Manage security identities
Manage security identities
- Prerequisites
- Browse security identities
- Refresh a security identity provider
- Review additional statistics
- Review global statistics
- Review the activity regarding security identities
- Download security identity provider update logs
- Troubleshoot missing content for a user
- Security identity state reference
- Edit a security identity provider
- Project association prompts
- Required privileges
- What’s next
The Security Identities (platform-ca | platform-eu | platform-au) page lets you review security identity refreshes and manage when they occur (typically daily).
Your Coveo organization maintains lists of relationships between all the security identities (users and groups) for all indexed systems. See Coveo management of security identities and item permissions for more information. When a user performs a query, Coveo refers to these lists to instantly determine the user’s permissions and return only items the user is allowed to see.
The Security Identities (platform-ca | platform-eu | platform-au) page shows a list of the security identity providers used by the sources that index permissions to replicate each repository’s permission system.
The table also indicates:
-
Type: This refers to the security provider type, which often matches your source connector. It also indicates the number of associated sources.
-
Name: This is the display name of the security identity provider, with the provider ID listed underneath.
-
Status: This indicates the status of the security identity provider, including the progress of the refresh operation, the outcome of the last refresh attempt, the date, and the number of processed identities.
-
Content: This shows the number of identities maintained for this security identity provider and the number of these identities that are in error.
Prerequisites
-
At least one of your sources indexes permissions, so Coveo maintains security identities that replicate the repository’s permission system. For more information, see Coveo management of security identities and item permissions.
-
You have the required privileges to view or edit security identities.
Browse security identities
To view a list of all security identities managed by a provider, on the Security Identities (platform-ca | platform-eu | platform-au) page, select the desired security identity provider, and then click Browse identities in the Action bar. See Browse security identities for details on this list.
Alternatively, when encountering access issues with a specific item or user, you can go to the Content Browser (platform-ca | platform-eu | platform-au) to inspect the security identities at play.
Refresh a security identity provider
You can manually refresh a specific security identity, or refresh all security identities at once.
Ensure however that the desired security identity is also automatically updated following a manual update. See Configure security identity refresh schedules for more information.
Manually refresh a specific security identity
To manually refresh a security identity, select the desired security identity provider on the Security Identities (platform-ca | platform-eu | platform-au) page, and then click Browse identities in the Action bar. Next, on the Browse security identities subpage, select the desired identity, and then, click Refresh now in the Action bar.
The Activity panel showcases details regarding the update process.
A manual refresh of a specific security identity is useful when you encounter issues with a specific identity. See Security identity state reference for details. You can also perform a manual refresh to ensure that important security identity changes made in a system are taken into account in your searchable content.
See Browse security identities for details on this subpage.
Refresh all security identities
On the Security Identities (platform-ca | platform-eu | platform-au) page, click Refresh all to refresh all security identity providers at once.
This is useful when you know important security identity changes were made in several systems and want to ensure that they’re now taken into account in your searchable content.
Configure security identity refresh schedules
You can configure refresh schedules for a security identity provider. The security identities in this provider are then updated automatically on a regular basis, and may only require a manually triggered refresh when in error.
-
On the Security Identities (platform-ca | platform-eu | platform-au) page, click the desired security provider, and then in the More menu, select Schedule automatic operations.
-
In the Schedule automatic operations panel, select a recurrence and time of day for each operation.
-
Click Save. Changes are effective immediately.
Review additional statistics
On the Security Identities (platform-ca | platform-eu | platform-au) page, click the security identity provider for which you want to view the associated sources, and then click More > View additional statistics in the Action bar.
In the panel that appears, on the left side, you can review statistics regarding the identities associated to this provider. See Security identity state reference for details. On the right, you can review the name, ID, and type of the sources using this security identity provider.
Review global statistics
On the Security Identities (platform-ca | platform-eu | platform-au) page, click to view security identity cache statistics.
In the Global stats: security identity cache panel, on the left side, you can review: the total number of security identity Providers and security Identities in this organization.
On the right, under Number of Identities by State, you can review how many identities are in each state. See Security identity state reference for more information.
Review the activity regarding security identities
As part of your duties, you may need to review activities related to security identities for investigation or troubleshooting purposes.
To do so, in the upper-right corner of the Security Identities (platform-ca | platform-eu | platform-au) page, click .
See Review resource activity for details on activities and alternative ways to access this information.
|
|
Note
Since disabled security identities aren’t processed, you might notice a difference between the Number of entities processed and the Total number of entities in the activity details. See Security identity state reference for details. In such case, rebuild the sources that use the identity provider. A disabled identity is re-enabled when:
|
Download security identity provider update logs
Should you need more information about an ongoing or completed security provider update operation, you can download logs of the desired activity. Log files provide a detailed account of the update process, including any warning or error that hinders part or all the update operation.
Information in update logs is nonsensitive.
To download an update log
-
On the Security Identities (platform-ca | platform-eu | platform-au) page, click the desired resource, and then click Activity in the Action bar.
-
In the Activity panel that opens, click the desired activity, and then click Download logs in the Action bar. The downloaded file is named after the unique operation ID representing the selected activity.
|
|
Note
For Crawling Module security providers, you can also download the resource’s full activity logs. |
See Ways to review activity for alternative ways to access this information.
Troubleshoot missing content for a user
Symptoms
A user can’t see search results they should have access to, or content is missing for one user while other users see the expected items.
Cause
Coveo filters items at query time based on the user’s security identity and each item’s permissions. Content is filtered out when the user’s identity isn’t allowed on the item, the identity isn’t resolved, the permission model is incomplete, or the identity is In error or Out of date. A source permission change can also be missing from the index.
Solution
Before making any adjustments, complete the following steps:
-
In the Content Browser (platform-ca | platform-eu | platform-au), inspect the item’s permissions to confirm whether the user’s security identity is allowed on the item and resolved.
-
On the Security Identities (platform-ca | platform-eu | platform-au) page, check the identity’s state and last update result. An incomplete permission model, or an identity that’s In error or Out of date, is a common cause of content being filtered out.
-
Manually refresh the identity, and confirm a refresh schedule keeps it current.
-
If a source permission change still isn’t reflected, rebuild the source and refresh the identity.
Permission-only changes don’t always update an item’s modification date and a refresh or rescan can skip the item.
Security identity state reference
Depending on the success of their update, security identities are flagged with one of the following states: Not updated, In error, Out of date, Disabled, and Up to date.
For additional information on an identity that isn’t up to date, go to the Item Properties panel, in the Permissions and Permission details tabs. See Review item properties for more information.
Edit a security identity provider
You can inspect and edit all security identity provider parameters from the JSON configuration, typically following instructions from the Coveo Support team.
-
On the Security Identities (platform-ca | platform-eu | platform-au) page, click the security identity provider for which you want to review or change the JSON configuration, and then click More > Edit JSON in the Action bar.
-
In the Edit a security identity provider JSON configuration panel:
-
Copy and save the original content somewhere so you can restore the configuration to its original state if your changes lead to issues.
-
Review or adjust the configuration as needed.
-
Click Save.
-
-
If you made changes, validate they perform as expected.
Project association prompts
A security identity provider is a resource you can associate with a project. Resources associated with a project can require confirmation when you modify them. These confirmation prompts help prevent accidental changes that could affect a Coveo implementation.
Required privileges
The following table indicates the privileges required to view or edit elements of the Security Identities (platform-ca | platform-eu | platform-au) page and associated panels. See Manage privileges and Privilege reference for details.
|
|
A member with the View access level on the Activities domain can access the Activity Browser. This member can therefore see all activities taking place in the organization, including those from Coveo Administration Console pages that they can’t access. |
| Action | Service | Domain | Required access level |
|---|---|---|---|
View security identity providers, browse identities and relationships, and view stats |
Content |
Security identities |
View |
Security identity providers |
View |
||
Organization |
Activities |
View |
|
Organization |
View |
||
Refresh security identity providers and edit provider JSON |
Content |
Security identities |
Edit |
Security identity providers |
Edit |
||
Organization |
Activities |
View |
|
Organization |
View |
||
Access the Activity Browser and view all organization activities |
Organization |
Activities |
View |
Organization |
View |
||
Content |
Connectivity diagnostic logs |
View |
|
Organization |
Activities |
View |
|
Organization |
View |
What’s next
-
Coveo management of security identities and item permissions to understand how Coveo resolves permissions at query time.
-
Review item properties to inspect the permissions applied to a specific item.
-
Refresh, rescan, and rebuild to update source content and permissions.