User Management Deep Dive

Goal: Understand the complete user and access model.


Where Users Are Managed

LevelWhat's Managed
PlatformAccount creation, SSO
OrganizationCross-workspace policies
WorkspaceTeam membership, roles
SurfaceFine-grained access

Authentication

Users authenticate via:

MethodConfiguration
Email/PasswordDefault, Azure AD B2C
SSOSAML, OIDC (Enterprise)
SocialGoogle, Microsoft (if enabled)
Workspace management interface

Authorization Model

Workspace Level

  • Users get a role for the entire workspace
  • Role applies to all surfaces within

Surface Level (Optional)

  • Override workspace role for specific surfaces
  • Useful for external partners
  • More restrictive than workspace role

Private Cloud Deployment

When OpenIndustrial runs on your infrastructure:

AspectLocation
User accountsYour identity provider
Role assignmentsOpenIndustrial database (in your tenant)
Audit logsYour Azure storage

In private deployments, you control the identity layer. OpenIndustrial handles authorization.


SSO Integration

For enterprise SSO:

  1. Configure your IdP (Okta, Azure AD, etc.)
  2. Provide SAML metadata or OIDC endpoints
  3. Map IdP groups to OpenIndustrial roles
  4. Users sign in through your IdP
Thinking Tip:

SSO is available on Enterprise plans. Contact us to configure.


User Audit Trail

Every user action is logged:

  • Logins and logouts
  • Resource access
  • Modifications made
  • Role changes

Access audit logs via:

  • Workspace settings → Audit tab
  • API: GET /v1/audit/users

Compliance

RequirementHow Addressed
GDPRUser data export, deletion
SOC 2Audit logging, access controls
HIPAABAA available (Enterprise)

Next Steps

If you want to...Go to...
Manage API credentialsSecurity →
Understand workflowSave vs Commit →
On this page