Users
Each user in your organization, with a profile, a status, and a record of
how they were added.
Schema
The schema of built-in and custom fields that every user profile can hold.
Groups
Collections of users you assign access to as a unit (manual, built-in, or
auto.
Auto Groups
Groups whose membership is computed from an attribute and stays current on
its own.
Importing users
Bring users in, in bulk from a file, and review the results.
Directory Sync
Sync users from an HRIS or directory solution so the directory stays current
automatically.
Roles
The role each user holds, which governs what they can do in Iru.
What lives in the directory
- Users are everyone in your organization represented in the directory. Each has a profile, a sign-in identity, and a status that reflects where they are in their lifecycle.
- Profile attributes are the fields a profile can hold: built-in facets such as name, email, and phone, plus any custom attributes you define in your schema.
- Groups are collections of users. You assign access to a group once, and everyone in it inherits that access. See Groups.
How users get into the directory
There are three ways to add users, and you can mix them as your needs change.Add manually
Create a user by hand from Directory → Users. Best for a few users or a
quick test.
Import from a file
Upload a CSV to create many users at once. See
Importing users.
Sync from your HR system
Connect an HR system so users are created, updated, and removed
automatically on a schedule. See
Directory Sync.
The user lifecycle
People join, move, and leave your organization, and their directory record follows along through a small set of statuses.
Suspending is reversible; you can reinstate a suspended user, and they return
to the status they held before. Removing a user is permanent and is meant for
users who have left for good. The difference between suspending and removing,
and how to invite users to finish setting up their accounts, is covered in
Users.
Where the directory is used
The directory is the foundation the rest of Iru Identity stands on:- Applications grant access through assigned groups, and map profile attributes into the identity details each app receives. See Assigning access.
- Authentication policies evaluate the user signing in and decide what they must prove. See Authentication policies.
- Auto Groups read profile attributes to compute their membership automatically. See Auto Groups.
New to Iru Identity? Start with Key concepts
for the full set of objects, then follow the
Quickstart to stand up your first
sign-on.