Managing users
Users can access different resources in IBM RPA according to their roles. You can organize users assigning them to teams with different roles. There are separate permissions to the user access tools like IBM RPA Control Center, IBM RPA Studio, IBM RPA Vault, or IBM RPA Launcher. Learn more about how to create, view, edit, and delete users in IBM RPA.
About this task
This procedure shows how to create, view, edit, and remove a team. Move forward direct to the specific procedure:
- Procedure for creating user
- Procedure for creating multiple users at once
- Procedure for managing user's roles
- Procedure for managing user's teams
- Procedure for resetting user vault credentials
- Procedure for editing user's details
- Procedure for managing user's identity provider
- Procedure for deactivating an existing user
Important: Versions earlier than 21.0.2 of IBM RPA implement a method of managing users based on three basic roles: Super Admins, Admins, and Users. For more information, see Managing users (IBM RPA version 20.12). This content is no longer regularly updated.
Before you begin
The user must have Tenant Administrator role permissions. For more information about roles and permissions, see Planning your environment to manage users.
Procedure for creating user
Starting from IBM RPA on premises version 23.0.8, newly created tenants can use custom identity providers for SSO authentication. If a custom provider has been assigned to the tenant, you can assign it to new user accounts. For more information, see Identity providers.
Creating a user
- From the Access menu, click the Users tab.
- Click the Create user button.
- Select Manually add users.
- Click Next.
- On the Name field, enter the user name used to log in.
- On the Email address field, enter the user's email.
- On the Identity provider field, select the identity provider to be used by the user's account for this tenant.
- Click Next.
Assigning a user to roles
- On the Access pane from the Create user window, click Assign roles directly.
- Click Next.
- Select the roles that you want to assign to the user from the checkbox.
- Click Next.
- Review the summary from the user details and roles.
- Click Create.
You can see the permissions in a granular mode expanding each permission assigned to the roles.
Assigning a user to teams
-
On the Access pane from the Create user window, click Add to a team.
-
Click Next.
-
Select the teams you want to assign to the user from the checkbox.
If you haven't created any teams yet, click Create a new team button. For more information, see Managing teams.
-
Click Next.
-
Review the summary from the user details, teams, and roles.
-
Click Create.
Procedure for creating multiple users at once
- Click the Create user button.
- Select Bulk add users.
- Click Next.
- Click download our .csv template here link to download either one of the bulk user creation file templates.
- Follow the template to create users. See Bulk user creation example.
- Upload the bulk user spreadsheet.
- Click Create.
Bulk user creation example
To create multiple users at once, use the downloaded file template. Following is an example table:
name | password | |
---|---|---|
username1 | email@example.com | password@123 |
username2 | email2@example.com | password@1234 |
Procedure for managing user's roles
Viewing user's roles
- Click on the user you want to edit or view the data.
- Click the Roles tab.
Adding a new role
- On the Roles tab, click Manage roles.
- Select the roles you want to assign to the user from the checkbox.
- Select the confirmation checkbox.
- Click Save.
Removing user's roles
From the Roles tab, click the subtract icon on the role you want to remove. Your user must have at least one role assigned.
Procedure for managing user's teams
Viewing user's teams
- Click the user you want to edit or view the data.
- Click the Teams tab.
Adding a new team
- On the Teams tab, click Manage teams.
- Select the teams you want to assign to the user from the checkbox.
- Click Save.
Removing user's teams
- On the Teams tab, click Manage teams.
- Clear the teams you want to remove from the checkbox.
- Click Save.
Procedure for resetting user vault credentials
On the user you want to reset vault credentials, click the vertical ellipsis button ⋮ > Reset Vault Credentials.
Procedure for editing user's details
- From the Access menu, click the user you want to edit.
- Click the Details tab, click the pencil
icon.
- Optional: Enter a new user name.
- Optional: Select the language preference from the list.
- Click Save.
Procedure for managing user's identity provider
- Go to the Details tab of the user whose identity provider you want to change.
- In the Danger zone section, click Change.
- A confirmation prompt shows up, click Confirm.
Local Identity Provider means that the user's account requires username and password to log in instead of SSO (single-sign-on).
- Changing from the Local identity provider to Custom identity providers deletes the user's account password and retains the email for single sign-on (SSO).
- Changing from Custom identity providers to the Local identity provider prompts the user to create a new password for their account through an automatic email sent to the registered email.
- The Local Identity Provider is the only provider that can access V2 APIs.
Procedure for deactivating an existing user
On the Details tab from the Danger zone section, click Deactivate Then, click Deactivate again.
What to do next
The new user receives an email to confirm the account creation. If the user is using the Local Identity provider, remember to follow the password complexity policy. For more information, see Password complexity policy.