Manage roles with directory groups
Push groups from your directory and map them to workspace roles.
Last updated 11 days ago
Part of Set up automatic provisioning (SCIM).
Once your directory provisions your members, it can set their roles too. Push some of its groups to Tinct, map each one to a role, and the members of a group get that role. When someone moves to another team in your directory, their role in Tinct follows.
What you need
- Automatic provisioning set up and switched on. See Set up automatic provisioning (SCIM).
- You must be an admin of the workspace.
1. Push groups from your identity provider
Okta. Open your Tinct provisioning application (see Set up automatic provisioning (SCIM)), go to the Push Groups tab, click Push Groups, find the group by name and click Save. Push Groups must be among the provisioning actions enabled on the Provisioning tab. Okta advises against pushing a group that you also use to assign the application; create a separate group for the role if you need to.
Microsoft Entra ID. Assign the groups to your Tinct enterprise application, under Users and groups; the next provisioning cycle pushes them with their members. Assigning groups needs a Microsoft Entra ID P1 or P2 licence, and Entra does not provision the members of nested groups: assign the groups that hold the people directly.
The groups then appear on Settings → Security, in the Directory groups section of the Provisioning (SCIM) card, with their number of members. A group only counts members your directory manages: people on your verified domains.
2. Map a group to a role
In Directory groups, pick a role in the group's Role column: Viewer, Editor or Admin. Its members get the role at once, and your Settings → Members page shows it.
Choosing - removes the mapping: the group has no effect on roles any more.
Mapping a group to Admin
Everyone in an Admin group becomes an admin of the workspace, including whoever your directory adds to the group later. So Tinct asks first: the Map … to Admin? dialog names the group and its number of members. Click Map to Admin to confirm.
Which role a member gets
- In one mapped group: that group's role.
- In several mapped groups: the highest of their roles (Admin, then Editor, then Viewer).
- Leaving their last mapped group: the role of new members set on the Provisioning card of single sign-on.
- In no mapped group at all: the role they already have. Groups you have not mapped never change anybody's role.
Roles are recomputed each time your directory changes a group, and each time you change a mapping. A member your directory has deactivated gets the role of their groups when they come back.
Groups have no other effect in Tinct: they give access to nothing else. Deleting a group in your directory removes it and its mapping; its members' roles are recomputed as if they had left it.
A mapped role is set by the directory
While provisioning is on, the role of a member in a mapped group cannot be changed on Settings → Members: Change role is unavailable, with Role set by the directory group mapping. Change their groups in your directory, or the mapping on Settings → Security. Otherwise the next group change would silently undo your edit.
The role of members in no mapped group stays yours to change in Tinct.
The last admin
Your workspace always keeps at least one admin. A change that would leave it without one is refused as a whole, whether it comes from your directory (removing people from an Admin group) or from a mapping you change. Tinct says so, and nothing is changed. Make another member an admin, by hand or through an Admin group, and try again.
An invited admin who has not accepted yet does not count.
FAQ
Can a group make someone a super admin, or create a service account?
No. A group can only give one of the three workspace roles: Viewer, Editor or Admin.
Why does a member have a role their groups do not explain?
They are in no mapped group, so they kept the role they had, or the one given to them in Tinct. Map one of their groups, or change their role by hand.
We switched provisioning off. What happens to the roles?
Members keep the role they have. You change roles in Tinct again, for everyone.