Settings
Notifications, device, administrators, SMS/WhatsApp and license settings
- Notifications
- Device Settings
- Administrators
- Administrator Profiles
- SMS Settings
- WhatsApp Settings
- License Information
- Module Permissions
Notifications
Notification Settings determine which events the system notifies you about by SMS or email. Because a silent failure in the 5651 log-signing process creates legal exposure, we recommend keeping the signing and log-flow notifications switched on.
How do I open this screen? From the left menu, go to Settings → Notifications.
Note: the field labels on this screen are still shown in Turkish; the Turkish label is given in brackets so you can find each switch.
Notification types
There are eight separate switches; each can be turned on or off independently.
5651 signing
- 5651 signing SMS notification (5651 İmzalama Sms Bildirimi): sends an SMS to your mobile when the log-signing job completes — or fails.
- 5651 signing email notification (5651 İmzalama Mail Bildirimi): the same information by email.
Capacity warning
- SMS notification at 90% of 5651 capacity (5651 %90'a ulaşınca SMS Bildirimi): sends an SMS when the log storage to be signed reaches 90% of the allocated quota, so you can act before the space fills and logs are lost.
- Email notification at 90% of 5651 capacity (5651 %90'a ulaşınca Mail Bildirimi): the same warning by email.
Log flow
- Log flow SMS notification (Log Akış SMS Bildirimi): sends an SMS when the log stream from your firewall to Useroam stops. This is the first signal you get if the syslog configuration on the firewall breaks.
- Log flow email notification (Log Akış Mail Bildirimi): the same warning by email.
User events
- User approval email notification (Kullanıcı Onay Mail Bildirimi): sends an email when a user registration needs approval, reminding you to review Guests → Pending Approval.
- User registration email notification (Kullanıcı Kayıt Mail Bildirimi): sends an email whenever a new guest registers on the portal. We recommend leaving this off at busy locations.
Confirm your selection with Save.
Related pages: Analytics and Reports → 5651 Logs (signing status), Guests → Pending Approval, Settings → SMS Settings.
Device Settings
Device Settings manage the record of the firewall / gateway that Useroam talks to. The RADIUS secret, 5651 logging, the firewall API connection and the captive portal HTML template that must be uploaded to the device all live on this page. It is the panel-side centre of the installation.
How do I open this screen? From the left menu, go to Settings → Device Settings.
1. Device Details
- Device Address: the WAN / external IP address the firewall uses to communicate with Useroam. If you have several WAN interfaces the device usually sends from the first one; to use a different interface, define an SNAT rule on the firewall. If this address changes and you do not update it here, the integration stops.
- 5651 Logging (on screen: 5651 Loglama): enables signing and retention of the device's logs under Turkish Law No. 5651. Keep it on if you rely on legal logging.
- Device Name: the device's name inside the panel. Use something distinctive if you run several locations.
- Brand Name (shown to guests): this name replaces
|company|in campaign messages. If left empty, the account's registered legal name is used. GDPR/KVKK texts always show the legal name — this field does not change the legal text. - Device Password: the RADIUS shared secret. You copy this value into the firewall when defining the RADIUS server (Shared Secret on Sophos, Secret on FortiGate and Palo Alto).
Confirm your changes with the Save button below this section.
2. Firewall API Integration
This section connects the firewall management API for setup and guest session control. The panel auto-detects the device brand (for example Auto-detected brand: Sophos) and shows the matching Setup guide link.
- Enable API integration: switching this on reveals the fields below.
- Management address (https): the address of the firewall management interface.
- Port: the port of the management interface.
- Mode: one of two options:
- Setup only — credentials are not stored; the API is used during initial configuration only.
- Permanently connected — credentials are stored encrypted; operations such as signing sessions in and out run over the API continuously.
If you use Sophos: the API user and its permissions must also be created on the firewall. See Installation Guides → Sophos API Connection for the steps.
3. Template
This code block, starting with <html>, is the captive portal template that gets uploaded to the device. Theme changes you make in Portal Settings are reflected in it.
Copy the entire block and paste it into the matching field on your device:
- Sophos: Authentication → Web Authentication → Captive portal appearance → Custom HTML
- FortiGate: System → Replacement Messages → Login Page
- Palo Alto: save it as
captive.htmlfirst, then upload it via Device → Response Pages → Captive Portal Comfort Page
Other actions
- Setup Document: opens the installation guide for your device brand.
- Delete Device: removes the device record. The deleted device's RADIUS secret becomes invalid and guest logins stop — use it only when you are genuinely retiring the hardware.
Related pages: Installation Guides (brand-specific steps), Analytics and Reports → 5651 Logs, Settings → License Information.
Administrators
The Administrators page lists and manages the user accounts that can sign in to the panel. In hotels, this is also where you create separate accounts for reception, housekeeping or technical services.
How do I open this screen? From the left menu, go to Settings → Administrators.
List columns
- USERNAME: the account name used to sign in to the panel.
- FIRST NAME and LAST NAME: the account holder's name.
- E-MAIL: the account's email address. Notifications and password operations go to this address.
- LAST LOGIN: when the account last signed in (date and time). Use it to spot accounts that are no longer in use.
- LAST IP ADDRESS: the IP address of the last sign-in, so you can see whether anyone signed in from an unexpected location.
Security tip: disable accounts with an empty last-login date or months of inactivity. To track who did what, see Analytics and Reports → Audit Log.
Navigating the list
- The 10 / 25 / 50 / 100 / All selector at the top left sets how many records appear per page.
- The search box at the top right filters instantly across all columns.
- Below the table you find the total record count ("Total: 5 / 1 - 5") and the page navigation arrows.
New Administrator
Use the New Administrator button at the top right to create an account. The form asks for username, first name, last name, email and password. Which screens the account can reach is determined by its administrator profile — you create profiles under Settings → Administrator Profiles.
Related pages: Settings → Administrator Profiles (permission groups), Analytics and Reports → Audit Log (who did what).
Administrator Profiles
Administrator Profiles are the permission groups that determine which screens a panel account can see and which actions it can perform. You create a profile once and assign it to several administrators, so permissions are managed in one place rather than account by account.
How do I open this screen? From the left menu, go to Settings → Administrator Profiles.
Profile list
The table has two columns:
- #: the profile's row number.
- GROUP NAME: the name of the profile.
If no profile has been defined yet, the table shows "No Data". In that case administrators operate with the default permissions.
New Profile
Use the New Profile button at the top right to create a permission group. Give the profile a name and tick the menus and screens that group may reach.
Common examples:
- Reception: only the Hotel Solution (request monitor, room board) and the guest lists.
- Marketing: only Bumerang (campaigns, surveys, reports); system settings closed.
- Technical: Settings and 5651 logs; marketing modules closed.
Tip: start with the narrowest permissions and widen them as needed. Keeping screens such as Device Settings and License Information restricted to the technical team prevents accidental changes.
Related pages: Settings → Administrators (accounts), Analytics and Reports → Audit Log.
SMS Settings
SMS Settings define how the verification/password messages sent to guests are generated and which service delivers them. If you enabled the module on the SMS Portal Settings page, this page must also be filled in correctly before a guest can receive a code.
How do I open this screen? From the left menu, go to Settings → SMS Settings.
1. SMS API Settings
- Custom API (on screen: Özel API): turn on to use your own SMS integration. To send messages under the Useroam sender name, this option must stay off. In short: turn it on to send under your own brand header, leave it off to use the shared Useroam header.
Enabling the custom API reveals these fields:
- SMS Provider: Mobilişim (Ekomesaj) is a ready-made integration; choosing Other means you define every request parameter yourself.
- URL: the provider's send endpoint.
- HTTP Method: GET or POST — pick whichever the provider's documentation requires.
- Use country code: numbers are sent with the country code (e.g. 90) prefixed.
- Add leading zero: prefixes the number with
0. It is not used together with the country code — pick whichever format your provider expects. - Response value: the value the provider returns on a successful send. The system uses it to decide whether a message counts as delivered.
- Username, Password, Header: the account credentials and the SMS sender name (originator) used by the Mobilişim (Ekomesaj) integration.
Request parameters
This table, with Parameter and Parameter Value columns, is where you add the fields your provider expects. Use + to add a row and - to remove one. When the Other provider is selected, the request is built from this table.
SMS Test: the test dialog on the page shows the URL of the request that will be built. Use it to confirm the parameters combine correctly before contacting the provider.
2. Password (coupon) generation
- Character Length: how many characters the code sent to the guest has. Use the - and + buttons to adjust. A short code is easier to type; a long one is harder to guess.
- Character Type: Lowercase Letters Only, Uppercase Letters Only, Letters Only, Numbers Only or All. Since guests type it on a phone, Numbers Only is usually the most practical.
- Group: the user group that guests registering by SMS are added to. The group's quota, speed and duration rules apply to them. Groups are managed on the Guests → Groups page.
- If the user is registered, send a new password: when a previously registered number logs in again, a new password is generated and sent. If off, the guest continues with their existing password.
- Message to be Sent: the SMS text delivered to the guest. Keep the placeholder that carries the password in the text; otherwise the guest never sees the code.
Confirm your changes with Save.
Related pages: Captive Portal → SMS Portal Settings, Guests → Groups, Analytics and Reports → SMS / WhatsApp Reports.
WhatsApp Settings
WhatsApp Settings define the format of the password generated for the "Log in with WhatsApp" flow, the group the guest is added to, and the message text that is sent. If you enabled the module on the WhatsApp Portal page, this page must be configured as well.
How do I open this screen? From the left menu, go to Settings → WhatsApp Settings.
1. Password generation and guest placement
- Character Length: how many characters the generated password has; adjust with the - and + buttons.
- Character Type: Lowercase Letters Only, Uppercase Letters Only, Letters Only, Numbers Only or All.
- Group: the user group that guests registering over WhatsApp are added to. The group's quota and duration rules apply to them (Guests → Groups).
- If the user is registered, send a new password: generates a new password when an already-registered number logs in again.
- Message to be Sent: the text delivered to the guest over WhatsApp. Keep the password placeholder in the text.
2. Service / API settings
The advanced section defines the delivery service:
- Provider: Mobilişim (Ekomesaj) is a ready-made integration; choosing Other means defining the parameters yourself.
- URL and HTTP Method (GET / POST): the service endpoint and request type.
- Use country code / Add leading zero: number formatting. Choose only the one your service expects.
- Response value: the value the service is expected to return on a successful send.
- Username, Password, Header: the service account credentials.
- Request parameters: Parameter / Parameter Value rows, managed with + and -.
Confirm your changes with Save.
*.wa.me, *.whatsapp.com, *.whatsapp.net and others). Details are in the Installation Guides.Related pages: Captive Portal → WhatsApp Portal, Guests → Groups, Analytics and Reports → SMS / WhatsApp Reports.
License Information
License Information is a read-only screen showing your account's license status and the contact details of the dealer serving you. The values here cannot be edited; license renewals and scope changes go through your dealer.
How do I open this screen? From the left menu, go to Settings → License Information.
1. License Details
- Company Name: the business the license is registered to. This name appears as the legal entity in the KVKK/GDPR and terms-of-use texts.
- License Number: the license key unique to your account. Quoting it when you open a support request speeds things up.
- License End Date: the last date the license is valid. Once this date passes, guest logins and 5651 log signing stop — contact your dealer as the date approaches.
- Type: the scope of the license (for example 5651 Logging/Hotspot). The scope determines which modules you can use.
2. Dealer Information
- Dealer Name: the partner providing the license.
- Authorized Person: your contact on the dealer side.
- E-Mail: the dealer's contact address. Write here about renewals, scope extensions and billing.
For technical support: for installation and integration problems, write to destek@useroamteknoloji.com.
Related pages: Settings → Device Settings, Analytics and Reports → 5651 Logs.
Module Permissions
The Module Permissions screen does two jobs at once: it sets which modules are installed for your business, and it restricts which of them sub-users can see. What appears in the staff app is affected from here too.
How do I open this screen? In the left menu go to Bumerang → BUSINESS (İŞLETME) → Module Permissions (Modül İzinleri). To create users, use Settings → Administrators.
1. Business modules
The upper section shows which modules the business uses — Hotel Portal, Digital Menu, Event and so on. A module that is not installed reads Not installed · Install; the Install link adds it to the business.
What happens to a module that is switched off? It goes inactive both in the panel and app and on the customer-facing (public) side — so the guest-facing screens of a module you switch off stop working too.
2. Per-user restriction
The lower section lists the business's users, each row showing the name, username and last sign-in time.
The rule is simple: administrators and unrestricted users see everything. Tick Restrict by module for a user and pick modules, and that user only sees the pages and menus of the modules you selected.
Modules that can be restricted
- Campaigns (Bumerang)
- Online Menu
- Surveys
- Hotel Portal
- Restaurant Portal
- Events
- Store (Retail)
- Staff App
- Reports
- Advertisements
- Viewing guest data (unmasking): Allows masked personal data on guest records to be revealed. Because this is access to personal data, grant it only to those who need it.
Selections are written per user with Save.
Example: Give the user who runs the housekeeping team only Hotel Portal — no other module appears for them in the panel.
Related pages: Settings → Administrators, Administrator Profiles; Useroam Go → App Screens by Department.