Skip to main content

Configure Domain User Systems

Define the types of Domain Users and their permissions. Enable organisations to add their users and delegate chosen parts of responsibilities to other employees.


note

For more explanation on how to successfully model an ecosystem/federation to fully reflect its needs and requirements, see the Modeling Ecosystems article.

Prerequisites

Get an Access Token with the directory:website scope - if you want to create or manage types of technical users using Connect's APIs.

Add Domain User System

  1. Select Reference Data > Domain Users Settings > New Domain User System.

  2. Fill in the fields defining the domain user system and save.

    Field NameField descriptionExample
    System NameEnter the domain user system nameSandbox Users
    System DescriptionDescription of the domain user systemUsers Managing Sandbox Environment

Add Domain User Type

  1. From the list, select a user system and the + icon to add a domain user type.

  2. Fill in the fields defining the technical user type and select Next.

    Field NameField descriptionExample
    User Type NameName of the user typePrimary User
    User Type DescriptionDescription of the user typePrimary users manage sandbox environment
    Linked Parent RoleLinked parent role if availablen/a
  3. Enable/disable the Directory Access checkbox to control whether the user has access to directory resources.

    If disabled, no additional permissions are available for configuration.

    Adding users without the directory access can be used if you want to enable them to have access scopes for other platforms that leverage the directory's SSO functionality even though they may not have any direct function in the directory itself.

  4. Enable the checkboxes under to permissions you wish the user type to have.

    For reference, see the User Type Access Levels and Available User Type Permissions sections.

  5. Enable the Receive Email Notifications checkbox if needed.

    The Receive Email Notifications setting defines whether the user will receive email notifications about any update to organisation's resources and configuration, for example, when a new organisation administrator is added.

  6. Save.

User Type Access Levels

  • Admin level access - user has the ability to view and modify all resources available within the platform.
warning

When selecting an administrator-level permission, the user has the write access permission to all resources, not just those associated with their bound roles.

  • Write level access - grants the ability view and modify the selected resource

  • Read level access - grants the ability to view but not modify the selected resource

  • None - the user can neither view nor modify the selected resource

Available User Type Permissions

Available permissions:

  • Software Statements Access: Users can view and/or edit resources related to Applications and Assertion (SSA). For example, the user can register a new application and request a software statement assertion.

  • Domain User Access: Users can view and/or manage Platform Users within their organisation.

  • Organisation Certificates Access: Users can view and/or manage the certificates issued for their organisation including requesting new certificates.

  • Organisation Contacts Access: The users can view and/or edit their organisation's contact addresses.

  • Authorisation Server Access: The users can view and/or manage the authorisation servers registered for an organisation including publishing API resources within the platform.

Manage Domain User Systems Using APIs

Raidiam Connect allows organisations to integrate with the following APIs for Authorisation Domain User System and Type Management: