👥 The Users section
The Users section explains how to create, authenticate, invite, and manage people who access the Germain Workspace.
⚙️ GermainUX user-management overview
GermainUX supports several user-management models, allowing organizations to manage accounts directly in GermainUX or integrate with an existing enterprise identity provider.
🔑 User Authentication Options
|
Method |
Description |
Recommended Use |
|---|---|---|
|
Database/JDBC |
Authenticates GermainUX-managed users against a configured database. |
Organizations that want to manage Workspace accounts directly in GermainUX. |
|
LDAP |
Authenticates users through an LDAP directory and maps groups to GermainUX Roles. |
Organizations using a centralized LDAP directory. |
|
OAuth 2.0/OpenID Connect |
Authenticates users through an external identity provider. |
Organizations requiring enterprise single sign-on. |
|
Windows Active Directory |
Uses Active Directory users and groups for authentication and Role assignment. |
Organizations managing identities through Microsoft Active Directory. |
📋 User Administration
Go to:
Germain Workspace -> Left Menu -> Settings --> System -> Auth Settings -> Users
Depending on the configured authentication method, administrators can:
|
Action |
|---|
|
Review configured users |
|
Create GermainUX-managed accounts |
|
Assign Roles and Teams |
|
Send welcome emails |
|
Reset passwords |
|
Review pending access requests |
|
Approve or reject requested access |
|
Enable or disable users |
|
Remove users who no longer require access |
Users managed by LDAP, Active Directory, or an OAuth provider are generally created and maintained in the corresponding external identity system.
🛡️ Roles and Teams
Each GermainUX user can be assigned:
|
Access-Control Object |
Purpose |
|---|---|
|
Role |
Controls what the user is authorized to do in GermainUX. |
|
Team |
Controls which dashboards, data, and Session Replays the user can access. |
When authentication is provided through LDAP or OAuth, external groups can be mapped to corresponding GermainUX Roles.
📖 User Documentation
Select the guide that matches your user-management requirement:
|
Guide |
Description |
|---|---|
|
Configure JDBC authentication and create GermainUX-managed users. |
|
|
Configure LDAP authentication, directory searches, and group-to-Role mapping. |
|
|
Configure OAuth 2.0 or OpenID Connect authentication and enterprise SSO. |
|
|
Allow eligible users to securely reset a forgotten password. |
|
|
Allow prospective users to request access and administrators to approve, reject, and audit requests. |
|
|
Create and map Active Directory users and groups for GermainUX access. |
📋 Recommended Configuration Process
-
Select the authentication method approved by your organization.
-
Configure the corresponding authentication provider.
-
Create or synchronize the required users.
-
Assign the appropriate Roles and Teams.
-
Test authentication with a non-administrator account.
-
Verify that the user can access only the authorized features, dashboards, data, and Session Replays.
-
Periodically review accounts and remove access that is no longer required.
Service: Management
Feature Availability: 8.6.0 or later