This guide explains how to configure groups and permissions when integrating TimeClock 365 with OKTA.
Groups and roles
Groups: Groups are imported from Okta into our system. They should represent different categories or teams within your organization.
Permissions: Permissions in our system define the access levels users can have based on their group membership.
Mapping groups to roles
Determine which roles in our system correspond to each group imported from Okta. For example, Group A from Okta might map to Permission X in our system. Users who belong to a specific Okta group will automatically receive the matching role in our system during the sync process.
Note that TimeClock 365 has four roles: system administrator, group manager, employee, and editor (with edit capability).
Setting the priority order for permission level
- Log in to our system.
- Navigate to the sidebar -> Settings -> Company Profile -> SAML section -> click "Add Item".
- Choose a group in the left column and a permission in the right column.
If a user meets the criteria for multiple permissions (for example, belongs to several groups defined by different permissions), the system applies the permission assignment specified by the rule that appears higher in the list.
For example, suppose an employee is assigned to both the managers group and the employees group in Okta. If users are not assigned to a group, you can set the default role: Navigate to the sidebar -> Settings -> Company Profile -> General -> find the Azure user sync section and select the role from the dropdown menu.