Employees, Roles, and Permissions
Invite people one by one or by CSV, set roles, managers, and groups, control sign-in with SSO, and review anyone's training record in OneRange Vero
For administrators · 5 min read
- Roles and what each can do — Four customer roles, combinable
- Adding people one at a time — Add Employee
- Bulk upload by CSV — Onboarding a team or a whole company
- Invites and signing in — What new people experience
- Single sign-on — Require your company's SSO portal
- Managers, teams, and groups — Two ways to organize people
- Editing a person — Edit Member
- An individual's training record — Everything about one person's training
- Good habits — Keeping your people data useful
- Common questions — Quick answers
1. Roles and what each can do
Four customer roles, combinable
| Employee | Takes assigned training and assessments. Sees My Training and My Profile. Everyone has this role, and it cannot be removed. |
|---|---|
| Manager | Sees their direct reports on the Dashboard, Employees (My Team), and Analytics. Can add people to their team and send reminders. Can browse courses and programs. |
| Course Manager | Builds courses and pathways, plans from a goal, assigns courses and pathways, and reviews the Feedback tab. Edits only what they created. |
| Admin | Everything: people and roles, Company Settings and the Knowledge Library, skill assessments, the Assignments hub, and every course and pathway. |
Roles combine. A team lead who builds training for their team can be Manager and Course Manager, and gets both views. Only Admins change roles, and an Admin cannot remove their own Admin role.
Permissions at a glance
| Build and edit courses and pathways | Admin (any), Course Manager (their own). |
|---|---|
| Assign courses and pathways | Admin, Course Manager. |
| Create and assign skill assessments | Admin. |
| See team analytics and records | Admin (company), Manager (direct reports). |
| Send reminders | Admin, Manager. |
| Customize Vero AI Catalog courses | Admin. Course Managers can view customizations. |
| Company Settings, Knowledge Library, MCP | Admin. |
| Grant test-out retakes | Admin. |
2. Adding people one at a time
Add Employee
On Employees, click Add Employee.
| Name and Email | Required. Any email domain is accepted. An email already registered with another company is rejected. |
|---|---|
| Job title (optional) | Vero uses it to pick training examples from their day-to-day work. |
| Groups | Type and press Enter or a comma. People can belong to several groups. |
| Role | Employee, Manager, or Admin. Add Course Manager afterwards with Edit Member. |
| Manager | Search by name or email, or choose No manager. |
Click Send Invite. If the person already has a Vero account, it is reattached and they get a fresh sign-in link. Managers can add people from My Team; they are set as the new person's manager automatically.
3. Bulk upload by CSV
Onboarding a team or a whole company
- On Employees, Company tab, click Bulk Upload, then Download template.
- Fill in one row per person: name, work_email, manager, job_title, and groups. Separate multiple groups with a semicolon or a vertical bar, up to 10 per person.
- Put the manager's email in the manager column. Managers must already exist in Vero, so upload managers first, or run the file twice.
- Click Choose CSV. The preview shows how many rows are ready and why any were skipped (missing name, invalid email, or a duplicate in the file).
- Send the invites. Each row reports Sent, Already registered, or failed with a reason.
- Up to 5,000 rows per upload.
- Re-running the same file is safe; existing people are not invited twice.
- Everyone arrives as Employee. Set Manager, Course Manager, or Admin roles afterwards.
- Common alternative headers are recognized, such as email for work_email, title for job_title, and department for groups.
4. Invites and signing in
What new people experience
- The invite email links to Vero. The link confirms their email and signs them in.
- They set a password, then land on My Training (or the Dashboard for admins and managers). With SSO only turned on, they skip the password step.
- Expired links offer Send me a new invite.
- After that, people sign in with their email and password, or Continue with Google.
- Vero is invite-only. People who have not been invited cannot create an account.
On Employees, the Status column shows Pending (with a Resend button) until someone signs in, then Active or Inactive.
5. Single sign-on
Require your company's SSO portal
In Company Settings, Single Sign-On, turn on SSO only to disable email, password, and Google sign-in for everyone in your company, admins included. People then reach Vero through your SSO portal. Your OneRange contact sets up the SSO connection with you first; confirm you can sign in through it before turning SSO only on.
Need people created and updated automatically from your HR system? OneRange can connect it through an API that creates people, updates job titles and groups, links managers, and deactivates leavers. Talk to your OneRange contact.
6. Managers, teams, and groups
Two ways to organize people
| Manager | Each person's manager defines My Team. It drives what managers see on the Dashboard and in Analytics, team filters on assignment pages, and reminders. |
|---|---|
| Groups | Free-form tags such as Sales, EMEA, or 2026 New Hires. A person can be in many. Groups power the All Groups filter on Employees, the Group filter when assigning, and the All Departments filter in Analytics. |
| Programs | Tick people on the Company tab and click Add to program to tag them into a program for reporting. Tagging does not assign anything. |
Tip: Keep group names consistent (Sales, not Sales Team in one row and sales in another). Analytics groups by the exact name.
7. Editing a person
Edit Member
Click the pencil on a row to open Edit Member.
| Name, Email, Job title | Keep the job title current. It shapes training examples. |
|---|---|
| Main kind of work | What they spend most of their time on. Vero uses it to choose examples and practice tasks. |
| Groups | Add or remove tags. |
| Role | Employee, Manager, Admin, and Course Manager, in any combination. |
| Manager | Change who they report to. |
| Account Active | Turn off to block access. Their training history is kept. |
You cannot deactivate your own account. To delete an account permanently, contact OneRange support.
8. An individual's training record
Everything about one person's training
Click a person's row to open their record. Managers see records for their direct reports.
- Header: job title, email, groups, and Position history when they have moved roles.
- Stats: Total Courses, Completed, Training Time, Avg Quiz Score, Skills Tracked, Assessments, and Assessments Done.
- Progress & Timeline: training over time, quiz scores, skill mix, and milestones.
- Recommended Courses: up to five prioritized suggestions. Admins and Course Managers can assign them directly.
- Certifications and Skills with a level on each skill.
- Training History: per course, the baseline, practice evidence, sessions, rubric breakdown, and the AI Performance Summary, with Regenerate summary.
- Skill Assessments with AI Assessment Insights, and Reminder History.
9. Good habits
Keeping your people data useful
- Set managers at invite time so team views work from day one.
- Fill in job titles. They are the cheapest way to make training more relevant.
- Review Pending invites weekly and Resend where needed.
- Deactivate leavers promptly rather than deleting them, so reporting history stays intact.
10. Common questions
Quick answers
Can people sign up without an invite?
No. Vero is invite-only; people who have not been invited see a message asking them to contact their admin.
Does Vero support Apple sign-in?
People sign in with email and password or Continue with Google, or through your SSO portal when SSO only is on.
Can someone have two roles?
Yes. Roles combine, and every person also has the Employee role.
What happens to a deactivated person's data?
Their training history is kept for reporting. They simply can no longer sign in.
Can a manager add people?
Yes, to their own team from My Team. Only admins change roles or deactivate accounts.