User Administration, Authentication, and Authorization
SAP Signavio Process Manager has its own user management.
Manage Users and Groups
User accounts are created by invitation: You invite users to your workspace by email, provide them with a license and access rights, and manage their accounts.
With JIT provisioning enabled, the following happens:
-
When a user logs in for the first time, a new account is automatically created.
In addition, SAP Signavio Process Manager and SAP Signavio Process Modeler users can invite internal and external process stakeholders to review and comment on diagrams. Internal users already have a SAP Signavio account. Externals need to create an account to log in.
With groups, you can effectively manage a large number of users and their access rights by creating a group for each organizational role and setting up a group hierarchy. This simplifies assigning access rights and feature sets to users.
To open the user management, select Workspace Settings in the side navigation of SAP Signavio Process Transformation Suite and open User management.
Users Invited for Feedback
Internal users
When users who already have an account and a license for this workspace are invited to review and comment on diagrams, they use their existing email address and password combination to log in.
Internal users are managed with the user management.
External Users
When external users are invited to comment on diagrams, they must create an account using the link in the invitation email. They can then sign in to SAP Signavio Process Collaboration Hub and view the diagram, for which they have received an invitation. Instead of a paid license, they are assigned a commenting license so that they can view and add comments.
The user accounts created in this way are like those created with the user management, but the following restrictions apply:
-
Users can't see any other diagram then the one they were invited to.
-
Users aren't assigned to any user group, not even the default groups.
-
Users can't access any other SAP Signavio component.
To revoke access, remove the account from the user management. When you just remove the licenses, external users can still sign in to SAP Signavio Process Collaboration Hub. They no longer see any diagram, instead they are informed that their trial has expired.
If needed, you can keep the account and manage it like any other account, for example assign more licenses and provide more access rights.
Users Invited to a Workspace
In the user management, you invite new users to your workspace. You also select the license type and the user groups you want to assign to the new user.
New users are automatically added to the user management once they have accepted the invitation and logged in to the workspace. You can then manage their access rights.
If users are not members of any group initially, they are able to read, write, delete, or publish in all folders and models in the Modeling Files folder.
If you want users to manage the workspace, you add them to the Administrators group.
Create Accounts
You have the following options to add users to your workspace:
-
Create accounts with bulk invites. The accounts are created when users log in for the first time. Only then can you change users' access rights.
-
Create user accounts instantly. With this option, you can change users' access rights immediately after you've created the accounts.
Every user you invite to your workspace has the following default permissions. Note that you can change these permissions by adding users to user groups.
-
Viewing and editing diagrams in the folder Modeling Files
-
Viewing and editing dictionary entries
You can change users' permission in Setup > Manage access rights in the explorer of SAP Signavio Process Manager or SAP Signavio Process Modeler.
Create Accounts with Bulk Invites
Follow these steps:
-
In SAP Signavio Process Transformation Suite, select Workspace Settings in the side navigation and open User management.
The user management opens.
-
In the sidebar, select Invites.
-
Paste the email addresses to the field. Email addresses must be separated by a whitespace.
-
Select a license from the drop-down list. Each user you invite will receive the selected license. You can assign additional licenses later.
-
Optionally, you can assign each user to a user group from the drop-down list.
-
Choose Send invites.
Email invitations with a link to the registration page are sent.
Create Multiple Accounts Instantly
Follow these steps:
-
In SAP Signavio Process Transformation Suite, select Workspace Settings in the side navigation and select User management.
The user management opens.
-
In the sidebar, select Invites.
-
Paste the email addresses to the field. Email addresses must be separated by a whitespace.
-
Select a license from the drop-down list. Each user you invite will receive the selected license. You can add additional licenses later.
-
Optionally, you can assign each user to a user group from the drop-down list.
-
Decide whether to send emails or not:
-
To send no invitation email to the users when you create their accounts, select Do not send invitation email. Users then only receive an email asking them to change their password.
-
To send no email at all, select Do not send change password email.
If service provider initiated authentication is enabled for the workspace, users are redirected to the identity provider, log in there, and enter the workspace. A SAP Signavio-specific password is not required.
When SP-initiated authentication isn't enabled, users must reset their password by using the I've forgotten my password link on the login page.
Read more in Single Sign-on Using SAML.
-
-
Choose Create users.
User accounts are created instantly. To change the users' permission, go to the Users tab.
Delete pending email invitation
Follow these steps:
-
In SAP Signavio Process Transformation Suite, select Workspace Settings in the side navigation and open User management.
The user management opens.
-
In the sidebar, select Invites.
-
Choose the user's email address.
-
On the right side, select Cancel. The link in the email invitation becomes invalid.
Resend email invitation
Follow these steps:
-
In SAP Signavio Process Transformation Suite, select Workspace Settings in the side navigation and open User management.
The user management opens.
-
In the sidebar, select Invites.
-
Choose the user's email address.
-
On the right side, select Resend. An email invitation is sent again.
Delete a User Account
To remove a user from a workspace, you delete their account.
When you delete an account, all content in the My Documents folder is deleted as well. The content the user created in the Modeling Files folder, their comments and changes, and the dictionary entries they created remain.
To remove a user, follow these steps:
-
In SAP Signavio Process Transformation Suite, select Workspace Settings in the side navigation and open User management.
The user management opens.
-
In the sidebar, select Users.
-
Choose the user you want to remove from the workspace.
-
In the right panel, select Delete. The user's account is deleted and the user can no longer log in.
Change User Settings
You can assign licenses to a user, assign users to groups, and reset the user's password. To do so, follow these steps:
-
In SAP Signavio Process Transformation Suite, select Workspace Settings in the side navigation and open User management.
The user management opens.
-
In the sidebar, select Users.
-
Choose the user whose settings you want to change.
-
On the right panel, you have the following options to change user's settings:
-
Licenses: Assign a license by selecting a license form the drop-down list.
-
Groups: Assign user to a group by selecting a group from the drop-down list.
-
Reset password: Send a password reset email. The link for resetting the password is only valid for 2 hours.
-
Remove user: Delete user account, see Deleting User Accounts.
-