Skip to main content

People Management

Overview

The People section is your central employee directory for security management. Import employees from identity providers, organize them into groups, and track security-related tasks.

Tabs Overview

TabPurpose
UsersEmployee directory and management
GroupsCompliance groups for training and campaigns
TasksAccess management and onboarding tasks

Users

Employee Directory

View all employees with:

  • Name and email
  • Department and title
  • Group memberships
  • Training status
  • Last activity

Importing Employees

From Identity Provider

  1. Navigate to EmployeesPeople
  2. Click Import Users
  3. Select your identity integration:
    • Azure Active Directory
    • Google Workspace
  4. Configure import settings:
    • Include/exclude groups
    • Sync frequency
    • Attribute mapping
  5. Confirm import

Manual Import

For employees not in your identity provider:

  1. Click Add User
  2. Enter employee details:
    • Name
    • Email
    • Department
    • Title
  3. Save

CSV Import

For bulk manual import:

  1. Click ImportCSV
  2. Download template
  3. Fill in employee data
  4. Upload completed CSV
  5. Review and confirm

Employee Details

Click on an employee to view:

  • Profile - Contact information
  • Groups - Group memberships
  • Training - Assigned and completed training
  • Phishing - Phishing campaign results
  • Tasks - Assigned security tasks

Employee Actions

ActionDescription
EditUpdate employee information
DisableDeactivate without deleting
DeleteRemove from system
Assign TrainingAdd training courses
Add to GroupAdd to compliance groups

Compliance Groups

Why Groups?

Groups help you:

  • Target training to specific departments
  • Scope phishing campaigns appropriately
  • Manage access reviews by team
  • Apply policies to subsets of employees

Creating Groups

  1. Navigate to PeopleGroups
  2. Click Create Group
  3. Configure:
    • Group name
    • Description
    • Member criteria
  4. Save

Group Types

TypeDescriptionExample
ManualManually assigned membersExecutive team
Rule-BasedAuto-populated by criteriaEngineering department
SyncedMirrors identity provider groupAD Security Group

Rule-Based Groups

Automatically populate groups based on:

  • Department equals "Engineering"
  • Title contains "Manager"
  • Location is "Remote"
  • Hire date within 90 days

Managing Group Members

Add Members:

  1. Open group
  2. Click Add Members
  3. Search and select employees
  4. Confirm

Remove Members:

  1. Open group
  2. Select member(s)
  3. Click Remove from Group

Tasks

Task Types

Task TypeSourceAction
Access ProvisionOnboardingGrant system access
Access RevocationOffboardingRemove system access
Access ReviewComplianceVerify access appropriateness
Training AssignmentTraining moduleComplete security training

Task Workflow

  1. Task Created

    Task is created automatically or manually.

  2. Assignment

    Task assigned to appropriate owner.

  3. Action

    Owner completes required action.

  4. Verification

    Action verified and task closed.

Managing Tasks

View Tasks:

  • Filter by status, type, assignee
  • Sort by due date or priority
  • Export task list

Complete Tasks:

  1. Open task
  2. Perform required action
  3. Add completion notes
  4. Mark complete

Sync Settings

Automatic Sync

Configure identity provider sync:

SettingOptions
FrequencyHourly, Daily, Weekly
ScopeAll users, specific groups
ActionsCreate, update, disable
NotificationsSync status alerts

Sync History

View past syncs:

  • Sync timestamp
  • Users added/updated/removed
  • Errors encountered
  • Sync duration

Conflict Resolution

When sync conflicts occur:

  • Identity Provider Wins - IdP data overwrites
  • Bastion Wins - Keep Bastion data
  • Manual Review - Flag for review

Offboarding

Automated Offboarding

When employees leave:

  1. Identity provider sync detects removal
  2. Employee marked for offboarding
  3. Access revocation tasks created
  4. Training assignments cleared
  5. Account disabled

Offboarding Checklist

  • Revoke system access
  • Remove from groups
  • Clear pending tasks
  • Archive employee data
  • Document offboarding date

Best Practices

Keep Directory Updated

Regular sync ensures accurate employee data. Stale data leads to security gaps.

Use Meaningful Groups

Create groups that align with how you manage security. Department-based is common.

Close Tasks Promptly

Unactioned access tasks are security risks. Set SLAs and monitor completion.

Audit Regularly

Review group memberships and access periodically to catch errors.

Next Steps