How to give a user access to more than one organization

Let someone work across several organizations, divisions, business units, or customer accounts from a single account. This covers the user record side; access inside each organization still comes from roles and groups there.

Before you begin

You need:

  1. The Account Admin role
  2. The organizations already created. See How to create an organization
  3. A decision on which organization is their primary, since that’s where they land at sign-in

Organizations are the outermost boundary in Datanyx. Users, roles, groups, and content all live inside one, and a user working in two organizations is effectively working in two separate worlds from the same account.

Adding an organization to a user’s record grants entry, not access. Three things stay organization-specific and none of them come with it:

  1. Groups are organization-scoped. Membership in one organization’s group doesn’t carry over. Someone who needs group-based access in both has to be added to a group in each.
  2. Roles are organization-scoped too. A role’s Organizational Access controls where it applies. A role that doesn’t cover the second organization grants nothing there.
  3. Filter parameters differ per organization. The same Report can return different rows depending on which organization the user is in, invisibly. This is by design, and it’s the most common source of confusion for people working across two.

There’s an administrative side effect worth knowing: an Account Admin can only reset the password of a user who shares an organization with them. Adding an organization to your own record is sometimes the quickest way to be able to support the people in it.

Steps

Step 1. Open User Management

From the main navigation, click Admin, then open the User Management tab.

Step 2. Find the user and open their profile

Search by user identifier or email address, then open Edit profile from their settings menu.

Step 3. Add the organizations

In List of Organizations, select every organization this person should be able to reach.

Step 4. Set the primary organization

Choose the Primary Organization: the one they land in at sign-in. Make this the organization they spend most of their time in. Someone who lands in the wrong place every morning and has to switch will eventually forget to, and then read the wrong numbers.

Step 5. Give them access inside each organization

Adding the organization isn’t enough on its own. In each one, confirm the user has a role whose Organizational Access covers it, and add them to any groups they need there. Without this they can enter the organization and find it empty.

Step 6. Save and check it from their side

Click Save, then have the user sign in and confirm they can reach both organizations and see what they should in each. Cross-organization access is the setup most likely to look correct in Admin and behave differently in practice.

Result

The user can work in every organization on their record, landing in the primary one at sign-in. What they see in each depends on the roles and groups they hold there, and on that organization’s filter parameters.

Common issues

  1. They can reach the second organization but it’s empty. Their roles don’t cover it. Check Organizational Access on each role they hold. A role scoped to one organization grants nothing in another.
  2. They’re in the group in one organization but not the other. Groups don’t span organizations. Add them to a group in each one separately.
  3. The same Report shows different numbers in each organization. Working as intended. Filter parameters are set per organization and applied invisibly. Compare the two organizations’ configuration parameters.
  4. They keep landing in the wrong organization. Change their primary organization on their profile.