IDP Support Center
  • Welcome
  • Getting started
    • What is IDP?
  • User Guide
    • User guide center
    • Get started with OXU
      • OXU Identity user guide
    • Account Management
      • Authentication
        • Sign up with Email and Password
        • Sign up with Google (optional)
        • Sign in with Email and Password
        • Google OIDC: Sign in to Google via OXU
        • Password requirements enforcement
        • Secure password hashing and storage
      • Account security
        • What should I do if I don't receive a verification code when signing up or forgot password?
        • Email verification
        • Two-Factor Authentication
          • Passkey authentication
          • 2FA-Email verification codes
          • MFA-Authenticator apps (TOTP)
          • MFA-Passkeys (FIDO2 / WebAuthn)
      • Data & Privacy
      • User Experience
        • Cross-platform web support
      • App Consent Management
    • Organization Admin App
      • Business Owner (Default Authority)
        • Organization Management
          • Organization creation
          • Domain ownership verification (DNS)
        • Organizational Structure
          • Organizational Units (OUs)
          • Workspaces
          • Hierarchical access scoping
        • Security & Governance
          • Enforced security policies
            • IP-Based access control
            • Geo-based access policies
            • Device and platform restrictions
          • Enforcing stronger authentication for risky login behavior
            • Risk Detection signals
            • Step-Up authentication
        • Roles & permissions
          • Assign role to user in Organization
          • Permissions list
      • SCIM – Automated user and workspace provisioning
        • What is SCIM used for?
        • User Lifecycle management
      • Administrator
        • Team & Access
          • Invite and manage users
          • Assign roles
          • Manage access at OU and Workspace level
            • Manage Access at Organizational Unit (OU)
            • Manage Workspace level
              • Team & Access – Members Management
        • Group management
        • Organization Unit
          • Create & manage Organization Units
          • Viewing and searching Organizational Units
          • Moving an Organizational Unit
          • Deleting an Organizational Unit
        • Manage activity logs of Organization's member
      • Become an OXU developer
      • App management - Workspace access
      • Report & Analytics Center
    • OXU Workspace
      • Guide to create workspace
      • Guide to manage workspace information
      • Guide to manage role and permissions
      • Applications
        • Guide to manage applications
        • OXU Developer
          • What is OXU developer
          • User guides
            • 1. Become OXU developer
            • 2. Create an app
            • 3. Input application info
              • About app ratings and reviews
            • 4. Config resource & security info
            • Security Best Practices
            • 5. Set up Pricing info
            • 6. Publish your app
              • Prepare before publishing your app
            • 7. Manage your app
              • App lifecycle
          • App versioning
        • OXU Store
          • What is OXU Store
          • 1. Register as an user
          • 2. Browsing & searching apps
          • 3. View app details
          • 4. Subscribe an app
            • Enable & Subscribe app for business workspace
          • 5. Manage subscriptions
          • 6. Rate & review an app
  • Support
    • Support center
      • What is Oten account & what can I do with Account Management App?
      • How to create account and password?
      • How to manage your Oten account information?
      • How to use MFA to protect your account?
      • What is WorkSpace & what can you do with WS?
      • What is Organization Admin app & what can you do with OAA?
    • Privacy Policy
    • Terms and conditions
      • Oten developer terms and conditions
      • Oten Store terms and conditions
    • FAQs
      • Store FAQs
      • Developer FAQ
    • Contact Us
  • Integration
    • Integration document
      • IDP integration
        • Environments: sandbox & production
        • Regular web application client
        • Native application client
        • Single page application client
        • SAML integration
        • Managing your integration applications
        • FAQ
      • What is SSO?
      • Why use SSO?
    • Provisioning connector
      • Google Workspace Configuration
    • Understand SSO flow
      • Overview
      • Flow Diagram
    • Developer Integration guide
      • Integration flow overview
    • Oten to OXU Migration guide
    • Prerequisites
      • Discovery Configuration
      • JAR Requirement - CRITICAL
      • JAR Complete Implementation Guide
      • PKCE Implementation Guide
        • Step 1: Choose OAuth Library
        • Step 2: Configure OAuth Client
        • Step 3: Implement Authorization Flow
        • Step 4: Handle Callback
        • Step 5: Token Management
      • Best practice
        • Security
      • Support & Troubleshoot
        • Common Errors
        • Debug and Troubleshooting
        • Contact Support
      • Appendix
        • Configuration Reference
        • Error Codes Reference
        • API Reference
        • Sample Code
        • Glossary
  • What's New
    • v1.0.29 - Aug 19, 2026
    • v1.0.28 - Aug 12, 2026
    • v1.0.27 - Aug 08, 2026
    • v1.0.26 - July 29 & 31, 2026
    • v1.0.25 - July 22, 2026
    • v1.0.24 - Jun 21, 2026
    • v1.0.23 - Jun 17, 2026
    • v1.0.22 - Jun 03, 2026
    • v1.0.21 - May 27, 2026
    • v1.0.20 - Apr 28, 2026
    • v1.0.19 - Apr 21, 2026
    • v1.0.18 - Apr 15, 2026
    • v1.0.17 - Apr 03, 2026
    • v1.0.16 - Mar 28, 2026
    • v1.0.15 - Mar 05 & 13, 2026
    • v1.0.14 - Feb 11, 2026
    • v1.0.13 - Jan 14, 2026
    • v1.0.12 - Jan 05, 2026
    • v1.0.11 - Jan 04, 2026
    • v1.0.10 - Dec 25, 2025
    • v1.0.9 - Dec 07, 2025
    • v1.0.8 - Nov 23, 2025
    • v1.0.7 - Nov 09, 2025
    • v1.0.6 - Oct 26, 2025
    • v1.0.5 - Sep 29, 2025
    • v1.0.4 - Sep 28, 2025
    • v1.0.3 - Sep 14, 2025
    • v1.0.2 - Aug 31, 2025
    • v1.0.1 - Aug 17, 2025
    • v1.0.0 - Aug 03, 2025
On this page
  1. User Guide
  2. Organization Admin App
  3. Administrator
  4. Team & Access
  5. Manage access at OU and Workspace level
  6. Manage Workspace level

Team & Access – Members Management

PreviousManage Workspace levelNextGroup management

Last updated 6 months ago

  • Scope
  • I am new. Where should I start?
  • Purpose
  • Prerequisites
  • I already understand. How do I proceed step by step?
  • Result

Scope

This document explains how Team & Access works at the Organizational Unit (OU) level, focusing on how Members, Groups, Roles, and Permissions are managed together to control access.


I am new. Where should I start?

Start by understanding the access model:

  • Members are individual users.

  • Groups are collections of members.

  • Roles define what actions are allowed.

  • Permissions are the smallest access units contained inside roles.

Best practice: assign permissions to roles, roles to groups, and users to groups.


Purpose

  • Manage who has access to an Organizational Unit

  • Control what users can see and do

  • Simplify access management using groups and roles

  • Ensure consistent and secure permission assignment


Before managing Team & Access, ensure that:

  • You have Admin or Access Management permission on the OU

  • The Organizational Unit already exists

  • Required roles are already defined (or default roles are available)


Navigate to Organization → Organizational Units and select the target OU.


From the OU details page, open the Team & Access section.

This section includes:

  • Members

  • Groups

  • Roles & Permissions


Members represent individual users within the OU.

You can:

  • View all members in the OU

  • Invite new members

  • Remove existing members

  • View assigned roles (direct or via group)


  1. Click Add Member

  2. Enter the user’s email

  3. Assign one or more groups

  4. (Optional) Assign a role directly

  5. Confirm the invitation

Note: Direct role assignment should be limited to special cases.


Groups help organize members and simplify permission management.

You can:

  • Create a new group

  • Add or remove members from a group

  • Assign roles to a group

Example groups:

  • QA Team

  • Backend Team

  • Security Admins

5.1 Add a Group to the Workspace

  1. Click + Add groups.

  2. Search and select a group by name or code

  3. Confirm to Assign the group.

Members of the added group will automatically gain access to the workspace.


5.2 View Group Members

This view is read-only and reflects members synced from the organization.


5.3 Manage Roles for a Group

  1. In the Groups list, open the Action (⋯) menu.

  2. Select Manage roles.

  3. Choose one or more roles from Select roles.

  4. Assigned roles define the permissions for all members of this group within the workspace.

Any role change applies immediately to all current and future group members.


5.4 Remove a Group from the Workspace

  1. Open the Action (⋯) menu of the group.

  2. Select Remove.

  3. Confirm the removal.

Warning:

  • Removing a group will revoke all roles and permissions granted through this workspace for its members.

  • The group itself is not deleted from the organization.


Roles

Roles are collections of permissions.

You can:

  • View predefined roles

  • Create custom roles (if supported)

  • Assign roles to groups or members

Permissions

Permissions define specific allowed actions, such as:

  • Read resources

  • Create or update data

  • Manage access settings

Permissions are not assigned directly to users — they are always part of a role.


After completing these steps:

  • Members have controlled access to the OU

  • Permissions are consistently applied through roles

  • Groups simplify onboarding and access updates

  • The OU follows security and access best practices

Prerequisites

I already understand. How do I proceed step by step?

1. Open Organizational Units

2. Open Team & Access

3. Manage Members

4. Add a Member

5. Manage Groups

  1. In the Groups list, click the Action (⋯) menu of a group.

  2. Select View members.

  3. A side panel opens showing:

6. Manage Roles & Permissions

Result

  • Member name

  • Email

  • Added date

  • Added by