Types of User Administrator
Use
In delegated administration, we distinguish between overall user administrators and delegated user administrators:
-
Overall User Administrators can add, modify, and delete users of all companies. They can create delegated user administrators and assign them appropriate roles and permissions. In addition the following tasks can only be performed by an overall user administrator:
-
Group management
-
Role management with permissions to assign all roles to all users and groups
-
User mapping
-
Import and export of user data
-
User management engine (UME) configuration
-
Consistency check and repair tools
In the portal, overall user administrators are all administrators who are assigned to the Super Administration or User Administration role. In all other cases, overall user administrators must belong to a role to which the Manage_All action is assigned.
-
-
Delegated User Administrators can add, modify, and delete users that belong to the same company as the delegated user administrator. When they search for users, only users in their company are displayed. They cannot perform any actions involving groups.
Constraints
-
Each user can only belong to one company. This means that each delegated user administrator can only belong to one company as well, therefore he or she cannot administer more than one company.
-
It is not possible to have a hierarchy of companies. As a result, you cannot have a hierarchy of user administrators.