Skip to main content

How can I manage users in the Console?

Administrators of Appointedd can manage users in the Console based on the access configuration

Updated over 2 weeks ago

The General Rules

Rule 1: You can control other users, if you are Administrator level.

Rule 2: You can modify other users, if you have access to the same account as them.

Rule 3: You can delete other users, if you have access to the same account as them.

Rule 4: You can modify your own access, but changing your access level, means you cannot change it back to Administrator! Only Admins can make user changes (Rule 1).

Rule 5: You cannot delete your own access.

The Rules for SAML SSO specifically

The general rules still apply, but there's more to be considered when SAML SSO is enabled. There are two areas where SAML SSO connections take place:

  1. Organisations (accounts/stores) can have a SAML connection

  2. Users (managers/store teams) can have a SAML connection

SCENARIO 1: SAML configuration is set for all users to login via SAML SSO only.

A Store Manager with SAML SSO enabled can login via SAML SSO and see a list of their SAML connected stores.

If a new Appointedd store has been created without a SAML connection, the Store Manager will not have visibility of the store.

Fix: contact your Account Manager and make sure the new store has SAML connected.

SCENARIO 2: SAML configuration is set for users to login via SAML SSO and/or with email and password.

A Store Manager with SAML SSO enabled can login via SAML SSO and see a list of their SAML connected stores.

If a new Appointedd store has been created without a SAML connection, the Store Manager will not have visibility of the store, unless they switch to login via email and password.

Fix 1: contact your Account Manager and make sure the new store has SAML connected.

Fix 2: disable access via email and password for all users in the SAML configuration to force SAML SSO login only. This can only be controlled by the Super User.

Summary

All Administrators, whether SAML enabled or not, can view the list of users in the Console. They can add new users, but they can only amend and delete if they're part of the same account.

Example:

Non-SAML Admins cannot:

  1. Modify the permission level of a SAML user, only non-SAML users.

  2. Delete a SAML user, only a non-SAML user.

They will receive an error message when attempting to action such a change.

Questions:

Can SAML users control non-SAML users in the Console? (Not currently in the back office)

Did this answer your question?