Assign system roles

Roles are assigned and managed on the Team page in Organization Settings. When your account manager enables System Roles for your organization, the Team page switches to a roles-enabled view that shows all users: Ocrolus accounts, LOS accounts, and pending invitations, in a single merged table.

What you need

  • Manager status on your Ocrolus account.
  • The user must have logged in at least once. A profile is created on first login. You cannot assign a role before that point.

Before go-live

Complete the following steps with your Ocrolus account manager before the feature is enabled for your org.

  1. Identify your role manager: Confirm that at least one user in your org has admin status and takes ownership of role assignment going forward.

  2. Audit your user list: Review your current users and decide which role each person needs. Have this list ready to action immediately after enablement.

  3. Agree on a duplicate-email strategy: If your org uses Encompass SSO, some users may have email conflicts with accounts in other Ocrolus organizations. Decide which default resolution strategy to use. See Resolving duplicate emails.

What changes when the feature is enabled

The Team page in Organization Settings upgrades to the roles-enabled view, which includes the following.

  • One merged Web Users table combining Ocrolus accounts, LOS accounts, and invitations.
  • A new UI to assign a role to any user.
  • A Roles table with a See Permissions action so you can inspect what each role allows before assigning it.

The merged table includes five columns.

ColumnDescription
EmailOcrolus account email
Encompass EmailLOS / Encompass email
SourceOcrolus / LOS / Both / Invitation
Link StatusLinked / Failed / Not initiated
RoleCurrent role assignment

Assign a role

To assign role perform the following steps:

  1. In the Ocrolus Dashboard, go to Organization Settings and select Team.
  2. Locate the user in the merged Web Users table.
  3. Select User actions > Manage Profile.
  4. In the role picker, select one or more system roles.
  5. Select Save. The new access applies immediately.

To review what a role allows before assigning it, select See Permissions on any role in the Roles table.

When role assignment is available

User stateRole assignment behavior
Existing Ocrolus accountAssign a role immediately.
First login via Encompass SSOProfile is auto-created with a broad default role. Reassign it as soon as the user appears in Team.
LOS / Encompass via webhookProfile appears in Team once the webhook runs. Assign after it is visible.
Invited but not yet logged inNo profile exists yet. Assign after first login.
💡

Tip

When a user logs in for the first time via Encompass SSO, they are automatically assigned a default role that grants broad access until an admin assigns a restricted one. Assign the correct role as soon as the user appears in the Team table. There is currently no automated prompt to remind admins to do this.

Resolving duplicate emails

A duplicate-email conflict occurs when an Encompass user's email address already exists under a different Ocrolus organization. The Team page flags the affected row with a Resolve action and offers two options:

  • Create account with proxy email (recommended): Ocrolus generates a system email alias for the conflicting account. The existing account in the other organization is left untouched. The proxy is not a real inbox and the user does not need to know or remember it. Use this option when both accounts are still needed.
  • Deactivate the existing account: The conflicting account in the other organization is deactivated, freeing the email to link to your organization. Use this option when the other account is no longer needed.
    💡

    Tip

    A user with a duplicate-email conflict is never blocked from logging in. Their account is simply not fully linked to your organization until a manager resolves the conflict.

Setting a default strategy for future conflicts

Rather than resolving each conflict individually, set a default strategy that applies automatically to all future duplicate-email cases. Configure the default in the resolution dialog or in Org Profile settings.

SettingBehavior
Default to proxy emailAutomatically uses a proxy email for every future duplicate-email case. Nothing in the other organization is changed.
Default to deactivateAutomatically deactivates the conflicting account for every future case, freeing the email to link.
📘

Note

Agree on your default strategy with your Ocrolus account manager before enabling the feature so conflicts resolve cleanly from day one.

Post-enablement checklist

After your account manager enables System Roles, complete the following before considering your rollout finished:

  1. Walk your role manager through the updated Team page, including the merged and the Roles tables.
  2. Resolve any duplicate-email conflicts that surface immediately.
  3. Set a default duplicate-email strategy in Org Profile settings.
  4. Assign an explicit role to every existing user. Do not leave users on fallback defaults.
  5. Establish a routine to review new logins, especially Encompass SSO logins, and assign roles promptly.

See also


Did this page help you?