⚠️ Role required: The features described in this guide require the Application Administrator role on one or more applications. If you do not have it, contact your Organisation Administrator.
Role Overview
As an Application Administrator, you manage the day-to-day usage of one or more specific applications within your organisation — who may use each application and how its licences are assigned. It is the customer-side, per-application counterpart to the Organisation Administrator, who administers the whole organisation.
The Licenses and Groups you see, and the licences and roles you can assign, are scoped to the application(s) you administer: you assign only the roles, licences and groups tied to those applications, and applications you do not administer are hidden.
What you can do
- Manage users — create, invite, edit and import (CSV) users, and manage their local login.
- Assign and revoke your application's licences to users and groups.
- Assign your application's roles through groups (the access a group grants inside the application).
- Track licence usage for your application.
What you cannot do
- Delete users — that is the Organisation Administrator's responsibility.
- Manage organisation-wide identity providers and IP access control.
- Activate or deactivate applications, provision environments, or size licence pools — those are Discngine-side actions (contact Discngine).
How you get this role
An Organisation Administrator grants the Application Administrator role from the Access Matrix, scoped to the application(s) you are responsible for. See Access Roles for the role and scope model.
Your main tasks
Assign licences for your application

Open Licenses, locate your application's licence, click Assign, and pick the users and/or groups to grant it to. For the full procedure (licence types, usage indicators), see How to Manage Licenses.
Manage access through groups
Use groups to give several users the same access to your application at once: a group carries your application's roles and licences, and its members inherit them. See How to Manage Groups.
Note: Application permissions are assigned to groups and licences, then synchronised to the identity system and carried in the user's token at sign-in. Some licences and roles are flagged default and are applied automatically on a user's first login — so a user may show no access until they have signed in once.
Support
For anything outside your scope — creating users, configuring SSO or IP access control, activating applications, or resizing licence pools — contact your Organisation Administrator or Discngine Support (support@discngine.com).
Related
- Organisation Administrator Guide
- Access Roles — the roles, sides and scope model
- How to Manage Licenses
- How to Manage Groups
- User Guide — the end-user experience