Skip to main content
andybuchanan
Contributor ⭐️⭐️⭐️⭐️
June 20, 2023
Current Behaviour

Automate Permission Bundle Assignment

Related products:CS Rules Engine
  • June 20, 2023
  • 8 replies
  • 124 views

Currently in SFDC User we have fields that determine “who” the user is.  This essentially determines if they are:

  • Individual CSM/CSE/Etc (standard end user)
  • Manager (Standard end user with extra priveleges / different field level permissions (handled with layouts today)
  • CS Ops (Similar extra permissions to Manager, certain admin areas like dashboard, JO, report building, etc)
  • Admin / Dev team (super admin)

All users will access via SFDC, so all permissions / provisioning should come from external system and would expect that additional work is not needed in Gainsight to provision users with correct access.

Also, Default bundle has “standard” tabs, but as an organization, I would want to control what is “standard” for our users as there are components of Gainsight that aren’t necessary

8 replies

gunjanm
Expert ⭐️
June 21, 2023

@andybuchanan I would never suggest using the Default Bundle for end users, and instead would suggest creating custom bundles.

There are automatic permission possibilities under the Permission Bundles page → within a bundle → + Rules. 

With the right Connector setup from SFDC to set Active/Inactive, the only thing you would need to do is set the license type in Gainsight.

Though, using the User Management API, you could likely fully automate the process too.

Gunjan
andybuchanan
Contributor ⭐️⭐️⭐️⭐️
June 21, 2023

Thanks @gunjanm for chiming in.  Your first statement although accurate is not encouraging. I don’t understand why this isn’t editable or useful.  If this is true, then this is a useless permission bundle, and definitely shouldn’t be the default.

As for the rules in Permission bundles, I was on a call as part of our NXT migration, and it was stated that the rules only run for “existing users” and wouldn’t run again when new users were created.  I’m trying to get meetings setup with others at Gainsight to truly understand this and this post is in response to what we were told by our Gainsight representative, so again, I’m hoping there was a misunderstanding in the functionality.  We use SFDC exclusively, and therefore don’t understand why Gainsight NXT wouldn’t have been setup from the beginning to pass variables from SFDC to automate licensing and permissions.  I don’t want to have an API to update the info when SFDC is my source of truth for User Access, and the Connector is baked into the product. Just creates another process that can get out of sync.

Andy
andybuchanan
Contributor ⭐️⭐️⭐️⭐️
June 21, 2023

Also, the fact that I can’t set the License Type from the connector is silly.  It’s unreasonable to sync active users from Salesforce, only to have to manually grant a license when they are already granted access via SFDC license.

Andy
gunjanm
Expert ⭐️
June 21, 2023

“stated that the rules only run for “existing users” and wouldn’t run again when new users were created.” first I’m hearing anything like this...I don’t know that that’s true. I would suggest getting that validated - maybe @revathimenon or @anirbandutta can help by tagging in a PM to confirm. 

The license management strategy is pretty intentional from what I understand based on different license purchase and assignment models. I would argue that I prefer it being separate but would also want a way to do it better automatically. 

Gunjan
anirbandutta
Expert ⭐️
June 22, 2023

“stated that the rules only run for “existing users” and wouldn’t run again when new users were created.” first I’m hearing anything like this...I don’t know that that’s true. I would suggest getting that validated - maybe @revathimenon or @anirbandutta can help by tagging in a PM to confirm. 

Roger that. Let me try get some validation.

It's an opportunity for engagement
Kartheek
Gainsight Employee ⭐️
Gainsight Employee ⭐️
June 23, 2023

@andybuchanan Sorry for the delayed response, as discussed, you can create custom permission bundles for full licensed users and create rules with in the permission bundles to assign users based on business criteria, and it should work on any new user getting added to it

Kartheek
Gainsight Employee ⭐️
Gainsight Employee ⭐️
June 23, 2023
No Status→Current Functionality
Expert ⭐️
June 23, 2023

@andybuchanan Someone on the work Admin group just ran into this issue too. 

 

The inactive user comment seems very wrong as the user object is like any other in rules engine. Their comment sounds more like if it is brought in via connector. Which that is where once it is brought in it does not update anymore, very odd IMO.

 

As far as the license type in rules engine, apparently this is just a simple request to support to turn on and then you can map to it in rules.