← Back to the hackathon home
Topic 15 of 18

Creating Users in DHIS2

Step by Step Guide: Roles, Users, Groups and Who May See What

Purpose of this guide

Nobody can enter or read data until they have an account, a role and an organisation unit. This guide builds all three, in the order that works, and ends with the rules that keep a system usable a year from now.

Step 1: Three Things, in This Order

A user on its own can do nothing. What a person may do comes from the role, and where they may do it comes from the organisation units on their account.

ObjectAnswersExample
User roleWhat they may doData entry clerk: enter data, run validation
Organisation unitsWhere they may do itNgelehun CHC only
User groupWho they belong to, for sharingMalaria programme
UserThe person, holding all threeFatmata Kamara
Click: Apps menu → Users
Step 2: Create the Role First

A role is a list of authorities, and the data sets the person may enter.

Figure 1. A data entry clerk role. This picture was drawn for the guide. Your screen will show your own names and dates.
  1. 1Name. Say what the person does, not who they are.
  2. 2Description. One line, so the next administrator understands it.
  3. 3Authorities. Tick only what the job needs. Data entry and run validation here.
  4. 4What to leave off. Maintenance and import authorities belong to administrators.
  5. 5Data sets. A role can only enter the data sets moved to the right.
  6. 6SAVE. The role is now available to every new user.
Step 3: Create the User
Click: Users → NEW USER
Figure 2. The new user form. This picture was drawn for the guide. Your screen will show your own names and dates.
  1. 1Username. Short, lowercase, and never shared between two people.
  2. 2Password. Temporary. The person changes it at first login.
  3. 3Names and email. The email matters for password resets and messages.
  4. 4User roles. Move the role you built in Step 2 across.
  5. 5Organisation units. Data capture units decide where they may enter data. Choose the facility, not the country.
  6. 6SAVE. The account can be used straight away.
Step 4: Check the List
Figure 3. User management. This picture was drawn for the guide. Your screen will show your own names and dates.
  1. 1User management. Everyone who can sign in.
  2. 2Search. By name or username.
  3. 3NEW USER. The button used in Step 3.
  4. 4The role column. Check it before you tell somebody their account is ready.
  5. 5Org units. A clerk with the whole country can enter data anywhere. Usually wrong.
  6. 6Status. Disable an account when somebody leaves. Never delete it, or their data loses its author.
Step 5: Group Users for Sharing

Groups are how dashboards, charts and data sets are shared. Sharing to a group means the list stays right when people come and go.

Figure 4. A user group. This picture was drawn for the guide. Your screen will show your own names and dates.
  1. 1Name. The team, not the task.
  2. 2Available users. Everyone else.
  3. 3Members. The people in the team.
  4. 4SAVE. Now usable in every sharing dialog.
Step 6: The Rules That Save Trouble Later
RuleWhy
One account per personShared accounts make the audit trail useless
Roles by job, not by personTwelve clerks should share one role
Capture units as low as possibleA clerk needs one facility, not the district
Disable, do not deleteDeleting breaks the history of who entered what
Superuser for two people at mostIt can change or delete anything
Share to groups, not to peopleSharing survives staff turnover

Final Checklist