Managing VA User Profiles
VA User Profile adds and maintains Vista users. For classic SQL users, the system creates a SQL login unless the user already exists or the name is a domain login. Profile creates/updates/deletes write HQ Master Audit (HQMA); report via HQ Audit Detail.
Trimble form: VA User Profile Form. Primary SQL procedure: Create a Vista SQL User in VA User Profile. Related: Create Vista User SSO with Trimble ID; Create a Vista Domain User.
Before you start
- Access to VA Password (Apply Form Security Settings).
- Know login type: SQL, domain (
DOMAIN\\user), or SSO/Trimble ID (Trimble Construction One cloud). - Know security groups and whether the account is Vista (app user) or User Application (integration only: no Vista license, cannot log in, VCSUsers/views only; datatype security still applies).
- TC1 cloud: classic SQL/Windows logins are stated as unsupported after fall 2025; use SSO/Trimble ID. Legacy cloud and on-premises may still use classic credentials.
Create a Vista SQL user
- Viewpoint Administration → Programs → VA User Profile → New Record.
- Enter User Name (must match SQL name exactly; case-sensitive). Set User Type = Vista.
- On Info: identity, cloud License Type if named-user, Form & Report Options, Defaults, Permissions, Override Max # of Rows, Menu Options.
- Optionally set Auto-Log Off, lookup/UI options, leave/timesheet/PM permissions, Security Groups, Notification Prefs, Project Collaboration fields.
- Save. If no SQL login and not a domain user, the system says it will create a SQL login — select Close. If the name contains a domain, Vista assumes a SQL login already exists and does not create one.
- VA Password: enter and confirm password, OK. System creates the SQL login if needed.
- Save again. New records: Deactivated is checked and locked ~1 minute, then refresh clears it if a license is free. Share credentials. Some option changes need Vista closed and reopened.
Key fields
Login / Info
- User Name (up to 128). SSO (TC1 cloud only): email = Trimble ID, check Is SSO Account. SQL: exact SQL name. Domain:
DOMAIN\\user. F4: Viewpoint Users or System Users. - User Type: Vista vs User Application (do not check Is SSO Account for User Application).
- Email: unique across profiles; also used by PM Create and Send.
- Deactivated / Expires: expired treated like deactivated; also disable SQL access when deactivating.
- License Type (cloud named-user only): Office, PM, Consultant (usage tracked, not against contracted limits). Concurrent licensing: dropdown disabled, default Office. License type does not block granted forms; PM users who open Office-required programs/reports are counted as Office.
- Company: default company (Main Menu company dropdown resets it).
- AP Pay Category: overrides AP Company Parameters; not validated per company.
Permissions / options (highlights)
- Menu Administrator / Form Administrator — grant sparingly (customizations / form properties).
- Display Earnings Rates in PR Timecard Entry — unlocks rates/amounts; grant sparingly.
- Disallow Self Security Assignment — blocked if VA Site Settings Disallow Self Security Modifications (All Users) is on.
- Lookups / Page Size / Suppress Max Warning Rows: per-user overrides of VA Site Settings.
- Auto-Log Off only if VA Site Settings Use Auto-Log Off is on.
- Security Groups tab; Notification Prefs (email vs VA Messages); Roles tab (HQ Roles).
Form Options and User Options update each other; not every field syncs. Menu fields sync with View and Options menus.
Hard rules
- Case-sensitive User Name must match SQL or Windows.
- Email used as login must be unique.
- New profile starts Deactivated until license provisioning (~1 minute).
- Domain in User Name → no automatic SQL login.
- User Application ≠ SSO.
- Site-wide disallow-self-security overrides the user checkbox.
Notes
- Related: VA Password; VA User Delete; VA Copy Security; VA Security Groups; VA Site Settings; VA Messages; User Options; HQ Roles; HQ Audit Detail; VA Business Intelligence Mgmt; Apply Form Security Settings.