Members and roles¶
Authentication and sign-in roles are managed through the configured identity provider. In the default deployment, OpenCrowd uses Keycloak.
When creating or updating a member:
- Confirm the correct environment and realm.
- Verify the person’s identity and business need.
- Assign the minimum role required.
- Avoid using shared administrator accounts.
- Review elevated access periodically and remove it promptly when no longer required.
The manage_connectors role provides broad administrative capabilities. Assign it only to staff responsible for application connections and governance operations.