Skip to main content

User Password Management

Most of the time, researchers manage their own Aeon passwords: they set one when they register, change it from their profile on the patron web pages, and use the Forgot Password? link on the logon page if they forget it. None of that touches the staff client.

Staff step in for the exceptions — a patron calls the desk locked out, a colleague needs a temporary password for a walk-in researcher, or you're creating an account by hand and want the person to choose their own password the first time they log in. For those cases the staff client lets you set a new password on any user record and, optionally, force a password change on next login so the value you type is only ever a one-time credential.

When you'll use this
  • A researcher can't log in and needs you to set a working password over the phone or at the desk.
  • You're creating a user account manually and want to seed a temporary password the patron must replace on first login.
  • You want to invalidate a patron's current password and require them to set a fresh one next time they sign in.
This is the staff side only

This page covers what staff do from the user record. The patron-facing flows — a researcher changing their own password under My Profile, or using Forgot Password? on the logon page to get a reset email — live in the Aeon patron web interface, which is a separate application from the staff client. When you set a password here, the patron can still change it themselves later from their profile.

Changing a user's password

You change a password from the user's record, so open the user first.

  1. Open the user record — search for the researcher and open their detail view (for example, user jdoe).
  2. In the toolbar, open the Manage dropdown and choose Change Password. (When the toolbar is in its compact, icon-only mode, Manage is the person-with-gear icon — hover it to confirm, then open it the same way.)
  3. The Change Password dialog opens, headed "Set a new password for user jdoe."
  4. Type the password into New Password, then type it again into Confirm Password. Use the eye icon at the end of either field to reveal what you've typed.
  5. Click Change Password.

On success you'll see a "Password changed for jdoe" confirmation and the dialog closes.

The two fields must match

Confirm Password exists only to catch typos. If the two fields differ, the dialog shows "Passwords do not match" beneath the confirm field and the Change Password button stays disabled until they agree. A password can be up to 50 characters.

Requiring a password change on next login

Inside the same dialog there's a checkbox: Require password change on next login.

  • Leave it unchecked to set a normal, permanent password — appropriate when the patron told you the value they want.
  • Check it to make the password you typed a one-time credential. The patron can sign in with it once, but Aeon immediately requires them to choose a new password before they can do anything else.

Checking the box is the safer choice whenever you picked the value (a temporary password read over the phone, for example), so a staff-chosen password never stays in place.

You can't reuse the current password

Aeon refuses to "change" a password to the value it already has. If the new password matches the account's current one, the change is rejected with "New password matches current password. Please choose a different password." Enter a genuinely different value.

Setting the password when you create a user

When you create a user account by hand, the password isn't optional — it's part of the new-user form, not a separate step afterward.

  1. Start a new user (see Creating a New User).
  2. In the top section of the form, fill in Password (required, marked with a red asterisk) and Confirm Password. The same show/hide eye toggle and 50-character limit apply.
  3. To make this a one-time credential, check Require password change on next login below the password fields — the same option as in the Change Password dialog.
  4. Finish creating the user.

This is the usual way to onboard a manually created account: set a temporary password, check Require password change on next login, and hand the temporary password to the researcher knowing they'll have to replace it the first time they sign in.

What the patron sees afterward

  • If you set a normal password, the researcher logs in with it as usual and can change it later from their profile on the patron web pages.
  • If you checked Require password change on next login, the patron's next sign-in sends them straight to a change-password step before they reach their account — Aeon has cleared the "password is current" marker, so the old value no longer works on its own.

Either way, the change is logged on the user's record. You can see that a password was changed (and by which staff member) in the user's change history — see User History and Change History.

Permissions
  • Setting a password from the user record is an administrative action. In the staff client, the Change Password menu item is available only to roles with Full access to Users — if your role has View or Edit on Users, the item is visible but disabled.
  • Creating a user (and therefore setting its initial password and the force-reset option) requires at least Edit access to Users.
  • A locked record blocks the toolbar's Manage menu while another staff member is editing the same user; wait until they release it. See Opening and Locking a User Record.