Users
Users reach the Digital.ai Platform three ways: you create them by hand, your identity provider provisions them on first sign-in, or they self-register with an approved email domain. This topic covers creating and managing users, and points to the topic that owns each of the other paths.
Compare the Ways Users Are Added
| How the user is added | Who creates the account | Where the account lives | Default role | Use it for |
|---|---|---|---|---|
| You add a local user | An administrator | The Platform database | Whatever you assign | The first few administrators, before SSO is connected. See Add a Local User. |
| Your identity provider provisions the user | Nobody — it happens on the user's first sign-in | The Platform, populated from your identity provider | account-user, unless a role mapper says otherwise | Everyone in your organization. See Add Users from an Identity Provider. |
| The user self-registers | The user | The Platform database | account-user | Portal access before an administrator sets up the account. See User Self-Registration. |
Create only a few local users at first — enough to do administrative work — then connect your identity provider to onboard everyone else. Adding hundreds of users by hand isn't work you want to do twice.
User Roles
A user's role determines what they can do in the Platform. The Platform has five roles, from account-user for end users through account-admin for administrators who own the account.
For what each role grants and guidance on choosing between them, see User Roles and Permissions.
Add a Local User
Local users are stored directly in the Platform database and are not associated with any outside user management system.
- Log in to the Platform as an administrator.
- In the left navigation, under User Management, click Users.
- Click the Add User button.
- In User Information, enter the user's details (including the Username they'll use to log into the Platform).
- In Roles, choose a role to assign to the user.
- In User Groups, choose one or more user groups to assign to the user.
- Click Create user.
At this point, the user will receive an email notification that prompts them to create a password and log in.
You can return to the Users page at any time to view the list of all local users, edit users' details, delete users, or reset passwords.
Add Users from an Identity Provider
To learn how to connect the Platform to your existing identity provider, see SSO Configuration.
After you have connected the Platform to your corporate SSO, users are provisioned in the Platform when the user logs in for the first time through that identity provider.
User Self-Registration
Any user can create their own Digital.ai Identity without being provisioned by an administrator. This is especially useful for providing users with access to the Digital.ai community, support, and documentation portals before an administrator has had a chance to set up the account.
For more information, see User Self-Registration.
Merge Local and SSO Users
When an existing local user signs in through SSO with the same username, email address, or both, the Platform detects the conflict and offers to merge the two accounts into one. This also catches users who self-registered before you connected an identity provider.
Users complete the merge themselves, from a prompt at sign-in. For the full flow, the scenarios that trigger it, and troubleshooting, see User Merge Flow.
After the accounts are merged, the local user password is deleted, and that user can no longer sign in as a local user.
Related Tasks
- Group users so you can assign permissions in bulk. See User Groups.
- Reset a user's password, or let them reset their own. See Reset a User's Password.
- Restrict which networks can reach the Platform. See Manage IP Address Allow List.