User Provisioning
User Guide — Giving People the Right Access to a Data Domain
| Last updated: September 2026
Contents
- Overview
- Key Concept: Roles, Approvers, and Requests
- Finding Your Way Around
- Define Role — Deciding What Access Exists
- User Management — Approving and Managing People
- The User Status Lifecycle
- Adding Users to a Domain
- Quick Reference
1. Overview
User Provisioning is where you control who can work in a data domain and what they're allowed to do there. It's the place to set up the roles a domain offers, decide who signs off on access, and then approve, manage, and remove the people who ask for it.
Access in OnCoor is granted per data domain, so what you set up here applies to the domain you're currently working in. Another domain has its own roles and its own users.
What you can do here
- Define the roles available in a domain, and choose who approves each one.
- Review the people who have asked to join the domain.
- Approve or deny their requests — one at a time or in bulk.
- Keep access tidy — re-send an invitation that has expired, or remove someone who no longer needs access.
- Add people to the domain — one at a time, or many at once through a batch upload.
WHERE TO FIND IT — User Provisioning is under Process Management → User Provisioning, and is split into three areas: Define Role, User Management, and Batch Uploads.
2. Key Concept: Roles, Approvers, and Requests
Three ideas work together here:
- A Role is a named set of permissions — what a person can see and do. A role only becomes available in a domain once you add it on the Define Role screen.
- An Approver is the person responsible for saying yes or no to requests for a particular role. Every role you add is given an approver.
- A Request is what's created when someone asks to join the domain (or is added to it). It waits until its approver deals with it.
So the flow is: you make a role available and give it an approver; a person's request for that role then appears in User Management, where the approver approves or denies it. Only after approval does the person actually get access.
Rule of thumb: set up your roles on the Define Role screen first — until a role exists with an approver, nobody can be approved into it.
3. Finding Your Way Around
Go to Process Management → User Provisioning. The module has three areas:
| Area | What it's for |
|---|---|
| Define Role | Define which roles the domain offers and who approves each (section 4). |
| User Management | Review, approve, deny, and manage the people in the domain (section 5). |
| Batch Uploads | A record of the bulk user uploads made to the domain (section 7). |
A sensible order is to set up Define Role first, then work in User Management as requests come in, using Batch Uploads whenever you need to bring in a group of people together.
4. Define Role — Deciding What Access Exists
The Define Role screen lists the roles available in the current domain. Each row is one role, with the person who approves requests for it.
Adding a role
- Click the Add button (the floating +).
- Choose the Role you want to make available.
- Choose the Approver who will handle requests for it.
- Save. The role appears in the list, ready to be requested.
What each column shows
| Column | What it means |
|---|---|
| Active | Whether the role is currently on offer. Untick it to stop new requests for the role without removing it. |
| Role | The role being offered in this domain. |
| Approver | The person who approves or denies requests for this role. |
| Updated By / Updated Date | Who last changed the row, and when. |
| Created By / Created Date | Who added the role, and when. |
You can change the Active, Role, and Approver values right in the row, and remove a role with the Delete icon in its Action column.
NO ROLE, NO ACCESS — A role has to be added here, marked Active, and given an Approver before anyone can be approved into it. If people can't request the access they expect, this is the first screen to check.
5. User Management — Approving and Managing People
The User Management screen lists the people in the domain and where each one stands. Use the search bar at the top to narrow the list.
What each column shows
| Column | What it means |
|---|---|
| Batch Name | The upload batch a person came in on, if they were added as part of a group. |
| User Email | The person's email address. |
| Status | Where their request stands — see section 6. |
| Remaining Time | For someone who's been invited but hasn't finished signing up, how long is left before the invitation expires. |
| User Roles | The role(s) the person is requesting or holds. |
| Updated By / Date, Created By / Date | Who last changed the record and who created it, with dates. |
The actions you'll see depend on a person's status, and appear in the Actions column:
| Action | When it appears | What it does |
|---|---|---|
| Info | Submitted, Account Created, or Rejected | Opens the person's details. |
| Approve | Submitted (and you are the approver) | Grants the request — the account is created. |
| Deny | Submitted (and you are the approver) | Rejects the request. |
| Re-send | Expired | Sends a fresh invitation so the person can finish signing up. |
| Delete | Expired | Removes the person's record from the domain. |
YOU ONLY APPROVE WHAT'S YOURS — The Approve and Deny actions show up only on requests for roles where you are the named approver. If you can't act on a request, it belongs to a different approver.
Approving or denying several at once
Tick the requests you want (only those waiting on you can be selected), then use the Approve or Deny action that appears above the list to handle them all together — handy after a batch upload.
6. The User Status Lifecycle
The Status column tells you exactly where each person is:
| Status | What it means | What to do |
|---|---|---|
| Submitted | The request is waiting for its approver. | The approver clicks Approve or Deny. |
| Account Created | The request was approved and the account now exists. | Nothing — the person has access. |
| Rejected | The request was denied. | Nothing, unless they should re-apply. |
| Expired | An invitation ran out before it was completed. | Re-send the invitation, or Delete the record. |
The usual path is Submitted → Account Created. A denied request becomes Rejected, and an invitation that isn't completed in time becomes Expired — where Remaining Time hits zero — which you can revive with Re-send.
WATCH REMAINING TIME — An invited person needs to finish signing up before their Remaining Time runs out. Once it does, their status turns to Expired and they'll need a fresh invitation via Re-send.
7. Adding Users to a Domain
People appear in User Management because they've been added to the domain — either one at a time or as a batch. Once added, they flow into User Provisioning for you to review and approve.
Adding a single user
There are two ways to add one person.
Create a brand-new user — for someone who doesn't have an OnCoor account yet. Click the Add button (the +) on the Users list to open the user form, then fill it in:
| Field | Notes |
|---|---|
| First Name | Required. |
| Middle Name / Last Name | Optional. |
| Email Address | Required, and must be a valid email. |
| Password / Confirm Password | Required; the two must match. |
| Default Domain | Required — the domain the user starts in. |
| Is Account Locked | Leave No unless you want the account blocked from the start. |
| Is Security Admin | Whether the user gets security-admin rights. Defaults to No. |
| Reset Password on Next Login | On by default, so the person sets their own password the first time they sign in. |
A password must be 8–128 characters and include uppercase letters, lowercase letters, numbers, and special characters. Click Save to create the user.
Add an existing user to the domain — for someone who already has an OnCoor account. Click Add Existing User to Domain, pick the person from the list (only users not already in this domain appear), and click Save.
Uploading a batch of users
To bring in many people at once, upload a list of their email addresses from the Batch Uploads tab.
- On the Batch Uploads tab, click Batch Add. The Upload User Data window opens.
- Click Choose a file and pick an Excel file (.xlsx or .xls). The first sheet must have a column headed exactly UserEmail, with one address per row.
- The selected file name appears. Click Upload.
- OnCoor checks every address and opens the Batch Details window, listing each one with whether it's Valid and, if not, the Reason — for example Invalid email format or Duplicate entry in file.
- Enter a Batch Name (required, up to 50 characters) and click Initiate.
- The valid users are added to the domain as Submitted requests, ready for their approvers in User Management. Any invalid rows are skipped.
THE FILE NEEDS A
UserEmailCOLUMN — The upload only reads a column headed UserEmail on the first sheet. If a file is rejected, check that heading first. Rows with a bad or duplicate email are flagged in Batch Details and simply left out — the good ones still go through.
The Batch Uploads list
Once a batch has been initiated, it's listed on the same Batch Uploads tab, which keeps a record of every batch:
| Column | What it shows |
|---|---|
| Batch Name | The name given to the upload. |
| Created By | Who uploaded the batch. |
| Created Date | When it was uploaded. |
Every person from a batch carries its Batch Name into User Management, so you can search that screen by batch and review or approve a whole group together.
8. Quick Reference
A fast lookup for the most common actions.
| I want to… | Do this |
|---|---|
| Make a role available in the domain | User Provisioning → Define Role → + → pick Role and Approver → Save |
| Stop new requests for a role without deleting it | Define Role → untick Active |
| Change who approves a role | Define Role → change the Approver in the row |
| See who's waiting for access | User Provisioning → User Management → look for Submitted |
| Approve or deny a request | User Management → Approve / Deny (on requests you approve) |
| Approve or deny a whole group | Select the requests → use the bulk Approve / Deny action |
| See a person's details | User Management → Info icon |
| Fix an expired invitation | User Management → Re-send on the Expired row |
| Remove someone | User Management → Delete on the Expired row |
| Create a brand-new user | Users list → + → fill the form → Save |
| Add an existing user to a domain | Users list → Add Existing User to Domain → pick the user → Save |
| Add many users at once | Batch Uploads tab → Batch Add → choose an .xlsx with a UserEmail column → Upload → enter a Batch Name → Initiate |
| Find everyone from one upload | User Management → search by Batch Name |
Source: OnCoor Process Management product documentation, written for end users. For the latest screens and options, always refer to the in-app interface.