Table Of Contents
Summary
Important: This feature is only available if you've configured SSO with Whistic-controlled roles. If you're using IDP-controlled roles, you'll need to manage permissions directly in your identity provider. Learn more about IDP-controlled role attributes.
This article explains how to set default permissions for new users who register with your company in Whistic. These default settings will automatically apply when new users are created, whether through SSO, invitations, or self-registration.
To modify permissions for users who already exist, go to Settings > User Management.
🪜 Steps to Access
- Login to Whistic (an admin will need to configure this setting)
- Click on Settings on the upper right corner
- Select Company Settings
- Scroll down on the Company Settings page and you will see the following below once SSO is required.
Please note, you will only see items 2 & 3 if 1 is set to Allow email address from these domains.
⚙️ Sign Up Approval Mode Options (#1)
There are 2 modes: Invitation Only and Allow email address from these domains
Invitation Only
- The admin permissions are automatically applied to new users coming in via SSO.
- This setting does not require any additional setup steps.
Allow email address from these domains
- An automated process that will auto-provision users based on the criteria you set up in #2 & #3 above. Enabling this setting will prompt the additional steps outlined below.
- This must be used with SSO and sign-in through SSO must be required.
- NOTE: If company email domain(s) aren't added prior to a user registering on Whistic, the default roles will not be properly assigned / user will be unmanaged. It's key to have this set up prior to any of your users accessing Whistic.
#2 Domains
You may add as many email domains as you would like here. Type in your email domain (@example.com) and hit the Enter/Return key.
#3 Default Privileges
Select default roles (as many as you need) and click Save. For more details on user privileges click HERE.