Start Using the Latest Features & Updates

🆕 User Management: decide exactly who sees what

Alvys avatar
Shared by Alvys • August 10, 2026

User Management has its own page now. Find it at Settings → Organization → Users. It is faster, searchable, and sortable, with filters by subsidiary.

The bigger change sits underneath. You can draw much sharper lines around who sees what.

  • See your whole team at once. Every user, role, and status on one page. Change a reporting role without leaving the list.
  • Set access by category, down to the individual action. Permissions group by area of the platform — rates, billing, dispatch, reporting, privacy. Grant a role its defaults, then tighten individual actions from there.
  • Keep sensitive data behind its own permission. Tax ID and SSN, PII, and ACH account and routing numbers each sit behind their own permission, in a dedicated privacy group. For ACH, we go further than hiding the field: without the permission, our server never sends the account and routing numbers at all. The page shows only that details are on file.
  • Separate viewing from editing. Let someone see a customer, carrier, or driver rate without letting them change it. Each is a separate permission.
  • Manage multi-company users per company. Add or remove company access, and set different permissions in each one.
  • The same rules follow your data into reporting. Permissions are enforced in our analytics layer too, so a user without them does not see masked fields surface in a report or an AI-assisted answer.
  • Reset a locked-out user's MFA. An admin can do this without a support ticket. Limits below.
  • Handle offboarding in seconds. Send a password reset. Remove access. Delete the user.
  • My Profile got the same treatment. Every user manages their own details, integrations, notification settings, locale, and password in one place.

Why we rebuilt it this way

The way freight companies get breached has changed. Permissions are now the control that decides how bad it gets.

Trucking's own standards body spent the last year tracking the shift. NMFTA's 2026 Transportation Industry Cybersecurity Trends Report names AI-assisted social engineering as a defining trend, and warns it is becoming difficult to detect by traditional means. The report also ties digital compromise to physical cargo theft: identity fraud and account hijacking have become standard tools for cargo crime networks. NMFTA's cybersecurity director Ben Wilkens covers the same ground in The Trucker.

Why MFA reset has limits

Locked-out users are a real problem. Left unsolved, they push your team toward exactly the workaround attackers exploit: an urgent call, a rushed identity check, a reset granted under pressure. So we built the reset into the product, and we scoped it three ways.

  1. The admin proves it is them. Resetting someone else's MFA requires the acting admin to confirm with their own authenticator code. An attacker who talks their way into an admin's session still cannot clear anyone's MFA without that admin's own second factor.
  2. Rank is enforced. An admin can only reset a user below them. An Admin cannot reset another Admin. A Partner Admin cannot reset an Admin or another Partner Admin. Users on a custom role are not eligible. Those cases route to our support team.
  3. The user re-enrolls themselves. The reset clears their enrolled authenticators; they set up a new one at next login. Nobody, including us, hands out a working second factor.

The second restriction matters most. No single account inside your company can take over every other privileged account.