Apono Users Management
Manage Apono users: Admins, End-Users and Contractors
Apono Users Management
Intro
Apono is a just-in-time, on-demand, temporary access platform.
Apono currently supports 3 types of users:
Admin
End-user or Grantee
External requester
How to manage Apono Users
Admin
Your Apono account is managed by Admins. Admins can use the Apono web app or IAAC tools of choice to manage integrations, create and edit Access Flows, create and export audit logs reports, view and manage synced identities, and use the Access Graph for access visibility. They also manage Apono users.
Onboarding
New to Apono? Signup to create an account
Invite your teammates and colleagues from DevOps, DevSecOps, IAM, IT or Security as admins
Click your account icon
Go to Administration -> Users
Click "Invite User"
Insert Email, Role (pick "Admin"), Full Name and Phone Number (optional)
New admins will receive an email from Apono
Actions
Apono admins can perform the following actions:
View the dashboard
Create and edit Access Flows
Create Access Bundles
Create and manage integrations
View activity logs and create audit reports
View synced identities
Use the Access Graph for access visibility
Generate API tokens
Invite and delete users and change their roles
End-user (Grantee)
Apono integrates with your identity provider (IdP) to sync data on your users. Once synced, every IdP user can become an Apono requester.
Learn more about our IdP integrations here.
Onboarding and access requests
Onboarding end-users to create access requests with Apono is easy:
Integrate Apono with your IdP
Apono will sync users from your identity provider, along with their groups and manager data
Create an Access Flow for different users and groups
End-users need to install the Apono Slack App, Teams App or CLI
Once installed, users can use the Slack/Teams app or CLI to make access requests and get access details
You can also add Grantees to Apono without syncing your IdP:
Click your account icon
Go to Administration -> Users
Click "Invite User"
Insert Email, Role (pick "Grantee"), Full Name and Phone Number (optional)
New grantees will receive an email from Apono and can log in to the End User Portal.
Read more about the Apono developer web portal here.
Actions and permissions
End-users cannot visit the Apono web app or use IAAC manage integrations or Access Flows.
If end-users arrive to the Apono app by mistake, they will see the following message:
Working with external users
Every company depends on 3rd party users, like consultants, contractors, and other external users, who require access to company resources from time to time.
Apono lets you manage Just-in-Time access for these users:
Without an account in your IdP or cloud applications
Without an email in your domain
Without downloading any software or client
Without access to your communications workspaces, like Slack or Teams
How to use it?
Create a new Access Flow or edit an existing Access Flow
Instead of "When user requests access", pick "User opens access link"
When an external user requires access, they can visit a the access link and request the access as needed.
Last updated