{"id":7476,"date":"2026-08-19T19:10:08","date_gmt":"2026-08-19T19:10:08","guid":{"rendered":"https:\/\/www.wiven.ai\/wiven-llm\/docs\/administration\/utilisateurs\/"},"modified":"2026-08-19T19:10:08","modified_gmt":"2026-08-19T19:10:08","slug":"utilisateurs","status":"publish","type":"wvn_doc","link":"https:\/\/www.wiven.ai\/en\/wiven-llm\/docs\/administration\/utilisateurs\/","title":{"rendered":"Users, roles and organizations"},"content":{"rendered":"<h1>Users, roles and organizations<\/h1>\n<hr \/>\n<h2>Two operating modes<\/h2>\n<p><strong>Single user<\/strong> <em>(by default)<\/em>. A single person, protected if necessary by<br \/>\na unique password. This is the desktop application mode.<\/p>\n<p><strong>Multi-user<\/strong>. Named accounts, roles, shared spaces, and more.<br \/>\nInvitations, a usable event log. This is the required mode for a<br \/>\norganization.<\/p>\n<p><strong>Toggle:<\/strong> <code>Settings \u2192 Security \u2192 Enable multi-user mode<\/code>. THE<br \/>\nThe account that performs the switch becomes the administrator. <strong>The operation is not<br \/>\nreversible from the interface<\/strong> \u2014 Make a backup first.<\/p>\n<hr \/>\n<h2>The roles<\/h2>\n<table>\n<thead>\n<tr>\n<th>Role<\/th>\n<th>Can do<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Administrator<\/strong><\/td>\n<td>Everything: instance configuration, providers, users, agents, security, logs<\/td>\n<\/tr>\n<tr>\n<td><strong>Administrator<\/strong><\/td>\n<td>Create and administer workspaces, manage their members, invite users. No instance configuration required.<\/td>\n<\/tr>\n<tr>\n<td><strong>User<\/strong><\/td>\n<td>Use the spaces he is a member of, manage his own conversations and personal settings<\/td>\n<\/tr>\n<tr>\n<td><strong>Guest<\/strong><\/td>\n<td>Limited and temporary access to designated areas<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Good practice:<\/strong> Limit the number of administrators. A Manager role<br \/>\nsufficient for the vast majority of management needs, and it does not provide access<br \/>\nneither the suppliers&#039; keys nor the configuration.<\/p>\n<hr \/>\n<h2>Create accounts<\/h2>\n<p><strong>Direct creation.<\/strong> <code>Settings \u2192 Users \u2192 New user<\/code> : identifier,<br \/>\nInitial password, role.<\/p>\n<p><strong>Invitation.<\/strong> <code>Settings \u2192 Invitations<\/code> generates a one-time use link. The<br \/>\nNo one chooses their password upon acceptance \u2014 the administrator does not<br \/>\nNever know. This is the preferred method.<\/p>\n<p><strong>Suspension.<\/strong> A suspended account can no longer log in, but its<br \/>\nconversations and his contributions remain. Prefer suspension to<br \/>\ndeletion when it is necessary to keep a history.<\/p>\n<hr \/>\n<h2>Access to workspaces<\/h2>\n<p>In multi-user mode, <strong>A user only sees the spaces they are in.<br \/>\nmember<\/strong>. Other people don&#039;t exist for him.<\/p>\n<p>Members are managed from the space settings, tab <strong>Members<\/strong>, Or<br \/>\nfrom the space administration for an overview.<\/p>\n<p>Administrators and managers can see all spaces.<\/p>\n<hr \/>\n<h2>Organizations<\/h2>\n<p>A <strong>organization<\/strong> groups users and spaces under the same<br \/>\nentity. Useful when a single instance serves multiple entities: subsidiaries,<br \/>\nautonomous services, clients of a service provider.<\/p>\n<p>What an organization stands for:<\/p>\n<ul>\n<li>his <strong>users<\/strong> and its <strong>workspaces<\/strong> ;<\/li>\n<li>his <strong>application connections<\/strong> own \u2014 his email, his calendar; ;<\/li>\n<li>his <strong>authentication connectors<\/strong>.<\/li>\n<\/ul>\n<p>The main advantage: two organizations on the same instance do not share either<br \/>\ntheir spaces, nor their application access. A messaging skill used<br \/>\nwithin a space of organization A uses the accesses of A, never those of B.<\/p>\n<p>Management in <code>Settings \u2192 Organizations<\/code>.<\/p>\n<hr \/>\n<h2>Single Sign-On (SSO)<\/h2>\n<p>Rather than WivenLLM-specific passwords, users can<br \/>\nconnect with their company account.<\/p>\n<p><strong>Supported connectors:<\/strong> Google, Microsoft, Facebook, and any provider<br \/>\nin accordance with <strong>OpenID Connect<\/strong> \u2014 the latter covering the majority of directories<br \/>\nenterprise and identity solutions.<\/p>\n<p><strong>Set up :<\/strong> <code>Settings \u2192 Authentication Connectors<\/code>. You declare the<br \/>\nprovider, application ID and secret, and you register<br \/>\nOn your end, the return address is displayed on the screen. A connector is activated or<br \/>\nIt deactivates without being deleted.<\/p>\n<p><strong>Provisioning.<\/strong> A user logging in for the first time via SSO<br \/>\nIt can be created automatically with a default role. Check this setting.<br \/>\nbefore opening: it determines what a newcomer has access to.<\/p>\n<p><strong>Good to know:<\/strong><br \/>\n\u2013 SSO connections and provisioning appear in the log<br \/>\n  of events.<br \/>\n\u2013 Keep at least <strong>a local administrator account<\/strong> if the supplier<br \/>\n  If your identity becomes unavailable, this is your only way in.<\/p>\n<hr \/>\n<h2>Guest access<\/h2>\n<p>Opens access to people without an account, for limited use.<\/p>\n<p>Settings in <code>Settings \u2192 Guest access<\/code> :<\/p>\n<ul>\n<li><strong>activation<\/strong> of the function; ;<\/li>\n<li><strong>information requested<\/strong> before access (e.g., name and address)<br \/>\n  e-mail); ;<\/li>\n<li><strong>validity period<\/strong> of the session; ;<\/li>\n<li><strong>accessible spaces<\/strong> to the guests.<\/li>\n<\/ul>\n<p><strong>Uses:<\/strong> a document assistant for visitors, internal support<br \/>\nA demonstration for collaborators without an account.<\/p>\n<p><strong>Precautions:<\/strong><\/p>\n<ul>\n<li>Only show guests areas that <strong>all the content is<br \/>\n  broadcastable<\/strong>.<\/li>\n<li>Disable sensitive agent skills in these spaces.<\/li>\n<li>Guest sessions are logged.<\/li>\n<\/ul>\n<p>For an assistant intended for a public website, the<br \/>\n<a href=\"\/en\/wiven-llm\/docs\/integrations\/widget\/\">web widget<\/a> is generally more suitable.<\/p>\n<hr \/>\n<h2>Transverse restrictions<\/h2>\n<p>Two instance settings govern usage independently of roles:<\/p>\n<ul>\n<li><strong>Hide conversation history<\/strong> \u2014 prevents users from<br \/>\n  review their past exchanges.<\/li>\n<li><strong>Limit deletion<\/strong> \u2014 prevents users from deleting certain<br \/>\n  elements, for conservation reasons.<\/li>\n<\/ul>\n<p>They combine with the <a href=\"\/en\/wiven-llm\/docs\/administration\/controle-de-contenu\/\">content control<\/a> and the<br \/>\n<a href=\"\/en\/wiven-llm\/docs\/administration\/journaux\/\">event log<\/a> to build a<br \/>\nusage policy.<\/p>","protected":false},"parent":7451,"menu_order":501,"template":"","meta":[],"class_list":["post-7476","wvn_doc","type-wvn_doc","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Utilisateurs et r\u00f4les \u2014 Documentation WivenLLM<\/title>\n<meta name=\"description\" content=\"Passer en multi-utilisateurs, attribuer les r\u00f4les, cloisonner par organisation, ouvrir un acc\u00e8s invit\u00e9 et brancher l&#039;authentification unique.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wiven.ai\/en\/wiven-llm\/docs\/administration\/utilisateurs\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Utilisateurs et r\u00f4les \u2014 Documentation WivenLLM\" \/>\n<meta property=\"og:description\" content=\"Passer en multi-utilisateurs, attribuer les r\u00f4les, cloisonner par organisation, ouvrir un acc\u00e8s invit\u00e9 et brancher l&#039;authentification unique.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wiven.ai\/en\/wiven-llm\/docs\/administration\/utilisateurs\/\" \/>\n<meta property=\"og:site_name\" content=\"Wiven AI\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.wiven.ai\\\/wiven-llm\\\/docs\\\/administration\\\/utilisateurs\\\/\",\"url\":\"https:\\\/\\\/www.wiven.ai\\\/wiven-llm\\\/docs\\\/administration\\\/utilisateurs\\\/\",\"name\":\"Utilisateurs et r\u00f4les \u2014 Documentation WivenLLM\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.wiven.ai\\\/#website\"},\"datePublished\":\"2026-08-19T19:10:08+00:00\",\"description\":\"Passer en multi-utilisateurs, attribuer les r\u00f4les, cloisonner par organisation, ouvrir un acc\u00e8s invit\u00e9 et brancher l'authentification unique.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.wiven.ai\\\/wiven-llm\\\/docs\\\/administration\\\/utilisateurs\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.wiven.ai\\\/wiven-llm\\\/docs\\\/administration\\\/utilisateurs\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.wiven.ai\\\/wiven-llm\\\/docs\\\/administration\\\/utilisateurs\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.wiven.ai\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Documentation\",\"item\":\"https:\\\/\\\/www.wiven.ai\\\/wiven-llm\\\/docs\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Administration\",\"item\":\"https:\\\/\\\/www.wiven.ai\\\/wiven-llm\\\/docs\\\/administration\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Utilisateurs, r\u00f4les et organisations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.wiven.ai\\\/#website\",\"url\":\"https:\\\/\\\/www.wiven.ai\\\/\",\"name\":\"Wiven AI\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.wiven.ai\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Users and Roles \u2014 WivenLLM Documentation","description":"Switch to multi-user, assign roles, partition by organization, open guest access and connect single sign-on.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wiven.ai\/en\/wiven-llm\/docs\/administration\/utilisateurs\/","og_locale":"en_US","og_type":"article","og_title":"Utilisateurs et r\u00f4les \u2014 Documentation WivenLLM","og_description":"Passer en multi-utilisateurs, attribuer les r\u00f4les, cloisonner par organisation, ouvrir un acc\u00e8s invit\u00e9 et brancher l'authentification unique.","og_url":"https:\/\/www.wiven.ai\/en\/wiven-llm\/docs\/administration\/utilisateurs\/","og_site_name":"Wiven AI","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wiven.ai\/wiven-llm\/docs\/administration\/utilisateurs\/","url":"https:\/\/www.wiven.ai\/wiven-llm\/docs\/administration\/utilisateurs\/","name":"Users and Roles \u2014 WivenLLM Documentation","isPartOf":{"@id":"https:\/\/www.wiven.ai\/#website"},"datePublished":"2026-08-19T19:10:08+00:00","description":"Switch to multi-user, assign roles, partition by organization, open guest access and connect single sign-on.","breadcrumb":{"@id":"https:\/\/www.wiven.ai\/wiven-llm\/docs\/administration\/utilisateurs\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wiven.ai\/wiven-llm\/docs\/administration\/utilisateurs\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wiven.ai\/wiven-llm\/docs\/administration\/utilisateurs\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.wiven.ai\/"},{"@type":"ListItem","position":2,"name":"Documentation","item":"https:\/\/www.wiven.ai\/wiven-llm\/docs\/"},{"@type":"ListItem","position":3,"name":"Administration","item":"https:\/\/www.wiven.ai\/wiven-llm\/docs\/administration\/"},{"@type":"ListItem","position":4,"name":"Utilisateurs, r\u00f4les et organisations"}]},{"@type":"WebSite","@id":"https:\/\/www.wiven.ai\/#website","url":"https:\/\/www.wiven.ai\/","name":"Wiven AI","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wiven.ai\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"}]}},"_links":{"self":[{"href":"https:\/\/www.wiven.ai\/en\/wp-json\/wp\/v2\/wvn_doc\/7476","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wiven.ai\/en\/wp-json\/wp\/v2\/wvn_doc"}],"about":[{"href":"https:\/\/www.wiven.ai\/en\/wp-json\/wp\/v2\/types\/wvn_doc"}],"up":[{"embeddable":true,"href":"https:\/\/www.wiven.ai\/en\/wp-json\/wp\/v2\/wvn_doc\/7451"}],"wp:attachment":[{"href":"https:\/\/www.wiven.ai\/en\/wp-json\/wp\/v2\/media?parent=7476"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}