Users
User management controls who can access AiX and provides the identity used to determine each user's access to platform capabilities and resources.
Depending on your organization's authentication configuration, users may be managed directly within AiX or provisioned through an external identity provider.
Administrators can use user management to review accounts, manage user status, and assign the appropriate roles, teams, and access permissions.
User Accounts
Each AiX user has an account that identifies the individual accessing the platform.
A user account may contain information such as:
- Username
- Display name
- Email address
- Authentication method
- Account status
- Assigned roles
- Team membership
- User profile information
- Last login information
The information available depends on your organization's configuration and authentication method.
Viewing Users
Administrators with the appropriate permissions can view users registered with AiX.
The user list may provide information such as:
- Username
- Name
- Authentication method
- Status
- Roles
- Last login
Use search and filtering options, where available, to locate a particular user or group of users.
Select a user to view additional account and access information.
Creating Users
How users are created depends on the authentication method configured for your AiX environment.
Locally Managed Users
Where local authentication is enabled, authorized administrators may create users directly within AiX.
Typical information may include:
- Username
- Display name
- Email address
- Authentication method
- Initial access settings
- Role assignments
- Team membership
Required fields may vary depending on your organization's configuration.
Enterprise Identity Users
Where AiX is integrated with an enterprise identity provider, users may be created or recognized through the organization's existing identity system.
Examples may include environments using:
- Microsoft Entra ID
- Active Directory
- LDAP
- OpenID Connect
- SAML
- Other supported identity providers
In these environments, identity information may be managed by the organization's identity provider rather than directly within AiX.
AiX maintains the information required to associate the authenticated identity with the appropriate AiX user and permissions.
Authentication Method
A user's authentication method determines how their identity is verified when accessing AiX.
Depending on your environment, authentication may be provided through:
Local Authentication The user's credentials are managed through AiX.
Single Sign-On (SSO) The user authenticates through an approved enterprise identity provider.
When SSO is used, password policies, Multi-Factor Authentication (MFA), account lockout, and other authentication controls may be managed by the external identity provider.
For detailed configuration information, see Authentication & SSO.
User Status
User accounts can have a status that determines whether the account can access AiX.
Common states may include:
Active The user is permitted to access AiX according to their assigned permissions.
Inactive or Disabled The account remains registered but cannot access the platform.
Disabling an account is generally preferred when access needs to be removed while retaining the user's historical activities and audit information.
Available status values may depend on your AiX version and configuration.
Roles and Permissions
Creating a user does not necessarily give that user access to every AiX capability.
Roles and permissions determine what the user is authorized to do after authentication.
Depending on their assigned permissions, a user may be able to:
- Use Chat
- Access Knowledge Bases
- Use Assistants
- Run Smartflows
- Create or modify resources
- Review or approve activities
- Manage other users
- Perform administrative functions
Administrators should assign only the access required for the user's responsibilities.
For detailed information, see Roles & Permissions.
Teams
Users can be assigned to teams to simplify collaboration and resource access.
For example, an organization might create teams for:
- Human Resources
- Finance
- Legal
- Operations
- Information Technology
- Project teams
Resources such as Knowledge Bases, Assistants, and Smartflows can then be shared with the appropriate teams rather than individually with each user.
A user may belong to more than one team where permitted.
For more information, see Teams.
User Profile
User profiles contain information associated with the user within AiX.
Depending on your organization's configuration, profile information may be used to support:
- Display information
- Organizational information
- Department or business unit
- Regional settings
- AI or processing preferences
- Resource access
- Processing or service routing
Some profile information may be maintained directly within AiX, while other information may originate from an enterprise identity provider.
Editing a User
Authorized administrators may modify user information that is managed by AiX.
Depending on the authentication method and permissions, editable information may include:
- Display information
- Account status
- Roles
- Team membership
- User profile settings
Information managed by an external identity provider may need to be changed in the source identity system rather than within AiX.
Disabling User Access
When a user should no longer access AiX, their account should be disabled according to your organization's access management procedures.
For example, access may need to be disabled when:
- An employee leaves the organization
- A contractor's engagement ends
- A user changes responsibilities
- Access is temporarily suspended
- An account is identified as no longer required
Disabling access preserves the relationship between the user and their previous platform activities.
Historical Smartflow executions, approvals, audit records, and other activities should remain attributable to the original user.
Deleting Users
Where user deletion is available, administrators should consider the impact on historical and audit information before permanently removing a user.
In many enterprise environments, disabling an account is preferable to deleting it because historical activities may need to remain associated with the original user.
Follow your organization's information retention and identity management policies when determining whether an account should be disabled or deleted.
User Lifecycle
A typical AiX user lifecycle is:
User Created or Provisioned
↓
Identity Authenticated
↓
Roles and Teams Assigned
↓
User Accesses AiX
↓
Access Changes as Responsibilities Change
↓
Account Disabled When Access Is No Longer Required
This lifecycle helps maintain controlled access while preserving accountability for activities performed within AiX.
Authentication and Authorization
Authentication and authorization serve different purposes.
Authentication answers:
Who is this user?
Authentication is performed by AiX or an approved identity provider.
Authorization answers:
What is this user allowed to do?
Authorization is controlled through AiX roles, permissions, teams, and resource access.
A successfully authenticated user does not automatically have access to every AiX capability or resource.
External Identity Management
When AiX is connected to an enterprise identity provider, the identity provider should normally remain the authoritative source for user identity.
For example, the identity provider may manage:
- Username
- Password
- Multi-Factor Authentication
- Account lockout
- Authentication policies
- Identity lifecycle
AiX manages the application-level information required to determine what the authenticated user can access and perform within the platform.
This separation allows organizations to continue using their established identity and security controls while managing AiX-specific authorization within AiX.
User Management Good Practices
Administrators should follow their organization's identity and access management policies when managing AiX users.
Recommended practices include:
- Create individual accounts for each user.
- Do not share user accounts.
- Use enterprise SSO where required by organizational policy.
- Apply the principle of least privilege.
- Use teams to simplify access management.
- Review user access periodically.
- Remove unnecessary roles and permissions.
- Disable accounts promptly when access is no longer required.
- Preserve user identity for historical and audit records.
- Review administrative privileges regularly.
Audit Information
User-related activities are recorded by AiX where applicable.
Audit information may include:
- User creation
- User changes
- Account status changes
- Authentication activities
- Role or permission changes
- Team membership changes
- Administrative actions
Audit records support operational investigation, security review, and organizational governance requirements.
For more information, see Audit & Activity and Security.
Related Documentation
Refer to the following sections for additional information:
- Roles & Permissions — Configure what users are authorized to do.
- Teams — Organize users and manage shared access.
- Authentication & SSO — Configure user authentication and enterprise identity integration.
- Resource Access — Control access to AiX resources.
- Audit & Activity — Review user and administrative activities.
- Security — Understand AiX security and access-control mechanisms.