Manage users
Coherent's recommendation is to integrate Keycloak, our Identity and Access Management (IAM) with your Identity Provider (IdP). This provides the best security for user accounts. See Identity and Access Management and Benefits of IdP versus local accounts.
This functionality may be disabled if Single Sign-On is enabled.
User groups
Tenant administrators (tenant-admins) can create user groups, which act like teams where different users are grouped together if they perform similar actions. For example, the Product team can be a part of the same user group, responsible for adding and updating the Excel files on Spark. User groups can control access to Folders, if part of a Private tenant.
In a Shared tenant, where every user has access to all folders and services within a tenant, the relevant user groups are
tenant-adminanduser:pf.In a Private tenant where users have restricted access to folders and services:
The relevant user groups also include
supervisor:pfand any other user groups the administrators may want to create, such as regional or functional teams.User groups can also define permissions for Authorization - API keys.
Default user groups
supervisor:epos
This is only used by Coherent Flow tenants.
👮 supervisor:pf
This user group by default has access to all Folders and Services.
🌟 tenant-admin
Realm administrator that can manage User, Groups, Clients, Roles and Realm/Tenant.
In a Private tenant, tenant-admins cannot see all Folders and Services unless they added to the supervisor:pf group.
tenant-admins can also use APIs to access all objects within Spark.
tenant-moderator
Realm Moderator that can manage only User and Groups. This group can remain unused.
tenant-viewer
Realm Viewer it can only view Users and Groups. This group can remain unused.
user:anonymous
This is only used by Coherent Flow tenants.
user:coherent.forms
This is only used by Coherent Flow tenants.
user:epos
This is only used by Coherent Flow tenants.
⭐ user:pf
Access to this user group is mandatory for a user to login to Spark.
View user groups
Login using
tenant-admincredentials.Choose Options from the User menu.
In the left-hand navigation that appears, select User groups.
Click View users to see all the users who are members of each user group.
Add user groups
Newly created user group names should begin with the prefix user: or supervisor:, for example user:NewUserGroup.
supervisor users are able to manage the users for folders they have access to. When a folder is created, supervisor user groups are also assigned access by default.
Follow View user groups to arrive at the User groups screen.
Click on Add user group.
Enter the required information.
Existing Users on Spark can be added to the user group.
Click Submit to finish adding the user group.
Edit user groups
Follow View user groups to arrive at the User groups screen.
Click on the "three-dot menu" and select Edit user group.
A similar screen to View user groups appears.
Click Submit to finish making changes.
Delete user groups
Follow View user groups to arrive at the User groups screen.
Click on the "three-dot menu" and select Delete user group.
Any permissions related to the deleted user group will no longer apply.
Users
tenant-admins also have the ability to add users to their Spark environment. Users can be managed from the Users page inside Spark. Individual users added to Spark will then have the ability to log in and start creating APIs.
View users
Login using
tenant-admincredentials.Choose Options from the User menu.
In the left-hand navigation that appears, select Users.
In the three-dot menu for each user, click View users to see all the users who are members of each user group.
Add users
user:pf is a mandatory user group for users to login to Spark!
Follow View users to arrive at the Users screen.
Click on Add user.
Enter the required information.
Users can be added to the relevant user groups.
user:pfis required to access Spark!.Alternatively, user permissions can be copied from an existing user.
Users can also be setup to use Multi-Factor Authentication to login. See Multi-Factor Authentication (MFA) for more information.
There is an option to choose between sending the user an invitation link or generating a password.
Click Submit to finish adding the user.
Edit users
Follow View users to arrive at the Users screen.
Click on the "three-dot menu" and select Edit user.
A similar screen to Add users appears.
Click Submit to finish making changes.
Deactivate users
Users cannot be deleted from Spark in order to support internal audit and tracking of events in Spark.
Follow View users to arrive at the Users screen.
Click on the "three-dot menu" and select Deactivate user.
The user account will be deactivated and no longer able to access Spark.
Last updated
