Skip to main content
Regulaxy

Access management

Who may sign in, who gets administrator rights, and why an administrator defined here cannot be removed on the roles screen.

Access management decides two things only: who can sign in at all, and which of them are administrators. Everything else — what each of them may do once signed in — is decided in Roles and permissions.

The three fields

FieldWhat it doesEmpty means
AD group allowed to sign inOnly members of the group can sign inAny valid directory user can sign in
Admin AD groupMembers of the group get administrator rightsNo administrators through a group
Admins by idA comma-separated list of user ids that get administrator rightsNo administrators through a list

Changes take effect at each user's next sign-in. There is no local list to keep in step: group membership is checked against the directory itself.

The screen is for administrators

Both reading these settings and writing them are reserved for administrators. The access-management permission opens the row in the settings menu, but the values themselves will not load for anyone who is not an administrator.

Alongside the two routes in the table there is a single local administration account, fixed at deployment, which is always an administrator. Its name is shown at the top of the screen. It exists so that the directory being unreachable cannot leave the system with no administrator at all.

An administrator defined here is not removed on the roles screen

An administrator who got the role through the AD group or the id list appears on the Roles and permissions screen as a member of the administrator role — but the remove button is disabled and the reason sits beside it: their administrator rights do not come from a database row, they come from this screen.

That is deliberate. If removal appeared to succeed, it would delete a row that was never the source of the grant — and the user would still be an administrator, with nothing on screen saying so.

Updated

This page is the file content/docs/en/v1/admin/users-and-access.mdx