Overview
Access in the Admin Center is granted through roles. Each role is given on a scope — your organisation and, where relevant, the application it applies to. This page explains the roles you can hold and manage within your organisation, and how they are granted.
These access roles control what a person may do inside the Admin Center (manage users, groups, licences, identity providers, and access). They are different from the application permissions carried inside each product: those are the application roles you assign through groups and licences, which are then synchronised to the sign-in system and included in a user's token when they log in to an application. See How to Manage Groups and How to Manage Licenses for those.
How scope works
When a role is granted, it applies to:
- Organisation — your organisation.
- Application — a specific application, or all applications.
Some roles cover your whole organisation; others are limited to a particular application.
The roles
Organisation Administrator
Administers your entire organisation. An Organisation Administrator can:
- manage users and groups,
- configure identity providers and IP access control,
- assign licences and application access,
- grant and revoke access roles for people in the organisation (via the Access Matrix, below).
This role always covers your whole organisation and all of its applications — its scope can't be narrowed.
Application Administrator
Manages the day-to-day usage of a specific application within your organisation:
- who has access to the application,
- how licences are assigned to users and groups.
It is scoped to your organisation and the application(s) it is granted on.
How access roles are granted — the Access Matrix
Access roles are granted and revoked from the Access Matrix. You choose a role, a scope (your organisation, and — for an application-scoped role — the application), and the people who should hold it. Changes are staged and then applied together.
Within your organisation, an Organisation Administrator can grant the two customer-side roles above (Organisation Administrator and Application Administrator). Discngine-side roles that operate the platform are managed by Discngine and are not granted from your organisation.
Summary
| Role | What it manages | Scope |
|---|---|---|
| Organisation Administrator | The whole organisation — users, groups, identity providers, IP access, licences, and access grants | Your organisation · all applications |
| Application Administrator | An application's user access and licence assignment | Your organisation · specific application(s) |
Related
- Roles and Permissions — a who-can-do-what matrix across the roles
- Organisation Administrator Guide — the day-to-day tasks these roles cover
- How to Manage Groups — how application permissions are assigned to users
- How to Manage Licenses — how licences (and their application roles) are allocated