ssm.ro Docs
User GuidesUser Guide

Settings

Advanced platform settings for ssm.ro — workplace supervisor, local accounts, language, employee import, email and STS signature.

Workplace supervisor identification mode

There are two ways to assign the workplace supervisor (CLM) for each employee. In both cases, the CLM can only be chosen from contacts with the Employee role.

1. Through the company organizational chart

You create an organizational chart of departments and sub-departments. Each employee is part of a department, and the department head automatically becomes the CLM. If the direct CLM is suspended, the head of the higher-level department is automatically taken over as CLM.

The supervisor is assigned from Organigrama → click on the department → choose the department manager. See Department manager.

2. Through employee badge number and supervisor badge number

Each employee is given a unique badge number (Nr. Marcă) and a Supervisor Badge Number (Nr. Marcă Conducător). The values can be imported or entered manually, from ContacteDetalii contactConducător Loc Muncă. If the assigned CLM is inactive, the higher CLM in the hierarchy is automatically taken over.

In this mode, the department manager option no longer appears in Organigrama.


Local accounts

Enable from Settings > Advanced Settings — allows adding accounts for employees without an email address.

The platform automatically generates addresses in the format:

{MARCA_ANGAJAT/NUME}@{ORGANIZATIE}.local

The user who sets up the account generates the access and receives the password. The employee can change the password and can later add a functional email address for notifications.


Communication language and bilingual documents

At employee level

Set the communication language from Details > Profile > Communication Language. The platform uses this setting for email notifications sent to the employee.

At organization level

Enable Bilingual Documents from Settings > Advanced Settings:

  • Training records, tests, and annual assessments are generated bilingually
  • The Instructions menus (SSM/PSI) allow uploading alternative documents in the selected language
  • Attached questionnaires are translated directly in the platform

Mandatory two-factor authentication (2FA)

From Settings > Advanced Settings you can require all users to have two-factor authentication (2FA) enabled in order to access the organization.

When the "Mandatory 2FA authentication for organization access" option is enabled, a user who does not have 2FA configured can no longer enter the organization: instead of the application, they are shown a page asking them to enable 2FA, with a button to account settings and a button to return to the organization list. After they enable 2FA (from My Account > Profile), access is unlocked automatically.

The restriction applies to all areas of the organization (Panel, Personal, Control, Signing).

Exceptions. The following accounts, which cannot use 2FA, are automatically exempted:

  • accounts that authenticate via SSO;
  • local accounts;
  • RFID accounts.

The setting can only be changed by the Super-User (the organization owner). To avoid locking themselves out, enabling the option is only allowed if the Super-User already has 2FA enabled on their own account; otherwise, the toggle displays a message and remains disabled.

The change is saved automatically.

The steps by which a user enables 2FA on their own account are described in Account security. On some dedicated installations 2FA may be unavailable; in that case the option does not appear in the interface.


Advanced employee import settings

Available under Settings → Options, in the Advanced employee import settings section. Editable exclusively by the Super-User.

Import modes

ModeDescription
Standard modeEmployee import works with the platform's default settings
Advanced modeAllows customizing import behavior from Excel files

Select the desired mode from the dropdown list — the change is saved automatically.

Advanced mode settings

When Advanced mode is selected, the following options appear:

Unique employee identification key

Defines the column in the import Excel file that will be used to uniquely identify an employee (to avoid duplicates and to update existing employees).

OptionDescription
EmailIdentifies employees by email address
Badge no.Identifies employees by internal badge number
CNPIdentifies employees by the personal numeric code

Department required

If set to Yes, the import file must contain the Department column for each employee. Rows without a department will be rejected on import.

Position required

If set to Yes, the import file must contain the Position column for each employee. Rows without a position will be rejected.

COR occupation required

If set to Yes, the import file must contain the Occupation column for each employee. Rows without an occupation will be rejected.

Automatically add departments

OptionDescription
YesIf the import file contains new departments (not existing in the platform), they will be created automatically
NoNew departments in the file will generate errors — they must be created manually in the platform before import

Automatically add positions

OptionDescription
YesNew positions in the file are created automatically
NoNew positions generate errors and must be created manually

All settings are saved automatically upon change. Changes take effect on the next import.


Email delivery error management

Delivery errors are notified to the super-user and can be viewed in Operations History.

Error typeDescriptionAction
SoftBounceMailbox full, temporary errorSending can be retried
HardBounceInvalid address or inactive accountThe address is blocked — it can be reactivated from Contact Details > Menu > Unblock address
SpamThe user marked it as spamPermanent block

STS signature provider configuration

Available for institutions and public authorities, after activation by ssm.ro technical support.

Configuration steps

  1. Generate a public/private key pair with OpenSSL:

    openssl genrsa -out private.pem 2048
    openssl rsa -in private.pem -pubout -out public.pem
  2. Go to Settings > Signature Providers > STS > Qualified Signature/Seal and copy the Redirect URI.

  3. Send the Redirect URI and the public.pem file to the STS provider.

  4. Enter the details received from the provider and the key from private.pem into the platform settings.


Installing the ssm.ro certificate in Acrobat Reader

To automatically verify signatures issued by the ssm.ro platform, add the public certificate to Acrobat Reader.

  1. Download the ssm.ro public certificate
  2. Open Acrobat Reader > Preferences > Signatures > Identities & Trusted Certificates
  3. Select Trusted Certificates > Import > Browse
  4. Select the downloaded certificate file
  5. Look for "Self Signed CA for platform SSM.ro"
  6. Check Use this certificate as trusted root and Certified documents
  7. Restart Acrobat Reader