Super Admin
By DataLexing Support
By DataLexing Support
How to Assign Super Admin
In DataLexing, only account owners or admins can assign the Super Admin role. Here's how you can assign a Super Admin role to someone on your account: What Does a Super Admin Do? A Super Admin has all the permissions of an admin but with extra capabilities, such as: - manage user - edit name and email - change user password - assign and revoke superadmin rights - deactivate - permanently delete user - delete workspaces - add sso providers - limit domains in emails that can sign up (e.g. allow sign up only those users that have datalexing.sa in their emails) - change settings - allow / restrict creating new accounts - allow / restrict resetting password - allow / restrict workspace creation - change number of days when userโs account will be deleted if he scheduled account deletion Make sure you assign this role only to trusted individuals since Super Admins have complete control over the account. Steps to Assign Super Admin Role in DataLexing: 1. Log into DataLexing: - Use your credentials to log into the DataLexing account. 2. Go to Admin Settings: - Click on your profile picture or initials in the bottom left corner of the screen to open the profile menu. - Select Admin Panel from the options to access the Admin Settings. 3. Manage Users: - In the Admin Settings, go to the Users section (usually on the left sidebar). - This will display a list of all users in your account. 4. Locate the User: - Find the user you want to assign the Super Admin role to. You can search for their name or email address if you have a large list of users. 5. Edit User Role: - Once you locate the user, click on the three dots (ellipsis) next to their name. - Select Edit from the dropdown. 6. Assign Super Admin: - In the role management options, select Super Admin. - After selecting the role, click Save to confirm the changes. 7. Notify the User: - The user will now have Super Admin privileges.
Authentication
Authentication Single Sign-On (SSO) enables users to log in once with a single set of credentials to access all corporate apps, websites, and data they have permissions for. DataLexing integrates with any third-party SSO provider using Security Assertion Markup Language (SAML) to control who can log in without requiring separate sign-ups for DataLexing. The Single Sign-On feature is part of the DataLexing Enterprise offering. Instance-wide features are only available on the self-hosted Enterprise plan. Only Instance admins have access to the DataLexing Admin panel, giving them admin access to the entire self-hosted instance. DataLexing users can use Single Sign-On (SSO) to maintain their user identities in a central location, allowing them to access many services using the same user base. Prerequisites To configure an authentication provider for single sign-on, users will generally need to: - Obtain the Client ID and Secret from their chosen provider and use them to create a new authentication provider in DataLexing. - Know the providerโs base URL for GitLab or OpenID Connect providers. - Set/allow the DataLexing Callback URL in the provider so users can be safely redirected back to DataLexing upon login. View a List of Authentication Providers To view the providers registered in your instance: 1. Visit your DataLexing server and log in as an instance-wide admin. 2. In the left menu, select "Admin." 3. Click the "Authentication" page. The Authentication providers pane will open and display a list of the providers in your server. Set up Google Provider Set up Microsoft Azure Provider SAML SSO Providers Security Assertion Markup Language (SAML) is a security standard for managing authentication and access. Using SAML SSO, users can log in to their DataLexing organization using the organizationโs identity provider.
Settings
Super Admins can manage two key aspects of their organizationโs DataLexing account on the Settings page of the Admin Panel: account restrictions and user deletion. Overview To access the Settings page, click on the Settings option in the Admin Panelโs tab. This will bring up a page with various settings options. Account Restrictions The "Account restrictions" section allows Super Admins to control who can access your organization. This setting can be adjusted by toggling the option on or off. - Allow creating new accounts: By default, any user visiting your DataLexing domain can sign up for a new account. Super Admins can disable this setting to prevent users from inviting non-users to sign up. - To disable sign-up on DataLexing: Admin โ Settings โ Allow creating new accounts โ Toggle off. - Allow signups via workspace invitations: If the "Allow creating new accounts" option is toggled off, an "Allow signups via workspace invitations" option will appear. Enabling this option means that only directly invited users can create an account. Only members with workspace admin roles can invite users. Even if new account creation is disabled, directly invited users can still create accounts. - Allow resetting passwords: By default, users can reset their passwords. This option lets Super Admins restrict users from requesting password reset links. Disabling this option risks locking out the Super Admin if they forget their password. - Allow everyone to create new workspaces: With this setting enabled, new users will automatically have a workspace created for them where they are Workspace Admins. To restrict this, disable the setting so that only Super Admins can create new workspaces. Newly invited users will start with the role they were invited with. User Deletion Grace Delay When an account is deleted in DataLexing, it remains in a retention period before permanent deletion. The default grace period is 30 days. Super Admins can adjust this period in the User deletion section. - Grace delay: This is the number of days without a login after which an account scheduled for deletion is permanently deleted.