/
The admin passphrase, the Administration area of Dermi Atlas Manager, the local account controls, the deployment-wide settings, and the deployment purge.
Administration of a Dermi Atlas Professional deployment is split between two places. Team membership, seats, and billing belong to the license owner in Dermi Portal. Everything that acts on the deployment itself, the settings that govern logging and retention, the immediate disabling of an account, and the permanent removal of clinical data, belongs to Dermi Atlas Manager on the computer that hosts the deployment, behind an admin passphrase.
This article covers setting that passphrase, the recovery phrase issued with it, what the Administration area holds, and how the deployment purge works.
The admin passphrase is set once, on the Admin Passphrase page that Dermi Atlas Manager opens at the end of a fresh installation and at the first launch on an existing installation. Until it is set, the Administration area cannot be opened.
The passphrase never leaves the host computer, as the setup page states: "It never leaves this computer". It is held there only as a hash, is not merged into the configuration that Dermi Atlas Manager sends to the deployment, is not written to the database, and has no Dermi-operated reset path.
Illustrative demo with synthetic data. Learn more
The passphrase is a safeguard at that computer rather than a second sign-in: it protects irreversible and deployment-wide actions from being taken casually or by accident, and it does not replace the Dermi Atlas sign-in that clinicians and staff use. Anyone with administrative control of the host computer itself is outside its reach, which is why the host is secured in its own right, as described in Data Security Architecture.
Immediately after the passphrase is set, the Recovery Phrase step shows a single-use recovery phrase of six groups of four characters. It is shown once and never again.
The phrase is what resets a forgotten passphrase, and a new phrase is issued each time one is used. To use it, open the Administration page in Dermi Atlas Manager, select Use Recovery Phrase on the locked page, and enter the phrase together with a new passphrase in the Reset Passphrase drawer.
A new phrase can be issued at any time from the Admin Passphrase card in the Administration area, using Reissue Recovery Phrase. Issuing a new one retires the previous phrase.
If both the passphrase and the recovery phrase are lost, the passphrase record is deleted from the deployment data directory on the host and Dermi Atlas Manager is relaunched, which returns to the setup page. Filesystem access to the host is the proof of custody in that case; the recovery document names the file to remove, and Dermi support walks through the step when needed. No accounts, settings, or patient records are affected by that reset.
The Admin Passphrase card in the Administration area carries Change Passphrase, which opens a drawer holding a Current Passphrase field and a New Passphrase field, with one Show passphrase checkbox governing both.
Administration is a section of the Dermi Atlas Manager sidebar. It is locked every time the application starts and is unlocked for the rest of that session by entering the passphrase once. A Lock control in the page header re-locks it without closing the application, and it refuses to lock while a settings edit is unapplied.
The unlock card carries an optional Operator Name above the passphrase field, up to 64 characters, described there as "Recorded on each administrative action taken while unlocked." A name entered is held for the unlocked session, recorded on every administrative action taken during it, shown beside Atlas Manager on the Administration Activity card, and cleared at Lock. It is a record of who was at the keyboard rather than a second credential: the passphrase remains the only gate.
The page is grouped into four headings.
User Accounts lists the accounts on the deployment, described as "Review membership and disable or re-enable accounts". It is a read-only mirror: each row carries the member's name, the username, a Clinician or Assistant chip, a membership chip reporting what the last member list from Dermi Portal said about that person, and a Disabled chip where the account has been disabled locally. Accounts appear here once a member claims an invitation. Pending invitations from the member list are listed after the accounts by email address with an Invited chip; they are acted on in Dermi Portal.
Each row offers one action:
Disabling is the immediate control for a member who must lose access at once, for example a lost device or a departure taking effect the same day. Removing the member in Dermi Portal is the durable one, because a member removed there is refused at the deployment from its next check-in whatever the local setting says.
Illustrative demo with synthetic data. Learn more
Above the list, a status row reports the state of the member list, and Sync Now checks in with Dermi Portal immediately rather than waiting for the next scheduled check-in. It is the control to use after a change is made in the portal that should take effect at once.
Illustrative demo with synthetic data. Learn more
Administration Activity sits after User Accounts and lists what has been done on the deployment, described as "Sign-in and administration records of the deployment". The rows are read-only and newest first, each carrying an operation chip, the actor, the time, and a one-line summary, with the address and device named on account rows.
The actor takes one of four forms:
Recorded here are sign-ins and failed attempts, two-factor, password, and email changes, invitation claims, session invalidations, account recovery and deletion, refused actions, settings changes, account disabling and enabling, member list check-ins and their outcomes, and purge outcomes. Refresh in the card header reloads the list from the newest row, and Load More at the end of the list appends older ones.
Clinical activity is not listed here. Patient, entry, and image events stay in Dermi Atlas and are read from the patient record, as described in Audit Logging Configuration.
Illustrative demo with synthetic data. Learn more
Three deployment-wide settings live here, each applying to every account on the deployment:
Illustrative demo with synthetic data. Learn more
These are covered in Audit Logging Configuration and Configuring Data Retention for Deleted Records. The Admin Passphrase card sits in the same group.
Alongside the cache and license controls, Member List Recovery clears the member list held on the deployment so that a correct one is received at the next check-in, with Sync Now on the User Accounts card checking in immediately. Accounts, sign-in, and patient records are not changed by it. The action is confirmed with the passphrase and is the step Dermi support asks for when a deployment is not receiving membership changes correctly.
Deployment Purge sits immediately before the Atlas uninstall card. It is described below.
The deployment purge permanently deletes every patient record on the deployment while leaving the deployment itself, its accounts, and its configuration in place. It is the tool for decommissioning a deployment, for clearing an evaluation or training installation before real use, and for returning a host to a clean state without reinstalling.
There is no recovery from it. A system backup taken beforehand is the only way back, and the card carries a link to the Backups page for that reason.
What is deleted:
What is kept:
To run it:
Illustrative demo with synthetic data. Learn more
The purge is reported in the drawer rather than as a notification, and open Dermi Atlas pages refresh themselves as the records disappear. It is recorded on the Administration Activity card, where the outcome is read once the drawer is closed. Only one purge runs on a deployment at a time; a second request while one is in progress is refused rather than queued.
Dermi Atlas Manager administers the deployment, not the team. It cannot invite a member, change a member's account type or email address, remove a member, or add or reduce seats. Those belong to the license owner in Dermi Portal, and the deployment applies them at its next check-in, described in Inviting and Managing Team Members. Dermi Atlas Manager holds no seat counts and no purchase controls.
Nothing in the Administration area sends clinical data anywhere. The member list travels from Dermi Portal to the deployment and reports only who is on the team; patient records, images, and clinical notes stay on the practice infrastructure throughout.
Your feedback helps us improve our documentation
Contact our support team for personalized help
All demonstrations, screenshots, and media on this page use synthetic data only. No real patient information is shown.
The following are synthetic and do not correspond to real patients:
Media is provided solely to illustrate platform functionality and workflows.