> For the complete documentation index, see [llms.txt](https://incident-tracker.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://incident-tracker.gitbook.io/docs/admin-guide/setup-walkthrough/part-3-users-permissions-and-integrations.md).

# Part 3 — Users, Permissions & Integrations

Add users, verify permissions, and connect Microsoft identity tools.

Add your team, define what they can see and do, and optionally connect Incident Tracker to Microsoft for automated user management.

{% hint style="info" %}
Complete [Part 1 — Customize Your Submit Report Page](/docs/admin-guide/setup-walkthrough/part-1-customize-your-submit-report-page.md) and [Part 2 — Notifications, Workflows & System Settings](/docs/admin-guide/setup-walkthrough/part-2-notifications-workflows-and-system-settings.md) before starting here. User restrictions reference the categories and locations configured in Part 1.
{% endhint %}

{% hint style="warning" %}
Some features in this section require an Enterprise subscription. If a setting is unavailable, contact your account manager for details.
{% endhint %}

***

### Step 1 — Understand user types

Before creating anyone, it helps to know the four common access patterns:

* **Submit only** — can submit reports but cannot view existing reports
* **View own reports** — can submit and see reports they submitted
* **View reports** — can see reports within permitted locations or categories
* **Admin** — full access to configuration and report data

Visibility comes from a combination of role settings and category or location restrictions.

You will configure those in the next steps.

***

### Step 2 — Create a new user

Create a test user that you can sign in as during the checkpoint.

* Set their basic account information
* Assign their access rights
* Apply category or location restrictions when visibility should be scoped

{% hint style="info" %}
See [Create New User](/docs/admin-guide/users/create-new-user.md) for full setup instructions.
{% endhint %}

***

### Step 3 — Create a user group

User groups let you manage permissions for many users at once.

A change to the group applies to everyone in it.

This is more efficient than editing users one by one as your team grows.

* Create a group that reflects a real role in your organization
* Add the user from Step 2
* Make one rights or restriction change at the group level and confirm it applies

{% hint style="info" %}
See [Manage User Groups](/docs/admin-guide/users/manage-user-groups.md) for full setup instructions.
{% endhint %}

***

### Step 4 — Audit user access

Two tools help you verify permissions before go-live:

* **Restriction Summary** — shows what each user and group can access
* **Export** — lets you review access data in a spreadsheet for audits or deeper checks

Revisit both whenever your team structure changes significantly.

{% hint style="info" %}
See [Restriction Summary](/docs/admin-guide/users/restriction-summary.md) for full details.
{% endhint %}

***

### Step 5 — Explore integration options

If your organization manages users in Microsoft Entra ID, Incident Tracker supports automated user provisioning.

This reduces manual account setup and deactivation.

* **Single Sign-On (SSO)** — users sign in with Microsoft credentials. See [Single Sign-on](/docs/admin-guide/application-information/authentication-settings/single-sign-on.md).
* **SCIM Provisioning** — automatically creates, updates, and deactivates accounts. See [SCIM Provisioning](/docs/admin-guide/application-information/authentication-settings/account-provisioning/scim.md).
* **Microsoft Graph** — an alternative provisioning method for Microsoft 365. See [Microsoft Graph](/docs/admin-guide/application-information/authentication-settings/account-provisioning/microsoft-graph.md).

{% hint style="warning" %}
SCIM Provisioning and Microsoft Graph require an Enterprise subscription.
{% endhint %}

***

***

{% hint style="success" %}
**Checkpoint:** Sign in as the non-admin user you created in Step 2. Submit a test report and verify their report visibility matches the rights you assigned. This is the best way to confirm your permission setup before rollout.
{% endhint %}

***

You're all set.

Your Submit Report page is configured, your workflows are running, and your users are in place.

For a deeper look at any area, continue with [Getting Started](/docs/admin-guide/getting-started.md) or [Submit a Ticket](/docs/support/need-help/submit-a-ticket.md) if you need help.
