Skip to main content

People Management

Overview​

The People section is your central employee directory for security management. Import employees from identity providers, organize them into groups, and track security-related tasks.

Tabs Overview​

TabPurpose
UsersEmployee directory and management
GroupsCompliance groups for training and campaigns
TasksAccess management and onboarding tasks

Users​

Employee Directory​

View all employees with:

  • Name and email
  • Department and title
  • Group memberships
  • Training status
  • Last activity

Importing Employees​

From Identity Provider​

  1. Navigate to Employees → People
  2. Click Import Users
  3. Select your identity integration:
    • Azure Active Directory
    • Google Workspace
  4. Configure import settings:
    • Include/exclude groups
    • Sync frequency
    • Attribute mapping
  5. Confirm import

Manual Import​

For employees not in your identity provider:

  1. Click Add User
  2. Enter employee details:
    • Name
    • Email
    • Department
    • Title
  3. Save

CSV Import​

For bulk manual import:

  1. Click Import → CSV
  2. Download template
  3. Fill in employee data
  4. Upload completed CSV
  5. Review and confirm

Employee Details​

Click on an employee to view:

  • Profile - Contact information
  • Groups - Group memberships
  • Training - Assigned and completed training
  • Phishing - Phishing campaign results
  • Tasks - Assigned security tasks

Employee Actions​

ActionDescription
EditUpdate employee information
DisableDeactivate without deleting
DeleteRemove from system
Assign TrainingAdd training courses
Add to GroupAdd to compliance groups

Compliance Groups​

Why Groups?​

Groups help you:

  • Target training to specific departments
  • Scope phishing campaigns appropriately
  • Manage access reviews by team
  • Apply policies to subsets of employees

Creating Groups​

  1. Navigate to People → Groups
  2. Click Create Group
  3. Configure:
    • Group name
    • Description
    • Member criteria
  4. Save

Group Types​

TypeDescriptionExample
ManualManually assigned membersExecutive team
Rule-BasedAuto-populated by criteriaEngineering department
SyncedMirrors identity provider groupAD Security Group

Rule-Based Groups​

Automatically populate groups based on:

  • Department equals "Engineering"
  • Title contains "Manager"
  • Location is "Remote"
  • Hire date within 90 days

Managing Group Members​

Add Members:

  1. Open group
  2. Click Add Members
  3. Search and select employees
  4. Confirm

Remove Members:

  1. Open group
  2. Select member(s)
  3. Click Remove from Group

Tasks​

Task Types​

Task TypeSourceAction
Access ProvisionOnboardingGrant system access
Access RevocationOffboardingRemove system access
Access ReviewComplianceVerify access appropriateness
Training AssignmentTraining moduleComplete security training

Task Workflow​

  1. Task Created

    Task is created automatically or manually.

  2. Assignment

    Task assigned to appropriate owner.

  3. Action

    Owner completes required action.

  4. Verification

    Action verified and task closed.

Managing Tasks​

View Tasks:

  • Filter by status, type, assignee
  • Sort by due date or priority
  • Export task list

Complete Tasks:

  1. Open task
  2. Perform required action
  3. Add completion notes
  4. Mark complete

Sync Settings​

Automatic Sync​

Configure identity provider sync:

SettingOptions
FrequencyHourly, Daily, Weekly
ScopeAll users, specific groups
ActionsCreate, update, disable
NotificationsSync status alerts

Sync History​

View past syncs:

  • Sync timestamp
  • Users added/updated/removed
  • Errors encountered
  • Sync duration

Conflict Resolution​

When sync conflicts occur:

  • Identity Provider Wins - IdP data overwrites
  • Bastion Wins - Keep Bastion data
  • Manual Review - Flag for review

Offboarding​

Automated Offboarding​

When employees leave:

  1. Identity provider sync detects removal
  2. Employee marked for offboarding
  3. Access revocation tasks created
  4. Training assignments cleared
  5. Account disabled

Offboarding Checklist​

  • Revoke system access
  • Remove from groups
  • Clear pending tasks
  • Archive employee data
  • Document offboarding date

Best Practices​

Keep Directory Updated

Regular sync ensures accurate employee data. Stale data leads to security gaps.

Use Meaningful Groups

Create groups that align with how you manage security. Department-based is common.

Close Tasks Promptly

Unactioned access tasks are security risks. Set SLAs and monitor completion.

Audit Regularly

Review group memberships and access periodically to catch errors.

Next Steps​