Access Manager: User Management and Single Sign-On (SSO)

The Access Manager is the central place in Tresio to manage user access. This feature lets users, e.g. accountants, log into multiple shared workspaces across different companies and manage all their activities from a single profile.

The Basics of the Access Manager Screen

The Access Manager screen is a helpful tool for workspace owners (account owners) and authorized users to manage access efficiently. Workspace owners can add and manage users, while users with write access can edit existing users but cannot add new ones.

Each user’s access can be granted individually: per company, which companies they can access at all, and per page or tool (e.g. Analytics, Bank accounts, Scenarios, Invoices, HR Planning, etc.), whether they can only read there or also edit (write access). This allows access to be controlled granularly down to the company and function level for every user.

The screen displays the following information:

  • User Name – the registered name of the user
  • Email – the email associated with the user’s login
  • User status – automatically updated when the user registers with Tresio
  • Active – indicates whether the user is Active or Blocked
  • Granted until – the expiration date of the user’s access rights
  • Comment – custom notes or remarks added directly to the user’s record
  • Description – details the user’s current access to pages and companies

The page also offers an option to print or export user records (Excel, CSV, PDF, copy to clipboard, or print) using the available export function.

Adding a new user

Only a workspace owner can add a new user. To do this, go to the Access Manager page and click the New button.

A pop-up window appears where you can enter the required user data, including the User type (Read-only user or Power-user).

Updating an existing user

Both the workspace owner and users with write access to the Access Manager page can change an existing user’s access rights. To do this, click the pencil icon next to the user’s name.

This opens the “Workspace account” page, where you can update the user’s active status, the date until which access is granted, a comment, and the access rights per company and page described above.

Two-factor authentication (2FA) will soon be available as an additional security option.

You can also update a user’s contact details via the person icon (name, address, contact details, User type).

Removing a user

Both the workspace owner and users with write access to the Access Manager page can remove existing users by clicking the trash icon.

Once a user is removed, they lose access to the Tresio system.

Single Sign-On (SSO) and authorized domains

With Single Sign-On (SSO), users can log in to Tresio with their existing corporate credentials (e.g. Microsoft 365 or Google Workspace) without needing a separate Tresio password. This simplifies the login process, increases security, and makes central user management easier.

Authorized domains ensure that only users with a specific corporate domain (e.g. @company.com) get access to the Tresio account. This gives companies full control over who can access their financial data.

Together, SSO and authorized domains provide more security, simpler administration, and a seamless user experience.

Using authorized domains requires a Tresio Enterprise account. Feel free to reach out to our team.

Adding a Domain

Navigate to Access Manager in the menu and click Add Domain.

Then add the domain you want to enable for Tresio access. Please note that this add-on is only available for Enterprise accounts. Once the access request is submitted, our support team will reach out to you. For any questions regarding this service, our team is happy to help.

Registering Additional Users

Once the domain is enabled, employees of your organization can create a new account.

New accounts under the enabled domain are created via the registration page (https://tresio.ch/system/homer/signup.php). New users can register either via email address or via Single Sign-On.

Managing Default User Permissions

Once the domain is enabled, employees of your organization automatically get access to your organization’s Tresio environment. To prevent unauthorized employees from accessing sensitive data, we recommend limiting the default view for new employees to a minimum. You can do this in the Access Manager as well.

By default, all views are disabled for new users (recommended). Once new users from your organization register, you can grant them the appropriate user rights.