IDP Support Center
  • Welcome
  • Getting started
    • What is IDP?
  • User Guide
    • User guide center
    • Get started with OXU
      • OXU Identity user guide
    • Account Management
      • Authentication
        • Sign up with Email and Password
        • Sign up with Google (optional)
        • Sign in with Email and Password
        • Google OIDC: Sign in to Google via OXU
        • Password requirements enforcement
        • Secure password hashing and storage
      • Account security
        • What should I do if I don't receive a verification code when signing up or forgot password?
        • Email verification
        • Two-Factor Authentication
          • Passkey authentication
          • 2FA-Email verification codes
          • MFA-Authenticator apps (TOTP)
          • MFA-Passkeys (FIDO2 / WebAuthn)
      • Data & Privacy
      • User Experience
        • Cross-platform web support
      • App Consent Management
    • Organization Admin App
      • Business Owner (Default Authority)
        • Organization Management
          • Organization creation
          • Domain ownership verification (DNS)
        • Organizational Structure
          • Organizational Units (OUs)
          • Workspaces
          • Hierarchical access scoping
        • Security & Governance
          • Enforced security policies
            • IP-Based access control
            • Geo-based access policies
            • Device and platform restrictions
          • Enforcing stronger authentication for risky login behavior
            • Risk Detection signals
            • Step-Up authentication
        • Roles & permissions
          • Assign role to user in Organization
          • Permissions list
      • SCIM – Automated user and workspace provisioning
        • What is SCIM used for?
        • User Lifecycle management
      • Administrator
        • Team & Access
          • Invite and manage users
          • Assign roles
          • Manage access at OU and Workspace level
            • Manage Access at Organizational Unit (OU)
            • Manage Workspace level
              • Team & Access – Members Management
        • Group management
        • Organization Unit
          • Create & manage Organization Units
          • Viewing and searching Organizational Units
          • Moving an Organizational Unit
          • Deleting an Organizational Unit
        • Manage activity logs of Organization's member
      • Become an OXU developer
      • App management - Workspace access
      • Report & Analytics Center
    • OXU Workspace
      • Guide to create workspace
      • Guide to manage workspace information
      • Guide to manage role and permissions
      • Applications
        • Guide to manage applications
        • OXU Developer
          • What is OXU developer
          • User guides
            • 1. Become OXU developer
            • 2. Create an app
            • 3. Input application info
              • About app ratings and reviews
            • 4. Config resource & security info
            • Security Best Practices
            • 5. Set up Pricing info
            • 6. Publish your app
              • Prepare before publishing your app
            • 7. Manage your app
              • App lifecycle
          • App versioning
        • OXU Store
          • What is OXU Store
          • 1. Register as an user
          • 2. Browsing & searching apps
          • 3. View app details
          • 4. Subscribe an app
            • Enable & Subscribe app for business workspace
          • 5. Manage subscriptions
          • 6. Rate & review an app
  • Support
    • Support center
      • What is Oten account & what can I do with Account Management App?
      • How to create account and password?
      • How to manage your Oten account information?
      • How to use MFA to protect your account?
      • What is WorkSpace & what can you do with WS?
      • What is Organization Admin app & what can you do with OAA?
    • Privacy Policy
    • Terms and conditions
      • Oten developer terms and conditions
      • Oten Store terms and conditions
    • FAQs
      • Store FAQs
      • Developer FAQ
    • Contact Us
  • Integration
    • Integration document
      • IDP integration
        • Environments: sandbox & production
        • Regular web application client
        • Native application client
        • Single page application client
        • SAML integration
        • Managing your integration applications
        • FAQ
      • What is SSO?
      • Why use SSO?
    • Provisioning connector
      • Google Workspace Configuration
    • Understand SSO flow
      • Overview
      • Flow Diagram
    • Developer Integration guide
      • Integration flow overview
    • Oten to OXU Migration guide
    • Prerequisites
      • Discovery Configuration
      • JAR Requirement - CRITICAL
      • JAR Complete Implementation Guide
      • PKCE Implementation Guide
        • Step 1: Choose OAuth Library
        • Step 2: Configure OAuth Client
        • Step 3: Implement Authorization Flow
        • Step 4: Handle Callback
        • Step 5: Token Management
      • Best practice
        • Security
      • Support & Troubleshoot
        • Common Errors
        • Debug and Troubleshooting
        • Contact Support
      • Appendix
        • Configuration Reference
        • Error Codes Reference
        • API Reference
        • Sample Code
        • Glossary
  • What's New
    • v1.0.29 - Aug 19, 2026
    • v1.0.28 - Aug 12, 2026
    • v1.0.27 - Aug 08, 2026
    • v1.0.26 - July 29 & 31, 2026
    • v1.0.25 - July 22, 2026
    • v1.0.24 - Jun 21, 2026
    • v1.0.23 - Jun 17, 2026
    • v1.0.22 - Jun 03, 2026
    • v1.0.21 - May 27, 2026
    • v1.0.20 - Apr 28, 2026
    • v1.0.19 - Apr 21, 2026
    • v1.0.18 - Apr 15, 2026
    • v1.0.17 - Apr 03, 2026
    • v1.0.16 - Mar 28, 2026
    • v1.0.15 - Mar 05 & 13, 2026
    • v1.0.14 - Feb 11, 2026
    • v1.0.13 - Jan 14, 2026
    • v1.0.12 - Jan 05, 2026
    • v1.0.11 - Jan 04, 2026
    • v1.0.10 - Dec 25, 2025
    • v1.0.9 - Dec 07, 2025
    • v1.0.8 - Nov 23, 2025
    • v1.0.7 - Nov 09, 2025
    • v1.0.6 - Oct 26, 2025
    • v1.0.5 - Sep 29, 2025
    • v1.0.4 - Sep 28, 2025
    • v1.0.3 - Sep 14, 2025
    • v1.0.2 - Aug 31, 2025
    • v1.0.1 - Aug 17, 2025
    • v1.0.0 - Aug 03, 2025
On this page
  1. User Guide
  2. Organization Admin App
  3. Business Owner (Default Authority)
  4. Roles & permissions

Permissions list

PreviousAssign role to user in OrganizationNextSCIM – Automated user and workspace provisioning

Last updated 7 months ago

1. Introduction

This document explains all system permissions within the Org Admin app (OAA). It is designed to help Administrators understand what actions each permission allows and how it affects the user interface (UI).

2. UI impact definitions

To understand how permissions work, it is important to distinguish between two main UI impacts:

  • Show:

    • Meaning: The UI element (such as a button, tab, or section) is only visible if the user has the required permission.

    • If permission is missing: The element is completely hidden from the UI.

  • Enable:

    • Meaning: The UI element is visible to all, but it only becomes interactive (clickable/editable) if the user has the appropriate permission.

    • If permission is missing: The element remains visible but disabled (e.g., grayed out).

3. Permissions by module

Here is a detailed list of permissions, grouped by functional module.

Module: Users

  • View internal list users & details: Allows viewing the account list and basic profile info (Tabs: General, Role, WorkSpace, Privacy).

  • Create account: Allows creating a new user with profile info and setting an initial password.

  • Edit account: Allows editing the user's General tab (e.g., name, email, phone number).

  • Lock/Unlock account: Allows temporarily disabling or re-enabling user login access.

  • Delete account: Allows permanently deleting a user account and removing all associated app/group assignments.

  • Export: Allows downloading the internal account list as a CSV file (no password or sensitive tokens included).

  • Reset password: Allows sending a reset password email or setting a new password manually for the user.

  • View Security: Allows viewing a user's security configuration (2FA/MFA status, trusted devices, session metadata).

  • Edit Security: Allows modifying user security settings (e.g., reset MFA, clear trusted devices, force logout).

  • Manage User role: Allows assigning or removing roles from individual users.

  • View Audit log: Allows viewing user activity history (logins, password changes, MFA resets, etc.).

  • View external list account: Allows viewing the list of invited guests and external users in the org.

  • Invite guest: Allows sending an invitation to an external user with temporary access.

  • Remove guest: Allows revoking an external user's access.

Module: Groups

  • View Group: Allows viewing the list of groups, group type, and number of members.

  • Create Group: Allows creating new groups, specifying type and membership rules.

  • Edit Group: Allows editing the group name, type, and membership configuration.

  • Delete Group: Allows permanently deleting a group.

  • Manage Group membership: Allows manually adding or removing user accounts to/from groups.

  • Manage Group role: Allows assigning or revoking roles applied at the group level (roles will apply to all members).

Module: Workspace management

  • View all workspaces: Allows viewing the list of all workspaces, their type, number of members, and status.

  • Create Workspace: Allows creating a new workspace. The creator is auto-assigned the "WS Admin" role for that workspace.

  • Manage Workspace: Grants full permissions to perform all management actions available in the WorkSpace App.

Module: Roles

  • View Role: Allows viewing the list of roles, their descriptions, and where they are currently assigned.

  • Create Role: Allows creating a custom role. (Note: Only Super Admin has this permission)

  • Edit Role: Allows editing a role's name, description, and its set of permissions.

  • Delete Role: Allows permanently deleting a role (only if not in use or system-protected)

Module: Applications

  • View Application: Allows viewing the list of registered applications and their status (enabled/disabled), type, and usage.

  • Manage Application: Allows creating new apps (e.g., SAML/OIDC), editing metadata (name, logo, redirect URL), or deleting them.

  • Configure App Availability: Allows controlling which workspaces are allowed to use each app.

Module: Profile

  • View Organization profile: Allows viewing organization info (name, logo, address, contact email, timezone, language).

  • Edit Organization profile: Allows editing the basic profile (name, logo, contact, default timezone/language, etc.).

Module: Domains

  • View Domain: Allows viewing all domains linked to the organization and their verification status.

  • Manage Domain: Allows adding new domains, updating records for verification, or removing domains.

Module: Security

  • View Security setting: Grants read-only access to all security configurations (2FA, password policy, session rules, etc.).

  • Manage MFA setting: Allows configuring 2FA enforcement and allowed methods.

  • Manage Password policy: Allows setting rules for password length, complexity, reuse, and expiration.

  • Manage Session policy: Allows defining max device limits, timeouts, and force logout rules.

  • Manage Location policy: Allows controlling allowed countries or IPs for login (Whitelisting).

Module: Org Unit

  • View Units: Allows viewing the OU tree structure and the detailed information for each OU.

  • Manage Org Units: Allows users to create new OUs, edit OU information (name, description), and change an OU's parent to move it in the tree.

  • Delete Unit: Allows deleting an OU from the system (requires handling members and child OUs before deletion).

The system includes the following default roles:

4. Predefined roles

  • Super Admin (Org Admin):

  • Group Manager:

  • Workspace Manager:

  • Help desk:

5. Default role assignment rules

  • Initial User setup: The first user who successfully registers an organization is automatically granted the Super Admin role.

  • Assigning Super Admin: Only users with the Super Admin role can assign this role to others.

  • Default invite assignment:

Description: Full access to all features.

  • Permissions: Full permission across all modules of the Org Admin app.

    • Description: Manage Groups.

    • Permissions: Full permission of module: Groups.

    • Permissions: Full permission of module: Workspace management.

    • Description: Limited support actions.

    • Permissions: View internal list account & details, Reset password , and Lock/Unlock accounts.

    • When an Org Admin invites a new member, the user will join with the Member role by default.

    • The Member role does not have access to the Org Admin app; they can only view their own profile.

    • The Admin can manually assign a different role during the invite flow if needed.