CREST account management: administrator guide
Open CREST Administration and sign in with your administrator email and password. Enter the six-digit code from your authenticator app when prompted.
All active users have access to Denmark and Sweden automatically. There are no region permissions to configure. Users sign in with their email address; email addresses cannot be changed. This guide uses the English screen labels.
Give a new employee access
- Ask the employee to open crest.nu, choose Request access, and submit their name and work email. They do not choose a password yet.
- New requests from gyldendal.dk, gyldendalastra.se and tukanforlag.se are approved automatically. You receive an FYI: SMS; no approval action is needed. Invitations should arrive within the next minute; ask the employee to check their spam folder.
- For other domains, you receive an email and SMS notification linking to Administration. You can also check Requests → Pending at any time.
- Check that you recognize the employee and that their email is correct. Requests are unverified: submitting the form does not prove ownership of the email address.
- Choose Approve and invite. CREST creates the account and emails a temporary password to the employee.
- The employee signs in at crest.nu with their email and temporary password within seven days, then chooses a new password of at least eight characters. Both markets are available immediately.
To decline a request, choose Reject. CREST does not send a rejection email; tell the employee separately if needed. For a mistyped email, reject the request and ask them to submit a new one with the correct address. A rejected email address can be submitted again after 24 hours.
Use the Approved and Rejected filters to review past decisions.
Find and manage an account
Choose Users, select Active, Suspended, or Deleted, then choose Open account beside the person. Use Refresh to update the view and Load more when more records are available. On a phone, account details appear below the list.
Active means the account is allowed to sign in. It does not mean the person is online or has completed their first login.
| Action | When to use it and what happens |
|---|---|
| Save name | Correct the display name. The sign-in email stays the same. |
| Resend invitation | Help someone who has not finished their first login. Sends a new temporary password and starts a new seven-day invitation window. They should use the newest invitation. |
| Send password reset | Help an established user regain access. Emails a reset code; sending it does not itself change their password. |
| Sign out all sessions | End access from all currently signed-in browsers/devices. The account remains Active and the person can sign in again with their existing password. |
| Suspend | Temporarily block access and sign out all sessions. The account and history are retained. |
| Reactivate | Restore a suspended account. The person must sign in again; previous sessions stay invalid. |
| Delete account | Remove the login account and sign out all sessions. The name, email and history remain in the Deleted view. This cannot be undone with Reactivate. |
Only applicable actions appear. Invitation and password-reset actions are available for Active accounts; wait at least 60 seconds between these email actions for the same person. You never need to know or choose their permanent password.
For a temporary absence, use Suspend, then Reactivate when they return. For a departing employee, use Delete account when access should end permanently. If they later return, they can request a new account using the same email after the 24-hour deletion cooldown. Their old history remains with the deleted account.
Suspension, deletion and signing out invalidate existing application sessions. Previously issued data links can remain usable for up to five minutes.
Administrator accounts cannot be suspended or deleted. Assigning administrator access is not available on this screen.
Help with sign-in and incomplete actions
- Invitation missing or expired: check the email shown on the account, ask the employee to check spam, then use Resend invitation. Invitations come from
support@crest.nu; replies go tocrest@rmstar.com. - Forgotten password: the employee can choose Forgot your password? on the sign-in page and follow the reset steps. Use the latest emailed code if more than one has been sent.
- No request notification: check Requests → Pending. Saved requests remain available even if the notification is delayed.
- “Approval in progress — retry to finish”: choose Approve and invite again to finish the existing approval.
- “An action is pending. Retry it to finish.”: choose Refresh, reopen the account if needed, and retry the action shown. CREST also retries pending account actions automatically every five minutes. Access restrictions remain in place while the action is pending.
- “This record changed…”: refresh, reopen the account and try again.
If an action remains stuck, use the technical operations guide for investigation. Do not delete and recreate an account to repair an interrupted action.
Check first login and recent activity
The Users list and account details show First login completed with its first recorded timestamp, or No completed login recorded. This is separate from Active, which means the account is enabled. A user can have an active account while still needing to use their invitation and set a password.
Last recorded server contact shows the latest contact recorded against a device session. Recent account activity lists successful authentication, use of an existing login, failed logins and failed session renewals. Use Load more for older entries and Refresh to reload the account.
Activity history is kept for 90 days; first-login evidence is retained with the account's session history. Updates can arrive with a delay. The panel shows when history was last updated and warns when updates are delayed or unavailable. An unavailable history is not evidence that the person has never logged in.
These records do not measure visits, time online or every interaction with already-loaded data. Several days of activity can use one device session. An empty history means no recorded authentication activity in that period. It does not establish whether someone read an invitation or found it in junk. All times are UTC.
Read session history
Recent sessions shows browser/device sessions, with their start, last server contact, end and expiry times. All times are UTC. The device label is a short identifier, not the device's model or name.
Valid means a session can still be used; Ended and Expired sessions can no longer be used. A valid session does not prove that someone is online, and last server contact does not measure time spent using CREST. Several sessions for one person are normal when they use multiple browsers or devices.
To end sessions, use Sign out all sessions; individual session removal is not available.
Check email delivery
Choose Emails to see invitations and password-reset/verification emails sent to users. Use Search with the complete recipient address, or select a status. Needs attention includes delayed, failed and complaint messages. Select an email to open its delivery timeline. The same Email history appears inside each account's details.
Sent means AWS accepted the send request. Accepted by mail server means the recipient's server accepted the email; it may still be in spam. Delayed means delivery encountered a temporary problem. Failed means delivery stopped, was rejected or was suppressed. Complaint received means the mail provider reported adverse feedback; the explanation distinguishes the reason.
History covers the last 90 days, starting when tracking was enabled. All times are UTC. Visible email panels refresh every 15 seconds; Refresh updates them manually. Passwords and email bodies are never shown.
Failures and complaints alert the operations mailbox at crest@rmstar.com. Alert links open the affected message after administrator sign-in. A resend is a new message with its own history. Use the existing account actions when needed; CREST does not automatically resend failed emails.