For the complete documentation index, see llms.txt. This page is also available as Markdown.

User Management & Access

Common questions about user provisioning, SSO, permissions, and access control in Harmony

How do I give users access to the self-service portal?

Users access the portal directly via your organization's portal URL.

  1. Add the portal URL as a bookmark app in your SSO provider (e.g., JumpCloud) and share it with the relevant users.

  2. Test access by provisioning a single user before rolling it out to everyone.

SSO access to the portal does not automatically grant access to the Harmony Dashboard. Dashboard access is controlled separately. Only users in the designated IT Admins group will have admin-level access.


Can SSO users be granted admin permissions for a specific desk?

Yes. Admin access can be scoped to a specific desk using SCIM and RBAC:

  • SCIM: Handles automated user provisioning and group membership sync from your identity provider.

  • RBAC (Role-Based Access Control): Assigns desk-level admin roles to synced users.

Contact your Harmony administrator to configure the appropriate SCIM group mappings and RBAC role assignments.


How does Harmony handle group membership visibility and permission conflicts?

Group membership visibility

Harmony syncs group members via SCIM. If members appear missing or undercounted in the UI, verify that your SCIM integration is active and that the count in Harmony matches your identity provider. If the issue persists, contact Harmony support.

Removing a role from a group

You can remove a role assignment from a group at any time. This gives you full control over access without deleting the group itself.

Permission conflicts for users in multiple groups

If a user belongs to more than one group, Harmony applies the highest permission level across all groups the user is a member of.


How do I configure IT approvers for an application?

  1. Navigate to Applications.

  2. Find the relevant application.

  3. Set the IT Approvers for that application.


Last updated

Was this helpful?