Skip to main content

User Provisioning

User Guide — Giving People the Right Access to a Data Domain​

|  Last updated: September 2026


Contents​

  1. Overview
  2. Key Concept: Roles, Approvers, and Requests
  3. Finding Your Way Around
  4. Define Role — Deciding What Access Exists
  5. User Management — Approving and Managing People
  6. The User Status Lifecycle
  7. Adding Users to a Domain
  8. Quick Reference

1. Overview​

User Provisioning is where you control who can work in a data domain and what they're allowed to do there. It's the place to set up the roles a domain offers, decide who signs off on access, and then approve, manage, and remove the people who ask for it.

Access in OnCoor is granted per data domain, so what you set up here applies to the domain you're currently working in. Another domain has its own roles and its own users.

What you can do here

  • Define the roles available in a domain, and choose who approves each one.
  • Review the people who have asked to join the domain.
  • Approve or deny their requests — one at a time or in bulk.
  • Keep access tidy — re-send an invitation that has expired, or remove someone who no longer needs access.
  • Add people to the domain — one at a time, or many at once through a batch upload.

WHERE TO FIND IT — User Provisioning is under Process Management → User Provisioning, and is split into three areas: Define Role, User Management, and Batch Uploads.


2. Key Concept: Roles, Approvers, and Requests​

Three ideas work together here:

  • A Role is a named set of permissions — what a person can see and do. A role only becomes available in a domain once you add it on the Define Role screen.
  • An Approver is the person responsible for saying yes or no to requests for a particular role. Every role you add is given an approver.
  • A Request is what's created when someone asks to join the domain (or is added to it). It waits until its approver deals with it.

So the flow is: you make a role available and give it an approver; a person's request for that role then appears in User Management, where the approver approves or denies it. Only after approval does the person actually get access.

Rule of thumb: set up your roles on the Define Role screen first — until a role exists with an approver, nobody can be approved into it.


3. Finding Your Way Around​

Go to Process Management → User Provisioning. The module has three areas:

AreaWhat it's for
Define RoleDefine which roles the domain offers and who approves each (section 4).
User ManagementReview, approve, deny, and manage the people in the domain (section 5).
Batch UploadsA record of the bulk user uploads made to the domain (section 7).

A sensible order is to set up Define Role first, then work in User Management as requests come in, using Batch Uploads whenever you need to bring in a group of people together.


4. Define Role — Deciding What Access Exists​

The Define Role screen lists the roles available in the current domain. Each row is one role, with the person who approves requests for it.

Adding a role

  1. Click the Add button (the floating +).
  2. Choose the Role you want to make available.
  3. Choose the Approver who will handle requests for it.
  4. Save. The role appears in the list, ready to be requested.

What each column shows

ColumnWhat it means
ActiveWhether the role is currently on offer. Untick it to stop new requests for the role without removing it.
RoleThe role being offered in this domain.
ApproverThe person who approves or denies requests for this role.
Updated By / Updated DateWho last changed the row, and when.
Created By / Created DateWho added the role, and when.

You can change the Active, Role, and Approver values right in the row, and remove a role with the Delete icon in its Action column.

NO ROLE, NO ACCESS — A role has to be added here, marked Active, and given an Approver before anyone can be approved into it. If people can't request the access they expect, this is the first screen to check.


5. User Management — Approving and Managing People​

The User Management screen lists the people in the domain and where each one stands. Use the search bar at the top to narrow the list.

What each column shows

ColumnWhat it means
Batch NameThe upload batch a person came in on, if they were added as part of a group.
User EmailThe person's email address.
StatusWhere their request stands — see section 6.
Remaining TimeFor someone who's been invited but hasn't finished signing up, how long is left before the invitation expires.
User RolesThe role(s) the person is requesting or holds.
Updated By / Date, Created By / DateWho last changed the record and who created it, with dates.

The actions you'll see depend on a person's status, and appear in the Actions column:

ActionWhen it appearsWhat it does
InfoSubmitted, Account Created, or RejectedOpens the person's details.
ApproveSubmitted (and you are the approver)Grants the request — the account is created.
DenySubmitted (and you are the approver)Rejects the request.
Re-sendExpiredSends a fresh invitation so the person can finish signing up.
DeleteExpiredRemoves the person's record from the domain.

YOU ONLY APPROVE WHAT'S YOURS — The Approve and Deny actions show up only on requests for roles where you are the named approver. If you can't act on a request, it belongs to a different approver.

Approving or denying several at once

Tick the requests you want (only those waiting on you can be selected), then use the Approve or Deny action that appears above the list to handle them all together — handy after a batch upload.


6. The User Status Lifecycle​

The Status column tells you exactly where each person is:

StatusWhat it meansWhat to do
SubmittedThe request is waiting for its approver.The approver clicks Approve or Deny.
Account CreatedThe request was approved and the account now exists.Nothing — the person has access.
RejectedThe request was denied.Nothing, unless they should re-apply.
ExpiredAn invitation ran out before it was completed.Re-send the invitation, or Delete the record.

The usual path is Submitted → Account Created. A denied request becomes Rejected, and an invitation that isn't completed in time becomes Expired — where Remaining Time hits zero — which you can revive with Re-send.

WATCH REMAINING TIME — An invited person needs to finish signing up before their Remaining Time runs out. Once it does, their status turns to Expired and they'll need a fresh invitation via Re-send.


7. Adding Users to a Domain​

People appear in User Management because they've been added to the domain — either one at a time or as a batch. Once added, they flow into User Provisioning for you to review and approve.

Adding a single user​

There are two ways to add one person.

Create a brand-new user — for someone who doesn't have an OnCoor account yet. Click the Add button (the +) on the Users list to open the user form, then fill it in:

FieldNotes
First NameRequired.
Middle Name / Last NameOptional.
Email AddressRequired, and must be a valid email.
Password / Confirm PasswordRequired; the two must match.
Default DomainRequired — the domain the user starts in.
Is Account LockedLeave No unless you want the account blocked from the start.
Is Security AdminWhether the user gets security-admin rights. Defaults to No.
Reset Password on Next LoginOn by default, so the person sets their own password the first time they sign in.

A password must be 8–128 characters and include uppercase letters, lowercase letters, numbers, and special characters. Click Save to create the user.

Add an existing user to the domain — for someone who already has an OnCoor account. Click Add Existing User to Domain, pick the person from the list (only users not already in this domain appear), and click Save.

Uploading a batch of users​

To bring in many people at once, upload a list of their email addresses from the Batch Uploads tab.

  1. On the Batch Uploads tab, click Batch Add. The Upload User Data window opens.
  2. Click Choose a file and pick an Excel file (.xlsx or .xls). The first sheet must have a column headed exactly UserEmail, with one address per row.
  3. The selected file name appears. Click Upload.
  4. OnCoor checks every address and opens the Batch Details window, listing each one with whether it's Valid and, if not, the Reason — for example Invalid email format or Duplicate entry in file.
  5. Enter a Batch Name (required, up to 50 characters) and click Initiate.
  6. The valid users are added to the domain as Submitted requests, ready for their approvers in User Management. Any invalid rows are skipped.

THE FILE NEEDS A UserEmail COLUMN — The upload only reads a column headed UserEmail on the first sheet. If a file is rejected, check that heading first. Rows with a bad or duplicate email are flagged in Batch Details and simply left out — the good ones still go through.

The Batch Uploads list​

Once a batch has been initiated, it's listed on the same Batch Uploads tab, which keeps a record of every batch:

ColumnWhat it shows
Batch NameThe name given to the upload.
Created ByWho uploaded the batch.
Created DateWhen it was uploaded.

Every person from a batch carries its Batch Name into User Management, so you can search that screen by batch and review or approve a whole group together.


8. Quick Reference​

A fast lookup for the most common actions.

I want to…Do this
Make a role available in the domainUser Provisioning → Define Role → + → pick Role and Approver → Save
Stop new requests for a role without deleting itDefine Role → untick Active
Change who approves a roleDefine Role → change the Approver in the row
See who's waiting for accessUser Provisioning → User Management → look for Submitted
Approve or deny a requestUser Management → Approve / Deny (on requests you approve)
Approve or deny a whole groupSelect the requests → use the bulk Approve / Deny action
See a person's detailsUser Management → Info icon
Fix an expired invitationUser Management → Re-send on the Expired row
Remove someoneUser Management → Delete on the Expired row
Create a brand-new userUsers list → + → fill the form → Save
Add an existing user to a domainUsers list → Add Existing User to Domain → pick the user → Save
Add many users at onceBatch Uploads tab → Batch Add → choose an .xlsx with a UserEmail column → Upload → enter a Batch Name → Initiate
Find everyone from one uploadUser Management → search by Batch Name

Source: OnCoor Process Management product documentation, written for end users. For the latest screens and options, always refer to the in-app interface.