All Products
Search
Document Center

Secure Access Service Edge:Employee Center

Last Updated:Mar 31, 2026

The Employee Center shows your organization's structure and employee accounts synced from your identity source. For custom identity sources, you can also create departments and add users directly in SASE.

Prerequisites

Before you begin, ensure that you have:

  • An identity source created in SASE

  • Identity information synced from the third-party identity source (if applicable). For more information, see Identity synchronization.

Identity source types

The operations available in the Employee Center depend on your identity source type.

OperationCustom identity sourceThird-party identity source
View organization chart and usersYesYes
Create departmentsYesNo
Add usersYesNo
Edit all user fieldsYesNo
Edit Position and Employment StatusYesYes
Delete usersYesNo

For third-party identity sources, make user and department changes in the third-party console, then run an identity synchronization to update SASE.

Custom identity sources

Add departments and users

  1. Log on to the Secure Access Service Edge console.

  2. In the navigation pane on the left, choose Identity Authentication > Identity Access.

  3. On the Employee Center tab, select a custom identity source from the drop-down list.

image
  1. Click Create Department. In the dialog box, enter a Department Name and click OK. Repeat this step to create multiple departments.

  2. Select the department to which you want to add users and click Add User.

image
  1. In the Add User panel, configure the user information and click OK. To add multiple users at once, select Batch Import: click Download Import Template, enter the user information, and upload the file.

    Important

    Keep login credentials secure. When no password is configured, SASE emails the auto-generated credentials to the user after the user is added. These credentials are used to log on to the SASE App.

    FieldRequiredDescription
    UsernameYesThe user's login name for the SASE App
    PasswordNoIf left blank, SASE auto-generates a password and sends it with the username to the user's email address
    DepartmentYesThe department the user belongs to
    PositionNoThe user's job title
    Email AddressYesUsed to receive login credentials when no password is set
    Mobile Phone NumberNoThe user's phone number
    Employment StatusNoThe user's current employment status
    Account Expiration TimeNoWhen reached, the account status changes to Suspended automatically

Manage users

  1. Select a department to view its users.

image

Each user has one of the following account statuses:

StatusMeaning
Pending ActivationThe user has not logged on to the SASE App yet
EnabledThe user has successfully logged on to the SASE App
SuspendedThe account is frozen. The user cannot log on, and any active sessions are terminated

An account moves to Suspended automatically when its Account Expiration Time is reached.

  1. In the Actions column, select an operation:

    • Details: View the user's full profile. From the details panel:

      • For Enabled or Pending Activation accounts: click Disable Account to freeze the account and terminate any active sessions.

      • For Suspended accounts: click Enable Account to restore access.

    • Edit: Modify the user's information in the Edit User panel and click OK.

    • Delete: Click Delete, then click OK to confirm.

    Important

    After a user is deleted, the user can no longer log on to the SASE App. Proceed with caution.

Third-party identity sources

After syncing a third-party identity source, the Employee Center displays the organization chart and employee information from that source.

  1. Log on to the Secure Access Service Edge console.

  2. In the navigation pane on the left, choose Identity Authentication > Identity Access.

  3. On the Employee Center tab, select a third-party identity source from the drop-down list.

image

The organization chart and employee information for the selected source are displayed. Account status values are the same as those for custom identity sources.

  1. In the Actions column, select an operation:

    • Details: View the user's full profile. From the details panel:

      • For Enabled or Pending Activation accounts: click Disable Account to freeze the account.

      • For Suspended accounts: click Enable Account to restore access.

    • Edit: In the Edit User panel, you can only modify Position or Employment Status and click OK.

Note

For third-party identity sources, adding users, deleting users, and modifying fields such as organizational departments, email addresses, or phone numbers must be done in the third-party console. After making changes there, run an identity synchronization to update SASE.