User management
An administrator role is required. For information, see User roles.
Note: Go to Settings > Tenant. The tenant and user details page opens. To return to the main menu, click
next to the Nintex logo.
In the User management page, you can:
- Configure single sign-on using SAML 2.0 protocol with SAML-supported identity providers. Example: Google Suite, Okta, Active Directory Federation Services and more.
- Add new users and assign roles. You can also edit and delete existing users from the tenant.
Jump to:
Access the User management page
-
Go to Settings > Tenant.
-
Click User management.
Create, edit, and manage user groups
Create new groups of users. Permissions of workflows and connections can be assigned to the created groups in order to share the workflows and connections with the members in the group.
-
Go to Settings > Tenant.
-
Click User management.
- Under the Groups section, click Add new. The Add new section is displayed with fields to create a new group.
- Type a Name for the group.
- Type a Description for the group.
- Select one or more owners from the Owner(s) drop-down list.
- Select the members you want to add to the group from the Member(s) drop-down list.
- Click Add. The group is created and displayed in the Groups section.
After the group is created, you can assign the permissions of workflows and connections to the group. For instructions, see Assign User and Owner permissions to connections and Workflow permissions.
-
Go to Settings > Tenant.
-
Click User management.
-
In the Groups section, on the right of the group you want to edit, click
and then select Edit. - Edit the fields as required and click Update.
-
Go to Settings > Tenant.
-
Click User management.
-
In the Groups section, open the Member(s) drop-down to view group members.
Add, edit, and remove tenant users
Note: Only users with email addresses from organization domain(s) can be added to your Nintex Workflow tenant.
-
Go to Settings > Tenant.
-
Click User management.
-
In the Users section, click Add user.
Additional fields appear.
- Type the Email address of the user you want to add to the tenant. The email address must match the organization domain(s). For example, if the domain configured is Nintex.com, the email address must be user@nintex.com.
-
Type the First name and Last name of the user.
- Select the role to assign to the user from the Roles drop-down.
-
Click Add.
The new user is added to the list of users on the page.
The added user receives an invitation email message to create a Nintex password. This password link expires in five days. If the link is expired, the added user can request a new link from Support or click Forgot password? on the login page and create a password through the reset password process.
-
Global administrators and Automation administrators cannot change their own user role.
-
Global administrator roles cannot be assigned to guest users.
-
Go to Settings > Tenant.
-
Click User management.
-
On the right of the row for the user you want to edit, click
and then select Edit. -
Select the role to assign to the user from the Role drop-down and then click Submit.
Important: When a user is deleted, the user's session will be terminated and any unsaved work will be lost.
-
Go to Settings > Tenant.
-
Click User management.
-
On the right of the row for the user you want to edit, click
and then select Delete.
User roles
Nintex Workflow users can be assigned one of the following user roles:
- Participant: Permissions to view and submit forms, and view and manage their tasks in Nintex Workflow tenant via the Nintex Mobile app and the My Nintex > Forms page. Tasks with authentication enabled will require assignees to have Participant access.
- Designer: Permissions to create and manage workflows and view tasks for the workflows they own. Includes permissions of the Participant role.
- Developer: Permissions to create and manage custom connectors, Xtensions and Form plugins. For instructions on creating custom connectors, and Xtensions see Nintex Xtensions SDK. For instructions on creating Form plugins see, Form plugins SDK. Includes permissions of the Designer role and Participant role.
- Automation administrator: Permissions to access all the Nintex Workflow tenant pages, which includes My Nintex, Workflows, and Settings. Automation administrators can override all tasks for all workflows. They can add users, but are not able to assign the Global administrator role. Automation administrators cannot configure Identity federation. Includes permissions of the Developer role, Designer role, and Participant role.
- Global administrator: All permissions in Nintex Workflow, including configuring Identity federation, and can assign Global administrator role to other users. Includes permissions of the Automation administrator role, Developer role, Designer role, and Participant role.
The Global administrator role is assigned automatically to the first person to request a Nintex Workflow tenant.
- Organization admin: Permissions to manage the organization portal, including identity federation (Single Sign On), domain management, and SCIM. Organization admins can view all users in the organization and manage organization settings but do not have access to tenant specific design or automation capabilities unless granted separately.
For information about workflow owner and business owner permissions for workflows, see Workflow permissions.
Permissions
The table below shows the permissions for each user role:
|
|
Participant |
Designer |
Developer |
Automation administrator |
Global administrator |
Organization admin |
|---|---|---|---|---|---|---|
|
Nintex Mobile app |
||||||
|
Complete tasks |
✔ |
✔ |
✔ |
✔ |
✔ |
N/A |
|
Submit forms |
✔ |
✔ |
✔ |
✔ |
✔ |
N/A |
| My Nintex | ||||||
| Complete tasks ** |
✔ |
✔ |
✔ |
✔ |
✔ |
N/A |
| Submit forms |
✔ |
✔ |
✔ |
✔ |
✔ |
N/A |
|
Workflows |
|
|
|
|
|
|
|
Create and modify workflows |
✘ |
✔ |
✔ |
✔ |
✔ |
N/A |
| Assign Workflow owner and Business owner permissions * | ✘ | With Workflow owner permissions : ✔ | With Workflow owner permissions : ✔ | ✔ | ✔ | N/A |
|
Create connections |
✘ |
Depends on Connection settings |
Depends on Connection settings |
✔ |
✔ |
N/A |
| Assign connection permissions | ✘ | Depends on Connection settings | Depends on Connection settings | ✔ | ✔ | N/A |
|
Access Xtensions framework |
✘ |
✘ |
✔ |
✔ |
✔ |
N/A |
| View workflow instances* | ✘ | ✔ | ✔ | ✔ | ✔ | N/A |
| View tasks* | ✘ | ✔ | ✔ | ✔ | ✔ | N/A |
| Override tasks | ✘ | ✘ | ✘ | ✔ | ✔ | N/A |
| Settings | ||||||
| Domain management | ✘ | ✘ | ✘ | ✘ | ✔ | ✔ |
| Configure identity federation | ✘ | ✘ | ✘ | ✘ | ✔ | ✔ |
| Add and manage users | ✘ | ✘ | ✘ | ✔ | ✔ | ✔ |
| Add and manage groups | ✘ | ✘ | ✘ | ✔ | ✔ | ✔ |
|
Assign Global administrator role to users |
✘ |
✘ |
✘ |
✘ |
✔ |
✔ |
| View and manage tokens | ✘ | ✘ | ✘ | ✔ | ✔ | ✔ |
| Assign Organization admin role to users | ✘ | ✘ | ✘ | ✘ | ✘ | ✔ |
*If the user has business owner permission for a workflow, they are able to view instance details and tasks for that workflow from Workflow tracking in My Nintex, despite their assigned role in User management. For information about applying permissions for workflows, see Workflow permissions.
**If the user has business owner permission for a workflow, they are able to delegate and override tasks depending on My Nintex Business owner settings.
|
Section |
Selection (or column or field) | Description |
|---|---|---|
|
Identity federation |
Configure |
Opens prompts in a new window for configuring identity federation to create a single sign-on experience. This selection is available only when no identity federation is configured yet. For the steps on configuring identity federation, see the following links: |
|
Provider |
The protocol or method which enabled single sign-on for your Nintex Workflow tenant:
For more information on SAML, see Frequently asked questions: Single Sign-on with SAML protocol. |
|
|
|
Domains |
The domains that are federated for single sign-on with the Nintex Workflow tenant. Example: YourDomain.com, YourCompany.com. |
|
|
Configured by |
Tenancy user name of person who configured the provider. |
|
|
Date configured |
Date and time on when the provider was configured. |
| Options ( |
Lists the following selections:
|
|
| Identity federation settings | Enable auto-acceleration |
This setting is enabled by default for new tenants.
|
| Send welcome email to new participant role users |
This setting is off by default. |
|
|
Users |
Add new |
Displays the Add user section with the following fields:
When you click Add, an invitation email message is sent to the new user to create a Nintex password. This password link expires in five days. If the link is expired, the added user can request a new link from Support or click Forgot password? on the login page and create a password through the reset password process. |
|
|
|
Email address of the user. |
|
|
First name |
First name of the user. |
|
|
Last name |
Last name of the user. |
|
|
Roles |
Roles assigned to the user: For more information about role permissions, see Permissions.
|
|
|
Options ( |
Lists the following selections:
|
| Groups | Add new |
Displays the Add new section with the following fields to enter details and create a new user group:
|
| Name | Name of the group. | |
| Description | Description of the group. | |
| Owner(s) | The owner or owners assigned for the group. Open the drop-down to see the names of the owners. | |
| Member(s) | The members assigned for the group. Open the drop-down to see the names of the members in the group. | |
| Options ( |
Opens a list with the following options:
|