is Locked and save, which unlocks the account and resets the failed-attempt counter, or
  • Reset the person's password. A password reset also unlocks the account and clears the counter as a side effect, so if someone is both locked out and has forgotten their password, the reset solves both at once. See Resetting a Staff Member's Password.
Locked out, but the password is fine?

If a staff member simply fat-fingered their password a few times and tripped the lock, you don't need to reset anything — just clear the Account is Locked checkbox and save. Their existing password still works.

Marking an account inactive

Use Inactive when someone has left. It blocks sign-in the same way a lock does, but it also takes the account out of the staff list you look at every day — so a departed colleague stops appearing in it without anyone having to delete their record.

There are three ways in, and which one you pick depends on how many people you're doing at once.

From the account editor — the same place as the lock:

  1. On the Staff tab, select the staff member.
  2. In the Account Status card, check Account is Inactive.
  3. Click Save.

There's no confirmation step on this path — the change applies when you save, like any other edit. You can't set it on your own account; the checkbox is disabled there.

From the staff list — quicker for one person:

  1. On the person's card, open the menu.

  2. Choose Inactivate.

    The staff card's ⋮ menu open, showing Copy, Inactivate, and Delete

  3. Aeon asks you to confirm.

    The Inactivate staff member? dialog listing what happens while the account is inactive, with Cancel and Inactivate buttons

The dialog spells out what you're about to do — the person will "Be blocked from signing in," "Have any active sessions ended immediately," and "Be hidden from the default staff list, but kept for tracking history" — and confirms it's reversible. Choose Inactivate to go ahead.

The menu doesn't offer Inactivate on your own card.

Several people at once:

  1. Click Select above the staff list. Checkboxes appear on every card.

  2. Check the people you want.

  3. Click Inactivate (N) in the bar that appears.

    Select mode on the Staff tab with two staff checked and the Inactivate (2) button active beside a grayed-out Reactivate (0)

  4. Confirm in the same dialog, which names the count instead of one person.

Click Done to leave Select mode.

What changes once an account is inactive

The account picks up an amber Inactive badge wherever it still appears:

A staff card carrying the amber Inactive badge

And it drops out of the staff list, because the Status filter above the list defaults to Active:

The Status filter open on the Staff tab, showing Active, Inactive, and All

Switch it to Inactive to see just the departed accounts, or All to see everyone. This is the difference from a lock: a locked account stays in the default list with a padlock, while an inactive one is filtered out until you ask for it.

Someone whose account is inactive is turned away at sign-in with a different message from the locked one:

Account is inactive. Contact an administrator.

The Aeon staff sign-in screen showing the message Account is inactive. Contact an administrator.

An account can be both

Account is Locked and Account is Inactive are independent. Setting either blocks sign-in, and an account can carry both at once — the padlock and the badge both show.

Reactivating an inactive account

Clear Account is Inactive and save, or choose Reactivate from the card's menu — or select several and use Reactivate (N). There's no confirmation on the way back. The role and site assignments were never touched, so the person signs in again to exactly what they had.

Deactivate or delete?

Account is LockedAccount is InactiveDelete
Blocks every sign-in methodYesYesYes
Ends open sessions immediatelyYesYesYes
Keeps the account, role, and site assignmentsYesYesNo
Keeps the person's tracking history and notesYesYesYes
Stays in the default staff listYes, with a padlockNo — the Status filter hides itNo
Can be set for several people at onceNoYes, in Select modeNo
ReversibleYes — uncheck and saveYes — reactivateNo — must recreate the account
Use it whenA pause, or clearing a self-lockoutSomeone has left, and you want the record keptYou need the account gone entirely

When in doubt, deactivate. It's reversible; deleting is not. For the delete workflow, see Managing Staff Accounts.

Unsaved changes are protected

Locking or unlocking an account is a normal edit, so the Save button applies to it. If you check or uncheck Account is Locked and then try to switch to another staff member without saving, Aeon stops you with "Discard unsaved changes?" — choose Stay here to go back and save, or Discard changes to abandon the change.