Signing in
UMS uses two-step login so only you can access your account.
1Enter your registered mobile number and password.
2Enter the 5-digit OTP to finish signing in.
3Tick Keep me signed in to skip the OTP on a trusted device until it expires.
Your password is encrypted in the browser before it is sent — it never travels as plain text.
Managing users
Everything on the Users screen, in the order you will usually need it.
Adding an account
1Go to Users → Add User.
2Enter the name, the 10-digit mobile number (this also becomes the username) and the email address. Both the mobile and the email must be unique.
3Set a starting password. It needs at least 8 characters with an uppercase letter, a lowercase letter, a number and a symbol.
4Leave Active ticked so the person can sign in straight away.
Approving someone who registered themselves
›Accounts created through Register arrive switched off, and the person cannot sign in until you approve them. The home page shows how many are waiting.
›Open the user, check the details against your own records, then tick Active and save.
Unlocking an account
›Too many wrong passwords locks an account temporarily. It clears by itself, but you can release it immediately: open the user, untick Locked and save. That also resets the failed-attempt count.
Removing access
›Prefer unticking Active over deleting. The person can no longer sign in, and their history stays intact and readable in the activity log.
Exporting the list
›Export downloads every user matching your current search as a spreadsheet — name, mobile, email, role, zone, status and dates.
Roles & permissions
Roles decide what a person can open. Permissions decide what a role can reach.
›Roles lists every role on the system. A role on its own grants nothing until it is mapped to one or more permissions.
›Permissions lists the menu entries and actions. This is also what builds the sidebar: switch a permission off and it disappears from everyone's menu.
›A user's roles come from two places — those given to them directly, and those attached to the post they hold. Both apply together.
›To take one role away from a single person without changing anyone else, add it to them as a Remove entry. That wins over everything, including roles inherited from their post.
Role changes reach someone already signed in within about a minute. Nobody needs to log out and back in.
Posts & assignments
Posts mirror your organisation chart. Putting a user on a post is usually the tidiest way to grant access.
›Post Master is where posts are created and edited; Post Hierarchy shows them as a tree and lets you move a post, and its children, under a different parent.
›Post & Role Mapping attaches roles to a post. Everyone assigned to that post then picks those roles up automatically — and loses them when they move off it.
›One person may hold several posts. One is their main charge; the rest are additional charge.
›Where someone holds more than one post, they can switch between them using the selector in the top bar. The switch changes which post they are acting under.
›A post outside the person's own group or department has to be mapped for them first. If it does not appear in their list, that mapping is what is missing.
Your own account
›Profile is where you update your name, email and mobile number, and upload a photo.
›Change password asks for your current one first. The same strength rules apply as for a new account.
›The theme picker in the top bar follows your account, so it looks the same on every device you sign in from.
›The home page reports your previous sign-in time and the address it came from. If either looks wrong, change your password and tell an administrator.
Common issues & solutions
Quick fixes for the problems people run into most.
Registration — choosing posts & charges
›You can select more than one post from the same group / department to hold additional charge — add each post to your assignment list.
›To add a post from a different group / department (outside your own), it must be mapped for you — please contact the HQ / System Administrator to enable it.
›For direct / unmapped posts, choose “No Division / Direct Posts” in the Division list, then pick your post.
OTP not received
›Wait a few seconds — it arrives by SMS on your registered mobile. Use Resend OTP if needed (up to 3 times), and check network coverage.
›Not landing on the OTP screen at all? You’re probably still signed in via “Keep me signed in” — log out (or use a private window) to sign in fresh.
› Demo / review builds only: a fixed OTP 11111 is used for everyone (and 12345 for the review account) and no SMS is sent. On the live system a real OTP is always sent to your phone.
Forgot / reset password
›On the login page tap Forgot password, verify with the OTP sent to your mobile, then set a new password.
Account locked
›After 5 wrong password attempts the account locks for 15 minutes and unlocks automatically — or ask an administrator to unlock it immediately.
Other tips
›Profile photo not showing? Re-upload it from Profile — the picture is saved against your account.
›Dashboard blank? Some networks block it from embedding — use “Open in new tab” to view it directly.
›Signed out unexpectedly? Sessions end after 1 hour of inactivity for security — just sign in again.
›Still stuck? Note the on-screen message and the time, and contact your UMS / HQ administrator.
Security & your data
›Two-factor login and role-based access — you only see the tools for your role.
›Full activity log — every important action is recorded with user, time and IP for audit.
›Independently security-audited (CERT-In empanelled auditor).
Need more help? Contact your UMS administrator.