This document describes the integration between eADM Acos Websak. The integration automates user account management in Acos Websak by synchronizing user and role information from eADM.
Overview
When an employee is granted access to Acos Websak, a user account is automatically created. This account is continuously updated and will be deactivated when the employee's employment ends. Roles within Acos Websak can also be managed automatically through rule sets defined in eADM assigned by a department manager. Additionally, the integration can maintain the organizational hierarchy in Acos Websak using data imported into eADM the organization's HR system.
Note: When users or departments are removed from the HR system, their corresponding entries in Acos Websak are deactivated, not permanently deleted. An account cannot be deleted from Acos until all cases and records associated with the user have been removed.
Pre-configuration
Before Identum can set up the integration, you must complete the following preparatory steps in collaboration with Acos.
1. Order the integration from Acos
You must first contact the Acos marketing department to request the integration and have them create the necessary "template users." These template users are used to assign system access to different roles, such as Archivist, Committee Secretary, Manager, or Case Officer.
When placing an order, ask Acos to provide the GIDs (unique IDs) for the template users they create. These IDs are essential for the integration.
To request the integration, please contact the following staff members at Acos:
-
Lene Hellesøy: lene@acos.no, Tel: 93 21 87 28
-
Eivind Svellingen: es@acos.no, Tel: 92 26 22 20
For information on the status of an existing order, please contact:
-
Asle Brakstad: asle@acos.no, Tel: 46 42 05 07
2. Obtain API credentials from Acos
Acos will provide you with the following API credentials required for the integration.
|
More information |
Value |
Description |
|---|---|---|
|
API URL |
[Customer-Specific] |
The URL for your organization's API endpoint. Example: |
|
Customer ID |
[Provided by Acos] |
The ID of the API user. This is often the same as the Scope. |
|
Customer Secret |
[Provided by Acos] |
The password for the API user. |
|
Scope |
|
The identifier for the API to be used. This is typically |
|
Top Node ID |
[Provided by Acos] |
The ID of the top-level node in your Acos organizational hierarchy |
Note: In some configurations, the Client ID and Client Secret may have the same value.
3. Prepare Existing Data in Acos Websak
To ensure successful synchronization, you must align existing user and department data in Acos Websak with the data in eADM.
Link Existing Users
To link users from the HR system to their existing accounts in Acos Websak, they must have the same username or email address. Make sure that the email address and/or username in Acos Websak matches the user's primary work email in eADM.
Warning: If this alignment is not performed correctly, the integration will create duplicate user accounts.
Link to Existing Departments
To link departments in the HR system with their corresponding departments in Acos Websak, they must share a unique ID. This is typically the department number found in eADM. You must enter this number into the department ID field for the corresponding department in Acos.
Warning: If this alignment is not performed correctly, the integration will create duplicate departments.
Configuration
Once the pre-configuration steps are complete, Identum will complete the setup.
1. Define Role Assignment Rules
You need to define the rules that determine which employees are automatically assigned a specific role or template user in Acos. Based on your requirements, Identum will create the necessary access control rules.
Note: These rules do not need to be finalized in advance. We can establish them together during a workshop.
2. Notify Identum
Once all the preparatory steps have been completed, please notify Identum. We will then proceed with the final configuration and activation of the integration.
Advanced Configuration (Optional) - Linking Multiple eAdm to a Single Acos Department
This type of configuration should generally be avoided, and a 1:1 department mapping is recommended.
If necessary, multiple departments in eAdm be mapped to a single department in Acos. To do this, enter the eAdm numbers into the department ID field in Acos, separated by a pipe character (|).
Example: 6705|5794|6347 With this configuration, all user data from departments 6705, 5794, and 6347 in eAdm be synchronized to the corresponding department in Acos.