Add, view, modify, deactivate, or delete members in your Alibaba Cloud DevOps organization.
Add organization members
Alibaba Cloud DevOps supports two ways to add organization members:
-
Manually create members as an administrator.
-
Synchronize members from a third-party identity provider.
Manually create members
-
Log on to an Alibaba Cloud DevOps organization as an administrator.
-
Click your profile picture in the upper-right corner and select Organization Settings from the drop-down menu.
-
In the navigation pane on the left, choose Members. Click New User and enter the required information, such as Name, Account ID, Initial Password, and Department, along with any optional information.
-
Click Confirm to create the member.
If you use username and password to log on to Alibaba Cloud DevOps, you must configure an IP address whitelist to ensure data security. If you log on through a third-party identity provider (SSO), you do not need to configure an IP address whitelist.
Synchronize members from a third-party identity provider
Integrate your existing corporate identity provider, such as an Alibaba Cloud account, DingTalk, or Lark, to automatically synchronize members and enable single sign-on.
How it works:
When single sign-on (SSO) is enabled for an identity provider, the system automatically creates an organization account for any user who logs on to Alibaba Cloud DevOps through that identity provider for the first time. The user is then added as a member. For more information, see Identity provider management.
Account ID generation rule:
The account ID is the combination of the account ID mapping field from the identity provider configuration, an underscore (_), and the current organization identifier.
View organization members
-
Log on to your Alibaba Cloud DevOps organization as an administrator. On any page, click your profile picture in the upper-right corner and select Organization Settings from the menu.
-
In the navigation pane on the left, choose to view and manage all members in the organization.
Each member has one of the following statuses:
-
In use: The member has successfully logged on to the Alibaba Cloud DevOps organization and occupies a license.
-
Never logged on: The member was synchronized but has never logged on to the Alibaba Cloud DevOps organization. This member does not occupy a license.
-
Deactivated: The member cannot log on and all permissions are revoked. This member does not occupy a license. If the member is reactivated, their permissions are automatically restored.
-
Deleted: The member cannot log on and all permissions are revoked. This member does not occupy a license. The member can be restored, but their permissions and previous configurations are not automatically restored and must be reconfigured manually.
Modify member information
-
As an administrator, on the Members page, select the target member.
-
Click the member's name, or click the operation icon in the rightmost column and select Modify Member Information.
If you set the Account Binding and Property Mapping rule in the identity provider configuration, fields that are mapped to the external identity provider cannot be edited. To modify these fields, you must make the changes in the identity provider. Alibaba Cloud DevOps automatically synchronizes these changes.
Deactivate an organization member
Deactivating a member prevents them from accessing the organization or its data, and frees the license. This is typically used for temporary suspensions. If a deactivated member is reactivated, their permissions are automatically restored.
-
As an administrator, on the Members page, select the target member.
-
Click the operation icon in the rightmost column and select Deactivate Member.
-
Confirm the deactivation.
Delete an organization member
Deleting a member revokes their access to the organization and frees the license.
-
As an administrator, on the Members page, select the target member.
-
Click the operation icon in the rightmost column and select Delete Member.
-
Confirm the deletion.
A deleted member's account is marked as deleted, but its unique identifiers, such as the account ID or email address, cannot be reused. You can restore the member. However, their permissions and related settings are not restored and must be reconfigured.