eADM

Acos Websak

This document describes the integration between eADM Acos Websak. The integration automates user account management in Acos Websak by synchronizing user and role information from eADM.



Overview

When an employee is granted access to Acos Websak, a user account is automatically created. This account is continuously updated and will be deactivated when the employee's employment ends. Roles within Acos Websak can also be managed automatically through rule sets defined in eADM assigned by a department manager. Additionally, the integration can maintain the organizational hierarchy in Acos Websak using data imported into eADM the organization's HR system.


Note: When users or departments are removed from the HR system, their corresponding entries in Acos Websak are deactivated, not permanently deleted. An account cannot be deleted from Acos until all cases and records associated with the user have been removed.



Pre-configuration

Before Identum can set up the integration, you must complete the following preparatory steps in collaboration with Acos.


1. Order the integration from Acos

You must first contact the Acos marketing department to request the integration and have them create the necessary "template users." These template users are used to assign system access to different roles, such as Archivist, Committee Secretary, Manager, or Case Officer.

When placing an order, ask Acos to provide the GIDs (unique IDs) for the template users they create. These IDs are essential for the integration.


To request the integration, please contact the following staff members at Acos:

For information on the status of an existing order, please contact:


2. Obtain API credentials from Acos

Acos will provide you with the following API credentials required for the integration.

More information

Value

Description

API URL

[Customer-Specific]

The URL for your organization's API endpoint. Example: https://integrasjoner.customer.acossky.no/

Customer ID

[Provided by Acos]

The ID of the API user. This is often the same as the Scope.

Customer Secret

[Provided by Acos]

The password for the API user.

Scope

userApi

The identifier for the API to be used. This is typically userApi.

Top Node ID

[Provided by Acos]

The ID of the top-level node in your Acos organizational hierarchy


Note: In some configurations, the Client ID and Client Secret may have the same value.


3. Prepare Existing Data in Acos Websak

To ensure successful synchronization, you must align existing user and department data in Acos Websak with the data in eADM.


To link users from the HR system to their existing accounts in Acos Websak, they must have the same username or email address. Make sure that the email address and/or username in Acos Websak matches the user's primary work email in eADM.


Warning: If this alignment is not performed correctly, the integration will create duplicate user accounts.


To link departments in the HR system with their corresponding departments in Acos Websak, they must share a unique ID. This is typically the department number found in eADM. You must enter this number into the department ID field for the corresponding department in Acos.


Warning: If this alignment is not performed correctly, the integration will create duplicate departments.



Configuration

Once the pre-configuration steps are complete, Identum will complete the setup.


1. Define Role Assignment Rules

You need to define the rules that determine which employees are automatically assigned a specific role or template user in Acos. Based on your requirements, Identum will create the necessary access control rules.


Note: These rules do not need to be finalized in advance. We can establish them together during a workshop.


2. Notify Identum

Once all the preparatory steps have been completed, please notify Identum. We will then proceed with the final configuration and activation of the integration.



Advanced Configuration (Optional) - Linking Multiple eAdm to a Single Acos Department

This type of configuration should generally be avoided, and a 1:1 department mapping is recommended.

If necessary, multiple departments in eAdm be mapped to a single department in Acos. To do this, enter the eAdm numbers into the department ID field in Acos, separated by a pipe character (|).


Example: 6705|5794|6347 With this configuration, all user data from departments 6705, 5794, and 6347 in eAdm be synchronized to the corresponding department in Acos.