Managing users
Accounts, roles, and the routine admin tasks around people joining, moving and leaving.
User management in ProFinda is mostly automatic once SCIM provisioning and the Workday integration are running. This page covers the parts that still need a human.
The built-in roles
| Role | Can do | Typical holders |
|---|---|---|
| Member | Maintain own profile, search, view own matches | Everyone |
| Requester | Raise and track resource requests | Partners, engagement managers |
| Resourcer | Triage requests, run matches, see availability across their scope | Resourcing team |
| Reporting | View dashboards and exports for their scope | Operations, finance |
| Admin | Configuration, integrations, all scopes | Platform team |
Roles are additive - a resourcing lead typically holds Member, Requester and Resourcer. Scope (which practice areas or regions a role applies to) is set per assignment.
Assigning roles
Prefer group-driven assignment: map IdP groups to roles under Admin → Users → Role mappings, and membership changes flow through automatically. Assign roles manually only for exceptions, and record why in the assignment note - unexplained manual grants are what access reviews choke on.
Joiners, movers, leavers
Joiners get accounts from SCIM and data from Workday; nothing to do unless they need a non-default role. Movers keep their account; check whether their role scopes should follow their new practice area. Leavers are deactivated automatically - never delete a leaver manually, because deletion breaks work-history records that feed other people’s inferred skills. Deactivation is the correct end state; retention of the underlying data is governed by data retention policy.
Quarterly access review
Export the role assignment list (Admin → Users → Export assignments) each quarter and have scope owners confirm their lists. The export flags manual assignments and accounts with no sign-in for 90 days, which are the two things reviewers should look at first.