Settings
Advanced platform settings for ssm.ro — workplace supervisor, local accounts, language, employee import, email and STS signature.
Workplace supervisor identification mode
There are two ways to assign the workplace supervisor (CLM) for each employee. In both cases, the CLM can only be chosen from contacts with the Employee role.
1. Through the company organizational chart
You create an organizational chart of departments and sub-departments. Each employee is part of a department, and the department head automatically becomes the CLM. If the direct CLM is suspended, the head of the higher-level department is automatically taken over as CLM.
The supervisor is assigned from Organigrama → click on the department → choose the department manager. See Department manager.
2. Through employee badge number and supervisor badge number
Each employee is given a unique badge number (Nr. Marcă) and a Supervisor Badge Number (Nr. Marcă Conducător). The values can be imported or entered manually, from Contacte → Detalii contact → Conducător Loc Muncă. If the assigned CLM is inactive, the higher CLM in the hierarchy is automatically taken over.
In this mode, the department manager option no longer appears in Organigrama.
Local accounts
Enable from Settings > Advanced Settings — allows adding accounts for employees without an email address.
The platform automatically generates addresses in the format:
{MARCA_ANGAJAT/NUME}@{ORGANIZATIE}.localThe user who sets up the account generates the access and receives the password. The employee can change the password and can later add a functional email address for notifications.
Communication language and bilingual documents
At employee level
Set the communication language from Details > Profile > Communication Language. The platform uses this setting for email notifications sent to the employee.
At organization level
Enable Bilingual Documents from Settings > Advanced Settings:
- Training records, tests, and annual assessments are generated bilingually
- The Instructions menus (SSM/PSI) allow uploading alternative documents in the selected language
- Attached questionnaires are translated directly in the platform
Mandatory two-factor authentication (2FA)
From Settings > Advanced Settings you can require all users to have two-factor authentication (2FA) enabled in order to access the organization.
When the "Mandatory 2FA authentication for organization access" option is enabled, a user who does not have 2FA configured can no longer enter the organization: instead of the application, they are shown a page asking them to enable 2FA, with a button to account settings and a button to return to the organization list. After they enable 2FA (from My Account > Profile), access is unlocked automatically.
The restriction applies to all areas of the organization (Panel, Personal, Control, Signing).
Exceptions. The following accounts, which cannot use 2FA, are automatically exempted:
- accounts that authenticate via SSO;
- local accounts;
- RFID accounts.
The setting can only be changed by the Super-User (the organization owner). To avoid locking themselves out, enabling the option is only allowed if the Super-User already has 2FA enabled on their own account; otherwise, the toggle displays a message and remains disabled.
The change is saved automatically.
The steps by which a user enables 2FA on their own account are described in Account security. On some dedicated installations 2FA may be unavailable; in that case the option does not appear in the interface.
Advanced employee import settings
Available under Settings → Options, in the Advanced employee import settings section. Editable exclusively by the Super-User.
Import modes
| Mode | Description |
|---|---|
| Standard mode | Employee import works with the platform's default settings |
| Advanced mode | Allows customizing import behavior from Excel files |
Select the desired mode from the dropdown list — the change is saved automatically.
Advanced mode settings
When Advanced mode is selected, the following options appear:
Unique employee identification key
Defines the column in the import Excel file that will be used to uniquely identify an employee (to avoid duplicates and to update existing employees).
| Option | Description |
|---|---|
| Identifies employees by email address | |
| Badge no. | Identifies employees by internal badge number |
| CNP | Identifies employees by the personal numeric code |
Department required
If set to Yes, the import file must contain the Department column for each employee. Rows without a department will be rejected on import.
Position required
If set to Yes, the import file must contain the Position column for each employee. Rows without a position will be rejected.
COR occupation required
If set to Yes, the import file must contain the Occupation column for each employee. Rows without an occupation will be rejected.
Automatically add departments
| Option | Description |
|---|---|
| Yes | If the import file contains new departments (not existing in the platform), they will be created automatically |
| No | New departments in the file will generate errors — they must be created manually in the platform before import |
Automatically add positions
| Option | Description |
|---|---|
| Yes | New positions in the file are created automatically |
| No | New positions generate errors and must be created manually |
All settings are saved automatically upon change. Changes take effect on the next import.
Email delivery error management
Delivery errors are notified to the super-user and can be viewed in Operations History.
| Error type | Description | Action |
|---|---|---|
| SoftBounce | Mailbox full, temporary error | Sending can be retried |
| HardBounce | Invalid address or inactive account | The address is blocked — it can be reactivated from Contact Details > Menu > Unblock address |
| Spam | The user marked it as spam | Permanent block |
STS signature provider configuration
Available for institutions and public authorities, after activation by ssm.ro technical support.
Configuration steps
-
Generate a public/private key pair with OpenSSL:
openssl genrsa -out private.pem 2048 openssl rsa -in private.pem -pubout -out public.pem -
Go to Settings > Signature Providers > STS > Qualified Signature/Seal and copy the Redirect URI.
-
Send the Redirect URI and the
public.pemfile to the STS provider. -
Enter the details received from the provider and the key from
private.peminto the platform settings.
Installing the ssm.ro certificate in Acrobat Reader
To automatically verify signatures issued by the ssm.ro platform, add the public certificate to Acrobat Reader.
- Download the ssm.ro public certificate
- Open Acrobat Reader > Preferences > Signatures > Identities & Trusted Certificates
- Select Trusted Certificates > Import > Browse
- Select the downloaded certificate file
- Look for "Self Signed CA for platform SSM.ro"
- Check Use this certificate as trusted root and Certified documents
- Restart Acrobat Reader