Users Users administration tasks. Overview Use Admin > Users to create and maintain MiRTA PBX web administrator and operator accounts. These accounts control access to the administration interface; they are separate from SIP extensions and extension web-panel accounts. The page is available to users with the Has menu Admin/Users privilege. The records and selectable values shown to an administrator are further limited by tenant, reserved-profile, routing-profile, call-rate, and user-profile privileges. Admin Users page with fictional documentation accounts. The screenshot was captured from the current MiRTA PBX server. The displayed users and tenant are fictional documentation values inserted only in the browser; no PBX records were changed. User list The grid initially shows the account identity, authentication method, assigned profile, and allowed tenants. Select a row before using actions that operate on an existing account. Column Description Username Unique login name used to access the MiRTA PBX web interface. Description Administrative description of the account or its owner. Authentication Internal uses the password stored by MiRTA PBX. LDAP authenticates the user through the configured LDAP service. Profile Primary user profile that supplies menus and privileges. Tenants Tenants the account is allowed to access. Select Columns to show or hide additional account properties, including Email, Profile ID, LDAP settings, IP-filter state, 2FA type, password-expiration state, password lock, dynamic-IP permission, and token validity. The column choice is retained in the current browser. List actions Action Purpose Add Opens Define User for a new web account. Edit Opens the selected account in Define User. Delete Deletes the selected account after confirmation, subject to tenant and reserved-profile privileges. Search Searches the user list. When advanced filters are enabled, multiple conditions can be combined. User Activity Opens the user activity log. With a row selected, the log is filtered to that user; without a selection, it shows all accessible activity. User Groups Opens user-group administration. This action is shown only with the Can manage the User Groups privilege. Columns Opens the column chooser and stores the selection in the browser. Which users are visible Privilege Effect Can edit all tenants Allows the administrator to view and manage user accounts across all tenants. Can edit own tenants Limits the list to accounts assigned to at least one tenant also available to the current administrator. Can manage reserved profile users Allows accounts using reserved user profiles to be displayed and maintained. Define User: information and authentication Field or option Purpose Username Required unique login name. MiRTA PBX checks that the name is not already in use. Description Free-form administrative description. Email Address used for password emails and email-based two-factor authentication. Password Local password for an internally authenticated account. Leave it empty while editing to keep the existing password. Generate creates a suggested password. Send Email Sends the create/update user email template with the new credentials. A new password and valid email address are required. LDAP Uses LDAP instead of the local password and disables local password entry. Custom LDAP user Optional custom LDAP user connection string for this account. Never expire Exempts the local password from the expiration period configured in Admin Settings. Password expiration date Shows the calculated expiration date and whether a change is due. It is informational and depends on the global password-expiration setting. Force password change at login Requires the user to replace the local password at the next login. Lock password, user cannot change it Prevents the account holder from changing the password. Last successful login Shows the most recent successful login time for an existing account. Login status Shows whether inactivity housekeeping disabled the account. Select Re-enable on save to reactivate it. Allow change of IP in the same session Allows an authenticated browser session to continue when the client IP address changes. Leave disabled unless mobile or changing networks require it. User Profile Primary privilege profile that determines the menus and operations available to the user. Some fields can be shown, hidden, unavailable, prefilled, or locked through Admin > New Items Defaults. Administrators with the corresponding override privileges can reveal or edit those fields. Resource assignments Field Purpose Tenants Defines which tenant records and tenant-level pages the account can access. Allowed Routing Profiles Defines which voice, SMS, and fax routing profiles the user can select when maintaining permitted objects. Allowed Call Rates Defines which client call-rate tables the user can select. Allowed User Profiles Defines which profiles the user may assign when creating or editing other accounts. The available choices depend on the privileges of the administrator performing the edit. A tenant-limited administrator cannot grant access to resources that the administrator cannot use. Restrictions Restrictions narrow access inside the assigned tenants. Select only the permitted objects. Leaving a restriction list empty means that the user is not restricted by that list. Field Purpose Restricted to Queues Limits queue pages, queue status, and queue-related information to the selected queues. Restricted to Extensions Limits extension-related pages and information to the selected extensions. Restricted to Providers Limits provider-related pages and information to the selected providers. Additional security Field or option Purpose Use IP Filter Restricts login to the addresses and IPv4 networks in Allowed IP list. Test the list before enabling it for the only administrator account. Allowed IP list Enter IPv4 addresses or CIDR networks. Whitespace, commas, and semicolons can separate entries; # starts a comment. An address without a prefix is treated as a single host. Use Two Factors Authentication (2FA) Selects no 2FA, a code sent by SMS, a code sent by email, or Google Authenticator. Mobile phone number Destination used when SMS two-factor authentication is selected. Secret code Secret used by Google Authenticator. Get generates a secret and QR code. Autogenerate Defers Google Authenticator secret generation and enrollment until login. Save, delete, and related actions Save stores the account and its tenant, routing-profile, call-rate, user-profile, and restriction assignments. Delete removes the account after confirmation when the current administrator has sufficient scope. Back returns to the Users list. User Quick shortcuts opens shortcut configuration for an existing account. Security recommendation: give each administrator an individual account, assign the least-privileged profile and tenant scope required, enable 2FA, and review User Activity regularly. Before deleting an account, verify that no operational process still depends on that login. User Activity Use Admin > Users > User Activity to audit web-interface, API, authentication, configuration, campaign, provider-number, and maintenance operations recorded by MiRTA PBX. From the Users list, select a user before choosing User Activity to open a prefiltered log, or open it without a selected row to review all activity available to your account. The page requires the Has menu Admin/Users privilege. Administrators with Can edit all tenants can review all tenant activity. Administrators limited to their own tenants see only activity allowed by their tenant and user scope. Admin User Activity page with fictional documentation events. This screenshot was captured from the current MiRTA PBX server. The displayed activity rows are fictional documentation values inserted only in the browser; no PBX records or activity-log rows were changed. Working with the log Control Purpose Search Filters the log. When advanced filters are enabled, multiple rules and groups can be combined. View Opens the selected row and shows fields that are hidden in the default grid. Undo Attempts to restore the saved old values for a selected UPDATE or DELETE row. See Undo limitations before using it. Columns Shows, hides, or reorders columns. The choice is retained in the current browser. CSV Export Exports the activity data and all supported columns for offline review. Columns Column Description ID Unique activity-log row ID. Date Date and time at which the event was logged. Tenant Tenant associated with the operation. System-wide operations can have no tenant name. User Web username or process label responsible for the event. Examples include OPENAPI, AUTO, or housekeeping. Action Short operation code. The current standard codes are described below. Host Client IP address. When location data is available, the interface also displays the country flag and name. User Agent Browser or API client user-agent string. Country code / Country Location resolved from the client IP address when the event was written. Table Database table or logical object associated with the operation. A suffix such as -de_destinations identifies related routing destinations. Table ID Database or logical record identifier used by the operation. Table value Human-readable value used to identify the affected object, such as an extension number or object name. Old values Field values captured before the operation. New values Field values captured after the operation. Changed values Calculated summary for standard insert, update, delete, and failed-upgrade events. Requested URI Host and web path that generated the log row. Important: activity details can contain configuration values, addresses, object names, and request information. Restrict access to trusted administrators and protect exported CSV files accordingly. Passwords and other secrets are masked by supported logging paths, but historical or custom log writers might not apply the same masking. Record and page-change actions Action code Meaning INSERT A new database or logical record was created. New values contains the captured state. UPDATE An existing record was modified. Compare Old values, New values, and Changed values. DELETE A record was removed. Old values contains the captured state before deletion. UNDO UPDATE An administrator used User Activity to restore the old values of an UPDATE row. UNDO DELETE An administrator used User Activity to recreate a record from a DELETE row. PAGE CHANGE Automatic fallback audit entry written when a page changed the database without writing a more specific activity row. The old side contains a sanitized request; the new side summarizes detected SQL mutations. Authentication and security actions Action code Meaning LOGIN Successful web-interface login. LOGIN FAILED The supplied web credentials were not accepted. reCAPTCHA FAILED The login request failed the configured reCAPTCHA check. LOGIN FROM IP NOT ALLOWED The global web GeoIP policy rejected the source IP country. TOO MANY FAILED LOGIN FROM IP Web fail2ban rejected the source IP after too many recent failures. LOGIN BLOCKED BY IP The user account IP filter did not allow the source IP address. LOGIN DISABLED BY INACTIVITY A login was refused because inactivity housekeeping had disabled the account. LOGOUT The user logged out, or the session was terminated for a security reason such as an unexpected IP change. Review the values for the reason when present. DISABLED BY INACTIVITY Housekeeping disabled a web user or extension after the configured period without a successful login. GOOGLE 2FA GENERATED A Google Authenticator secret was generated or enrolled for a user. MULTIMANAGER LOGIN Successful login to the MiRTA PBX MultiManager socket service. MULTIMANAGER LOGIN FAILED Failed login to the MultiManager socket service. MULTIMANAGER LOGOUT Logout from the MultiManager socket service. Campaign actions Action code Meaning START The selected campaign was requested to start. STOP The selected campaign was stopped and returned to the ready state. PAUSE The selected campaign was paused. RESUME The selected campaign was resumed. RESETCALLS Attempt, disposition, duration, and related call-result fields were reset for the selected campaign numbers. SIP and runtime-state actions Action code Meaning RESET An extension, virtual extension, flow, BLF, or related runtime state was reset to the value shown in New values. PRUNING A SIP or PJSIP endpoint was pruned from runtime state while maintaining or refreshing an extension. UNREGISTERING A SIP or PJSIP endpoint was explicitly unregistered while changing or deleting an extension. System, report, and access actions Action code Meaning READ A protected object was opened or retrieved by a logging-enabled path, currently including provider details and recording access. It does not mean that every ordinary page view is logged as READ. EXECUTE A configured report was executed. The logged values include the requested date range and generated report-data ID when available. TESTSENDEMAIL The test-send action was used for an email template. DATABASE UPGRADE A database upgrade step completed and advanced the stored database version. FAILED DATABASE UPGRADE A database upgrade step failed. Review the old/new version and saved error message, then also check the process and PHP logs. DID-provider and emergency-data actions Action code Meaning NUMBER ALLOCATE A number was allocated through a supported DID provider. NUMBER ACTIVATE An allocated DID-provider number was activated. NUMBER ASSIGNED A provider number or number from a block was assigned to a MiRTA PBX tenant/DID record. NUMBER SET Routing targets for a DID-provider number were changed. NUMBER DEACTIVATE A DID-provider number was deactivated. BLOCK NUMBER ACTIVATE A block of provider numbers was activated. BLOCK DEACTIVATE A block of provider numbers was deactivated. 999 SET UK emergency-service address data for a provider number was changed. 999 CREATE A UK emergency-service address record was created for a provider number. Additional action codes The Action field is a text value, not a fixed database enumeration. The tables above list every standard literal code used by the current MiRTA PBX source, while dynamic CRUD logging resolves to INSERT, UPDATE, or DELETE. Older releases, plugins, integrations, or local customizations can write other codes. Interpret an unfamiliar code together with User, Table, Table value, the old/new values, and Requested URI. Undo limitations Undo is available only for rows whose action is exactly UPDATE or DELETE. The activity row must contain enough saved old values to identify the table, primary key, and restorable columns. For an update, the target record must still exist. For a delete, a record with the same key must not already exist. Routing-destination logs receive special handling, but Undo otherwise restores one logged table at a time. Related rows, generated configuration, caches, and runtime state are not automatically guaranteed to be restored. A successful operation creates an UNDO UPDATE or UNDO DELETE audit row. Recommendation: inspect the complete row first, take an appropriate backup, and use the normal configuration page when the change affects multiple related objects or runtime configuration. After Undo, verify the object and apply any normal reload or regeneration step required by that feature.