Overview: Service accounts are used for system-to-system access rather than individual human logins. This article walks through how to create a service account user in the Admin Centre.
Before You Begin
Make sure the following are in place before starting:
Owner permissions: Only users with Owner-level access can create a service account user.
Inbox access: The email address you use will receive an account setup invite (see below), so confirm you can access that inbox before creating the account.
Warning: A service account gives complete read and/or write access to your Active tenant via the available API endpoints. This is a high level of access — treat service account credentials with the same care as any other privileged system credential, and only create one when it's genuinely needed.
User Setup Steps
1. Navigate to User Management
Go to Admin Centre > Users & License Management.
2. Start a New User
Click the New User button to open the user creation form.
3. Fill Out Identity Details
Under the Identity section, complete the required fields:
First Name
Last Name
Email
(Optional) Position and Code
Leave Register a User Account checked, as shown in the form.
4. Configure Role & Permissions
This is the key step for setting up a service account correctly. Under Role & Permissions:
Security Role: Set to Admin
Service Account Role: Set to Read Access
These two settings together designate the account as a service account with the appropriate access level, rather than a standard interactive user account.
5. Save the User
Complete any remaining fields and save the new user record.
Email & Account Setup Requirements
Once the service account user is created, an invite email will be sent to the email address entered on the form. Whoever has access to that inbox will need to:
Set up the account password
Configure Two-Factor Authentication (2FA)
Access to the inbox for the email address used is required to complete this setup step, so make sure this is arranged before creating the account.
The email address does not need to be a personal or named mailbox — a distribution list can be used instead. This is often preferable for service accounts, as it allows multiple team members to receive the invite and manage account setup and future access (e.g. password resets, 2FA re-configuration) without depending on a single individual's inbox.
