[Developers]

User Management

Managing tens of thousands of users manually is not sustainable. The User Management module handles the full user lifecycle with automation where it helps most: provisioning that runs before a new hire's start date…

Category: ManagementLast Updated:
managementreal-timecompliance

Overview#

Managing tens of thousands of users manually is not sustainable. The User Management module handles the full user lifecycle with automation where it helps most: provisioning that runs before a new hire's start date, deprovisioning that triggers the moment an offboarding is recorded in your HRIS, and bulk operations for the department reorganisations that always seem to happen at the worst time.

Anomaly detection runs continuously in the background, flagging the access patterns that warrant a closer look before they become a security incident.

Key Features#

  • User Lifecycle Management: Complete CRUD operations covering single user creation with real-time validation, bulk import from CSV and Excel files, and automated provisioning through HRIS integration. Status management supports active, inactive, locked, suspended, and archived states with cascade effects including session revocation and token invalidation.

  • User Profile Management: Rich profiles with organisational hierarchy, custom attributes, and comprehensive metadata. Job-based and department-based templates accelerate profile creation while real-time validation maintains data quality. A self-service portal allows users to manage their own contact information, preferences, and security settings, with approval workflows for sensitive changes.

  • Bulk Operations: Mass user management for department reorganisations, location moves, manager updates, and status changes. Preview mode shows impact before applying; batch processing handles thousands of updates efficiently; rollback capability provides a safety net for large-scale changes.

  • Advanced Search: Find users across 20+ filter criteria including status, department, location, role, login history, MFA status, and custom attributes. A visual query builder supports complex nested conditions with AND/OR logic. Save and share search templates for common queries and subscribe to search results for change notifications.

  • Automated Workflows: Event-driven lifecycle automation for onboarding (account creation before start date, role assignment, training enrolment), offboarding (scheduled deactivation, ownership transfer, access revocation), and job changes (automatic role updates, department-specific access management). HRIS integration enables real-time or scheduled synchronisation.

  • User Analytics and Reporting: Dashboard views showing user counts, activity metrics, security posture, and compliance status. Pre-built reports cover access reviews, audit trails, and regulatory compliance. A custom report builder supports drag-and-drop field selection, aggregations, and scheduled delivery.

  • Anomaly Detection: Behavioural analysis identifies unusual login times, new locations, multiple failed attempts, concurrent sessions from different geographies, and sudden permission changes. Real-time alerts and daily digests keep security teams informed without overwhelming them.

  • Soft and Hard Delete: Soft delete preserves audit trails with configurable retention periods and undelete capability. Hard delete supports GDPR right-to-erasure with PII anonymisation while preserving audit logs. Bulk deletion requires safety limits and approval workflows to prevent accidental data loss.

Use Cases#

  • Law enforcement agencies automating the provisioning and deprovisioning of officer accounts across case management and evidence systems, with access tied to active assignment status.
  • Government departments managing access governance at scale with automated HRIS-driven lifecycle and quarterly access reviews that satisfy audit requirements.
  • Intelligence organisations monitoring access patterns through anomaly detection, where deviations from established baselines trigger immediate review.
  • Financial institutions meeting SOX requirements for access governance with complete audit trails, automated access reviews, and privileged access monitoring.
  • Healthcare providers automating clinician lifecycle so access to patient records is provisioned before the first shift and revoked the day an employee leaves.

Open Standards#

  • SCIM 2.0 (RFC 7643 / RFC 7644): The provisioning layer implements the System for Cross-domain Identity Management protocol to automate user and group lifecycle events (create, update, deprovision) with external HRIS systems and identity platforms.
  • SAML 2.0 (OASIS Security Assertion Markup Language): Federation with enterprise identity providers (Azure AD, Okta, Keycloak, and others) uses SAML 2.0 assertions for single sign-on, with entity metadata exchanged over the standard XML-based protocol.
  • OpenID Connect 1.0 / OAuth 2.0 (RFC 6749): Identity provider integrations listed in the module (Auth0, Zitadel, Google Workspace, and the OIDC provider class generally) rely on OpenID Connect for delegated authentication and OAuth 2.0 for authorisation token issuance.
  • FIDO2 / W3C Web Authentication (WebAuthn Level 3): Passwordless credential registration and management connects to a WebAuthn server using the W3C WebAuthn specification, enabling phishing-resistant hardware and platform authenticators for users.
  • JSON Web Token (RFC 7519): Access control decisions throughout user and admin operations are derived from JWT claims (organisation identifier, issuer, step-up proofs), with tokens validated at the API boundary.
  • OAuth 2.0 and JWT Bearer Token: Token-based authentication protects typed, auditable read and write workflows across the platform.
  • GDPR (Regulation (EU) 2016/679, Article 17): The hard-delete flow implements the right to erasure by anonymising personally identifiable information while preserving audit log integrity, in compliance with the EU General Data Protection Regulation.

Getting Started#

  1. Define User Schema: Configure custom attributes and profile templates that match your organisational structure.
  2. Set Up Integration: Connect your HRIS or identity provider for automated user synchronisation.
  3. Configure Workflows: Define onboarding, offboarding, and job change automation rules.
  4. Create Search Templates: Build saved searches for common administrative queries.
  5. Enable Monitoring: Activate anomaly detection, compliance reports, and activity dashboards.

Integration#

  • Identity Providers: LDAP/Active Directory, Azure AD, Okta, Auth0, Google Workspace, Zitadel, Keycloak, and SAML/OIDC providers
  • HRIS Systems: BambooHR, ADP Workforce Now, Rippling, Gusto, and custom integrations
  • Security Tools: SIEM systems for security event forwarding, PAM tools for privileged access monitoring

Last Reviewed: 2026-02-23 Last Updated: 2026-04-14

Ready to Integrate?

Access NATO STANAG gateway documentation or contact our defence integration team for support.