Assigning user permissions and roles via SCIM in Fluid

Modified on Fri, 12 Jul at 3:20 PM


Once you have configured SCIM identity synchronization, see Setup SCIM Identity Syncronization (Azure AD) you can optionally manage Fluid security roles and license types from AD. Users are assigned to specific groups in Active Directory which are in turn mapped to user roles or license types within Fluid.


If you decide not to do this, then user security roles / license types will need to be managed internally within Fluid via the User Administration console. 


The AD group name is the key used for Fluid role mapping, you need to create the AD group according to the list below, ensure the group name is exactly as defined. Users which are apart of the AD group, will be mapped and assigned to the corresponding security role / license type in Fluid.



TABLE OF CONTENTS


Security Roles


1. Create all the groups listed in the table in Active Directory.

  

Group in Active DirectoryRole in Fluid
Fluid Accountable ExecutiveAccountable Executive
Fluid Application administratorApplication administrator
Fluid Benefit accessBenefit access
Fluid Budget ApproverBudget Approver
Fluid Data AdministratorData Administrator
Fluid Financial accessFinancial access
Fluid Financial AdministratorFinancial Administrator
Fluid Project accessProject access
Fluid Project administratorProject administrator
Fluid Project submissionProject submission
Fluid Project ViewerProject Viewer
Fluid Resourcing accessResourcing access
Fluid Team managerTeam manager
Fluid Timesheet administratorTimesheet administrator
Fluid Timesheet ExemptTimesheet Exempt
Fluid UserUser
Fluid User AdministratorUser Administrator



For more information on the security user roles, see User Security Roles



2. Assign all the groups to the Enterprise Application.

3. To assign a user a role in Fluid, add them as a member to the appropriate group with in the Enterprise Application. You can also assign the user to a group for the license type that will be applied to the user.


  E.g.:
1. To provision a user with only the Fluid User role: add the user as a member of the "Fluid Users" group in Active Directory.

2. To provision the user with the Fluid Project Administrator role add the user as a member of the "Fluid Users" and the "Fluid Project Administrator" groups.





License Type


Users created in Fluid as part of SCIM are automatically assigned the "User" security role and "Licensed" license Type. If you optionally want to manage license type as part of your AD user onboarding, then you need to define the AD groups per the table below and assign the users accordingly. 


If you decide not to do this, then license types will need to be managed internally within Fluid via the User Administration console. 


below are the AD groups for license type. You will need to create the AD group as defined below.


1. Create all the groups listed in the table in Active Directory.


Group in Active DirectoryLicense Type
Fluid Licensed UserLicensed User - all roles are available.
Fluid Collaborator UserCollaborator License - locked to three roles: project access, timesheet exempt, user
Fluid Unlicensed UserUnlicensed User - disallow login remove the user role.



2. Assign all the groups to the Enterprise Application.

3. To assign a user a license type in Fluid, add them as a member to the appropriate group with in the Enterprise Application. 


Eg.

  • To provision a user with only the Collaborator License type: add the user as a member of the "Fluid Collaborator User" group in Active Directory.




Further Reading





Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article