This page is machine-translated from French. Read the French original.

Users, roles and organizations


Two operating modes

Single user (by default). A single person, protected if necessary by a unique password. This is the mode of the desktop application.

Multi-user. Named accounts, roles, shared spaces, invitations, a usable event log. This is the required setup for an organization.

Toggle: Réglages → Sécurité → Activer le mode multi-utilisateurs. The account that performs the switchover becomes the administrator. The operation is not reversible from the interface — Make a backup first.


The roles

Role Can do
Administrator Everything: instance configuration, providers, users, agents, security, logs
Administrator Create and administer workspaces, manage their members, invite users. No instance configuration required.
User Use the spaces he is a member of, manage his own conversations and personal settings
Guest Limited and temporary access to designated areas

Good practice: Limit the number of administrators. A Manager role is sufficient for the vast majority of management needs, and it does not provide access to supplier keys or configuration.


Create accounts

Direct creation. Réglages → Utilisateurs → Nouvel utilisateur : username, initial password, role.

Invitation. Réglages → Invitations This generates a one-time-use link. The user chooses their password upon acceptance—the administrator never knows it. This is the preferred method.

Suspension. A suspended account can no longer log in, but its conversations and contributions remain. Prefer suspension to deletion when it's important to preserve a history.


Access to workspaces

In multi-user mode, A user only sees the spaces of which they are a member.. Other people don't exist for him.

Members are managed from the space settings, tab Members, or from the space administration for an overview.

Administrators and managers can see all spaces.


Organizations

A organization It groups users and spaces under a single entity. Useful when a single instance serves multiple entities: subsidiaries, standalone departments, clients of a service provider.

What an organization stands for:

  • his users and its workspaces ;
  • his application connections own — his email, his calendar; ;
  • his authentication connectors.

The main advantage: two organizations on the same instance do not share their workspaces or application access. A messaging skill used in a workspace of organization A uses A's access, never B's.

Management in Réglages → Organisations.


Single Sign-On (SSO)

Rather than WivenLLM-specific passwords, users can log in with their company account.

Supported connectors: Google, Microsoft, Facebook, and any compliant provider OpenID Connect — the latter covering the majority of corporate directories and identity solutions.

Set up : Réglages → Connecteurs d'authentification. You declare the provider, the application's identifier and secret, and you register the return address displayed on the screen. A connector is activated or deactivated without being deleted.

Provisioning. A user logging in for the first time via SSO may be automatically created with a default role. Check this setting before opening: it determines what a new user can access.

Good to know: - SSO connections and provisioning appear in the event log. - Keep at least a local administrator account : if the identity provider becomes unavailable, this is your only way to access.


Guest access

Opens access to people without an account, for limited use.

Settings in Réglages → Accès invité :

  • activation of the function; ;
  • information requested before access (e.g., name and email address); ;
  • validity period of the session; ;
  • accessible spaces to the guests.

Uses: a document assistant for visitors, internal support for employees without an account, a demonstration.

Precautions:

  • Only show guests areas that all content is distributable.
  • Disable sensitive agent skills in these spaces.
  • Guest sessions are logged.

For an assistant intended for a public website, the web widget is generally more suitable.


Transverse restrictions

Two instance settings govern usage independently of roles:

  • Hide conversation history — prevents users from viewing their past exchanges.
  • Limit deletion — prevents users from deleting certain items, for preservation reasons.

They combine with the content control and the event log to build a usage policy.