Skip to main content
Preassignments let you decide a user’s role and permission-group memberships before they have ever signed in to Aperium — before an identity-provider subject exists for them at all. When the invited email first authenticates, Aperium matches the pending preassignment and applies the role and groups automatically. It’s the way to get new hires landing in the right place on day one. Find them under Settings › Workspace › Access › Preassignments. Once a user has signed in, manage them from Members instead.

Creating a preassignment

Open Create preassignment and fill in:
  1. Email. The address the user will sign in with. It must match the email their identity provider returns; matching is case-insensitive but otherwise exact.
  2. Role. Only member can be preassigned. Administrative roles are granted from a member’s detail page after they’ve signed in once — you cannot preassign tenant_admin or super_admin.
  3. Groups. Optionally attach one or more permission groups. The user joins them the moment they sign in.
A super admin first picks the tenant the preassignment applies to.

Statuses and lifecycle

A preassignment moves through three statuses, filterable at the top of the tab:
  • Preassignments carry an expiry (expires_at). An expired pending preassignment no longer applies on sign-in.
  • Revoke a pending preassignment to cancel it — the user no longer receives that first-login access.
  • Group memberships from a preassignment are the user’s native permission groups once consumed; edit them from the member’s detail page afterward.

Notes

  • Preassignments don’t send email. Aperium does not email the user. Tell them through your usual onboarding channel that they can sign in.
  • Revoking a consumed preassignment has no effect. Once consumed, the role and groups are part of the user’s profile; change them from Members.