The Users section

Prev Next
  • Applies to: All Board Cloud subscriptions

Introduction to the Users section

The Users section allows you to create and manage users on your Board Cloud platforms, import users from external files, export users to a CSV file, and set up the authentication data retrieval from Board to external applications and services. You can also configure automatic users synchronization between the Subscription Hub and individual Board Cloud platforms.

From the User section, you can assign roles and access permissions in a granular way for each Board Platform, diversifying the permissions at the level of individual user, or you can assign authorizations through a Permission Group. Thus, you can allow some users to develop and modify the structure of Capsules and Screens, while others can only consult and interact with data in Play mode.

The users list

In the Users home page, you can see all users of each platform and their main information: the table is sortable and searchable using the interactive header fields. You can also show or hide columns to your liking, by clicking the Column chooser button in the upper right corner of the table.

User account details including role, email, and account status information displayed in a table.

By default, you can view the following for each user:

  • Profile image

  • Name

  • Account name

  • Email address

  • License

  • Role for each associated platform

  • Platforms with granted access

  • Authentication method

  • Last time the user logged in

  • Account status (Active or Disabled)

  • Enrollment status (Completed, ImportedPending or New Request)

Enrollment Status

The enrollment status is marked as Completed in the following cases:

  1. The user's authentication type is "Board authentication" and his/her email address has been successfully validated.

  2. The user has successfully logged into Board through an enrollment process (with direct approval or with manual approval).

  3. The user account has been manually created by an administrator and the selected authentication type is an external identity provider (IDP).

The enrollment status is marked as Imported when the user has been imported from a newly associated platform or a CSV file, his/her authentication type is "Board authentication" and an administrator has not yet sent him/her the invitation email to continue the registration process.

The enrollment status is marked as Pending when the user's authentication type is "Board authentication" and his/her email address hasn't been successfully validated.

The enrollment status is marked as New Request when the user has completed the manual approval enrollment process and his/her account is still to be approved by an approver or an administrator.

Create a user

To create a user, follow these steps:

  1. Click on “+USER” in the top left corner.

  2. Fill out the following recommended account details:

    1. Account name

    2. Email

    3. Name

    4. Culture

  3. Give the user a license and an authentication type

  4. Set up the user’s platform authorization and whether they should have authorization to the Subscription Hub

  5. Configure the user’s collaboration permissions

  6. Save

Once you have created a new Board authenticated user account in the Subscription Hub, the user will receive an email and needs to verify the associated email address and set a password.

All the necessary instructions will be sent to the user through the email notification see Send / Resend Email below.

  • If an Enrollment process is in place, users will be able to register directly in Board or request access to Board right from the sign-in page. If the request is accepted, a new account will be automatically created.  See The Enrollment section for more information.

Manage Users

You can perform different actions on one or more user accounts by selecting them and by clicking on the different buttons above the users list, like delete, export, audit log, and sync to Data Model.

contents/assets/images/sub-hub-quick-users-23.png

  • You can modify multiple user accounts at once, by selecting the checkboxes at the beginning of each row. This option is available for Authentication type, License and Culture attributes, along with Office, Mobile and Disabled checkboxes. You can also bulk assign roles and licenses for each individual platform in the Platform authorization table (see View user details below).
    Please remember that the platform license count must be equal to or less than the main user license count for all selected users: the system only shows platform licenses that you can actually assign to selected users.
    By clicking on the "SAVE" button, all the changes will be applied to all selected user accounts: all unchanged information will be retained.

    • If you edit a user's Name field and that user is associated with one or more platforms affected by a Sync rule, the new value is automatically synced between the Subscription Hub and the associated Databases and Entities. User synchronization is also performed whenever you associate a user with one or more platforms affected by a Sync rule.

  • You can delete multiple user accounts at once, by selecting the checkboxes at the beginning of each row and by clicking the "DELETE" button: this button will appear when at least one row is selected.

    • If you delete one or more user accounts associated with one or more platforms affected by a Sync rule, the prefix "#del#" is added in the corresponding entity members' description to retain the historical data.

  • You can export multiple users at once, by selecting the checkboxes at the beginning of each row and by clicking the "EXPORT" button. See Export users for more details.

  • You can download an Audit log file which keeps track of events related to users accounts managed through Board's Subscription Hub of a customized date range by clicking the "AUDIT LOG" button. See Audit log for more details.

View user details

From the Users home page, click anywhere on the corresponding row to view that user details. A User profile panel on the right-hand side of the page will appear, showing the complete user information.

User profile panel in Board's Subscription Hub

Send / Resend Email

The SEND or RESEND button is available in the User profile panel if the user’s enrollment status is “Imported” or “Pending”.

If a user's enrollment status is marked as Imported and his/her authentication type is "Board authentication", you will see a "SEND EMAIL" button in the lower right corner of the User profile panel: click on it to send the user an invitation email to continue the registration process. If a user hasn't received the first invitation email, you can always send him/her another by clicking the "RESEND EMAIL" button in the lower right corner of his/her User profile panel. You can also bulk send invitation emails by clicking the "SEND EMAIL" button that appears in the upper left corner on the page when there are users with enrollment status marked as Imported.

Permission Group

The "Permission Group" dropdown menu allows you to manually assign a Permission Group to the user. See The Permission Groups section for more details.

Click the link icon contents/assets/images/link-out.png to open the Permission Groups home page.

contents/assets/images/perm group dropd.png

Licenses

The “Licenses” dropdown allows you to manually assign a license to a user. The amount of licenses you have and can assign depends on the individual client agreement.

Read more about the different permissions of each license.

The following checkboxes are available as add-ons to the user license:

  • Office. Check this box to grant access for the specific user to use the Board MS Office Add-in.

  • M365 Add-ins. Check this box to grant access for the specific user to use the Board for Microsoft 365 Add-ins.

    M365 Add-ins are included for Developer and Power User licenses and do not require this configuration.

    This license add-on is only available for Board versions 15 or newer.

    In addition to this license access, the user still must activate and deploy the add-in.

  • Mobile. Check this box to grant access for the specific user to use a mobile device.

Dropdown menu for selecting license type with options for Office and M365 Add-ins.

Sign in

The authentication dropdown allows you to assign a specific IDP for verifying the identity of the user before logging into Board. The "Board Authentication" authentication type is always available, while other external identity providers have to be configured in the Identity Provider Federation section.

Password never expires. Check if you want to override the default password expiration policy which is 365 days.
This option only applies to the "Board Authentication" authentication type.

Disabled. Check if you would like to disable the users ability to sign in. This action unassigns the current license, making it available to reassign to another user.

Board supports identity provider based on SAML2 and OIDC standards.

Sign-in interface showing authentication options and password settings for user accounts.

Subscription Hub authorizations

In the "Subscription Hub authorizations" table, you can manage authorization levels for each Administrator: you can grant or deny access to specific sections of the Subscription Hub to other Administrators, thus enforcing a deeper level of security and access control.

The amount of information displayed and the ability to edit it is defined by two authorization levels:

  • Edit. The user can access the corresponding sections and make changes.

  • Not authorized. The user cannot access the corresponding sections.

contents/assets/images/authorizations.png

To edit authorizations, click the downward-facing arrow at the end of each row and select the desired setting.

contents/assets/images/change-permissions.gif

The "ALL TO EDIT" button sets all authorizations to "Edit", while the "REMOVE ALL" button sets all authorizations to "Not authorized".

When a user has at least one authorization level set to "Edit", they are automatically considered to be a Subscription Hub Administrator, regardless of their Board license and Platform-specific permissions. Consequently, they will be eligible to become an approver in a manual approval enrollment process. When an Administrator logs into the Subscription Hub, the side menu and the administration tiles reflect their authorization settings; sections set to "Not authorized" will not be visible and will not be reachable, even using a direct URL.

Collaboration Groups

In the "Collaboration groups" table, you can review all User groups the user is a member of. Checked checkboxes in the "Feed author" column indicate in which groups the user has been granted the "News author" role. Two icons at the end of the row indicate which Collaboration feature is enabled for each group (Feed and/or Chat).

The Collaboration groups section displays which collaboration groups a user is assigned to. The table has the following table headers:

  • Group. Displays the Collaboration group names assigned to the user.

  • Feed author. Displays a checkbox where the user may be assigned as a Feed author.

  • Services. Displays the icons of the services enabled in the Collaboration group assigned to the user.

To add a user to a Collaboration group, select the button labeled "GROUPS" with the pencil icon within the user's profile whom you want to assign the group to and select all that apply from the list of options that appear in the table. Click the "DONE" button when you've finished editing and click "SAVE" in the bottom right corner of the page to update the user information.

Read more about Collaboration groups in the Collaboration feature.

contents/assets/images/collaboration-groups.png

The list of groups can be created and configured in the Collaboration services area accessed by the icon contents/assets/images/pop.out.view.png "Go to Groups" next to the Collaboration groups title.

Authorization hierarchy

The Authorization hierarchy section displays an overview of the user's authority access. This includes every instance for which a user has access to in terms of the role and license assigned to them. If the user has full access to every area of the instance, only the name of the environment will display. If the user has a Data model-specific Security profile or Folder security profile assigned to their role, a drop down appears underneath the instance name with the corresponding information for that security filter assigned role.

The dropdown displays the access the user has to Data Models, Cubes, Folder profiles, and Capsules. The following information can display in the Authorization hierarchy section of a user's profile:

Instance. The instance name that the user has access to will display in the Authorization hierarchy box with the following information:

  • Role. Displays the Role assigned to the user of the instance.

  • License. Displays the type of license the user has for the instance.

Data models. If a Data model-specific security profile is assigned to a user's role, the Data models in which a user has access to will display with the following information:

  • DB profile. Displays the name of the Data Model Security profile assigned to the user's role.

  • Permission. Displays the Security system Access level assigned to the Database security profile that is assigned to the user.

Cubes. If a Data model-specific security profile with a Cube visibility security filter is assigned to a user's role, the Cubes in which a user has access to will display with the following information:

  • Access mode. Displays the Cube visibility Access level of a Database security profile assigned to the user.

Folder profiles. If a Data model-specific Folder security profile is assigned to a user's role, the Capsule folders in which a user has access to will display with the following information:

  • Folder profile. Displays the Folder security profile assigned to the user.

Capsules

  • Permission. Displays the Access level configured in the Folder security profile assigned to the user (ReadOnly, PlayOnly, or Read & Write).

    contents/assets/images/authorization.hierarchy.png

Fields formats and information

Field name

Description

Examples

Account name

  • Function: used for logging into Board

  • Required value. Must be unique.

jbarry

Email

  • Function: used for receiving notification emails, screens and presentations a users has subscribed to.

  • Required value. Must be unique. String type field which accepts complete email addresses.

jbarry@acme.com

Name

  • Function: used in the user profile page within Board and in selected entities when a Sync rule is in place.

  • Optional value. Should be specified when a Sync rule is in place.

John Barry

Phone number

  • Function: displays the user's phone number in the user profile page within Board.

  • Optional.

111-111-1111

Culture

  • Function: applies a specific number, date and time format to the user's data visualization within Board. Leave it blank to apply the default date and time format.

  • Optional.

English (India)

[Custom fields] (User metadata section)

-

Permission Group

-

License

  • Function: defines the set of Board functionalities available for a single user account.

  • Required value. Must be one of the available options. The license is automatically applied as the main user license.

Developer

Office (Checkbox)

  • Function: allows the user to use the Board Office Add-in.

  • Optional.

-

M365 Add-ins (Checkbox)

  • Function: allows the user to use the Board for M365 Add-ins. This is only available from version 15 and newer.

  • Included in Developer and Power User licenses.

  • Optional for other licenses.

Gen AI (Checkbox)

  • Function: Allows the user to use the Board Gen AI agent

Mobile (Checkbox)

  • Allows the use of Board on a mobile device

  • Optional

Authentication type (Sign-in section)

  • Function: used for verifying the identity of the user before logging into Board.

  • Required value. Must be one of the available options.

  • The "Board Authentication" authentication type is available out of the box, while other external identity providers have to be configured in the Identity Provider Federation section.

  • Board supports identity provider based on SAML2 and OIDC standards.

Board Authentication

Password never expires (Checkbox)

  • Function: overrides the password expiration policy (default value: 365 days).
    This option only applies to the "Board Authentication" authentication type.

  • Optional.

-

Disabled (Checkbox)

  • Function: prevents the user to access Board with that particular account.
    When a user account is disabled, its license is immediately available to assign to other accounts.

-

Role (Platform authorization table)

  • Function: grants access to the corresponding platform and its resources (Capsules, Capsules Folders, Data models). Roles are configured in Board Platforms (the "Admin" role is available out of the box).

  • Optional value. Must be one of the available options.

Admin

License (Platform authorization table)

  • Function: grants access to the corresponding platform and locks/unlocks Board functionalities for the user.  It is always equal to or lower than the main user license.

  • Optional value. Must be one of the available options.

Power user

Admin (Platform authorization table - checkbox)

  • Function: grant the user administrator privileges for the corresponding Board platform.

  • The Admin checkbox is only available when a "Developer" platform license is selected.

-

Authorization (Subscription Hub authorizations table)

  • Function: grants the user administrator privileges for the corresponding Subscription Hub section.

  • Optional value. Must be one of the available options.

Edit

Feed author (Collaboration groups table - checkbox)

-