Skip to main content

Manage users and service accounts

Two kinds of principal can act in Creatio AI Studio. A user is a person. A service account is a non-human principal that lets a runtime, an integration, or a deployment pipeline authenticate without anyone's login.

Both get their capabilities from roles. Learn more: Create a role and assign permissions.

Manage users​

  1. Go to the Security section under Administration in the navigation panel.

  2. Open the Users tab. Each row shows the email, full name, and last login.

  3. Open a user to review their access.

    • The Roles tab lists the roles the user holds, each with its source, for example, "Administrators group" for one inherited rather than assigned directly. Click Assign to add a role.
    • The Permissions tab lists what those roles grant, with the source of each.

As a result, you can see exactly why a user can do something — and which role to change if they should not.

The user page Actions menu carries Edit, to change the user's details, and Finish session, which ends the user's Creatio AI Studio session. Their Identity Platform session stays active.

note

If group-derived sources are not displayed, your Identity Platform account lacks the user management permission. The roles are still applied — you simply cannot see which group supplied them from this page.

Create a service account​

  1. Open the Security section and go to the Service Accounts tab.
  2. Click New. This opens the "Create service account" dialog.
  3. Enter a name. Name it after what uses it, because the name is the only description the account carries.
  4. Set Expires at, if the account should stop working on a date.
  5. Select the Environment, if the account should act in one specific environment.
  6. Click Save.

As a result, Creatio AI Studio creates the account. Give it an API key so it can authenticate, and a role so it can do something once it has. Its page also carries Permissions, which lists what its roles grant, and OAuth clients.

Create an API key for a service account​

  1. Open the service account from the Service Accounts tab.
  2. Go to the API keys tab and click Create key. This opens the "Create API key" dialog.
  3. Set the expiration date in the Expiration date field. Leave it empty for a key that never expires.
  4. Click Create key.

As a result, Creatio AI Studio generates the key and shows it once, in the "New API key" dialog.

Important

The key secret is shown only immediately after you create it and never again. Copy and store it securely before closing the dialog. If you lose it, revoke the key and create a new one.

To withdraw a key, select its row on the API keys tab, click Revoke, and confirm in the "Revoke keys?" dialog. The key's status becomes "Revoked."

Grant a role to a service account​

A service account with an API key can authenticate, but with no role it can do nothing once it has.

  1. Open the service account from the Service Accounts tab.
  2. Go to the Roles tab.
  3. Click Assign.
  4. Select the role that carries the permissions the account needs.

As a result, the service account holds the role and can act within its permissions.

You can work from the other side instead: open the role, go to its Principals tab, click Assign, and pick the account on the Service Accounts tab. Either route produces the same assignment, and neither takes a scope — a role applies to everything it covers. Learn more: Create a role and assign permissions.


See also​

Create a role and assign permissions

Start an agent with a trigger

Creatio AI Studio overview