This document describes how to view the organization chart and user information from created identity sources. You can also add organization charts and users for custom identity sources.
Background information
If your company does not use an identity source to manage its organization chart, you can create a custom identity source in SASE to validate user identities. If you already use an identity source, connect it to SASE to sync your organization chart. This allows employees to use their corporate identity to log on to the SASE App. After you create an identity source, you can go to the Employee Center to view the synchronized organization chart and employee information from third-party identity sources. You can also create an organization chart and add users for custom identity sources.
Prerequisites
You have created an identity source and synchronized the information from the third-party identity source. For more information, see Identity synchronization.
Custom identity sources
After you create a custom identity source, you can add and manage its departments and users in the Employee Center.
Add departments and users
Log on to the Secure Access Service Edge console.
In the navigation pane on the left, choose .
On the Employee Center tab, select a custom identity source from the drop-down list.

Click Create Department. In the dialog box, enter a Department Name and click OK.
You can repeat this step to create multiple departments.
Select the department to which you want to add users and click Add User.

In the Add User panel, configure the user information and click OK.
User information includes Username (required), Password, Department (required), Position, Email Address (required), Mobile Phone Number, Employment Status, and Account Expiration Time.
You can add user information in one of the following two ways:
Manually Add
Configure the parameters for the user.
Batch Import
Click Download Import Template, enter the user information, and then upload the file.
ImportantIf you do not configure a Password, SASE sends the username and an automatically generated password to the user's email address after the user is added. These credentials are used to log on to the SASE App. Keep this information secure.
Manage user information
Select a department to view the user information for that department in the list.

Account Status:
Pending Activation: The user has not logged on to the SASE App.
Enabled: The user has successfully logged on to the SASE App.
Suspended: The user account is frozen. The user cannot log on to the SASE App, and any logged-on users are forced to log out.
Account Expiration Time: After the account expires, the Account Status is automatically updated to Suspended.
You can view user details, edit user information, or delete users.
View details
In the Actions column, click Details.
In the Details panel, you can view the user's detailed information.
For users whose Account Status is Enabled or Pending Activation, you can click Disable Account.
After an account is frozen, the user cannot log on to the SASE App. Any logged-on users are forced to log out.
For users whose Account Status is Suspended, you can click Enable Account.
Edit
In the Actions column, click Edit.
In the Edit User panel, modify the user information and click OK.
Delete: In the Actions column, click Delete, and then click OK.
ImportantAfter a user is deleted, the user can no longer log on to the SASE App. Proceed with caution.
Third-party identity sources
After you create an identity source and enable automatic synchronization, you can view the synchronized organization chart and employee information in the Employee Center.
Log on to the Secure Access Service Edge console.
In the navigation pane on the left, choose .
On the Employee Center tab, select a third-party identity source from the drop-down list to view its organization chart and employee information.

Account Status:
Pending Activation: The user has not logged on to the SASE App.
Enabled: The user has successfully logged on to the SASE App.
Suspended: The user account is frozen. The user cannot log on to the SASE App, and any logged-on users are forced to log out.
View details
In the Actions column, click Details.
In the Details panel, you can view the user's detailed information.
For users whose Account Status is Enabled or Pending Activation, you can click Disable Account.
After an account is frozen, the user cannot log on to the SASE App. Any logged-on users are forced to log out.
For users whose Account Status is Suspended, you can click Enable Account.
Edit
In the Actions column, click Edit.
In the Edit User panel, you can only modify the user's Position and Employment Status. Then, click OK.
NoteFor third-party identity sources, you cannot add new users, modify important user information (such as organizational departments, mailboxes, or phone numbers), or delete user information. To perform these operations, you must use the console of the corresponding third-party identity source. After the operations are complete, perform an identity synchronization.