
Bacularis makes it possible to manage both individual users and groups of users representing teams, departments, branch offices, or other organizational units. In this article, we present Bacularis features that make it easier to manage such groups and organize user administration.
Below are some features that can be useful when configuring team-based user management in Bacularis.
| Capability | Typical use |
|---|---|
| Organizations | Create logical groups for different types of users |
| Bulk actions | Perform a single action on a selected group of users |
| Organization authentication | Assign different authentication methods to different groups |
| Organization assignment | Automatically assign new users to an organization |
| Organization administrators | Assign full administrative access to selected users in an organization |
| Organization role mapping | Use separate role mappings for organizations using different identity providers |
Organizations are logical units used to group users.
If a company has different teams, departments, or branch offices, employees from each of them can be assigned to a dedicated Bacularis organization. This provides a natural way to group related users and keep user management organized.
| User group | Organization |
|---|---|
| Development department | DevTeam |
| Special team | SpecGroup |
| Company branch in XXX | XXX_Employees |
| Company branch in ZZZ | ZZZ_Employees |
| CTO, CEO | Directors |
| External auditors | Auditors |
Details: Organizations documentation
Organizations can use different identity providers.
For example, if a company has branch offices in different cities or countries and each branch uses a different identity provider, a separate authentication method can be assigned to each organization.
Organizations can also use the same identity provider or other authentication methods, such as LDAP or local Bacularis users.
When signing in, employees assigned to particular groups select the authentication method associated with their organization and authenticate using their organizational credentials.
This allows a single Bacularis instance to serve groups of users belonging to different identity domains or using different authentication methods.
| Organization | Authentication method |
|---|---|
| IT Department | Identity Provider XXX |
| Testing Department | Identity Provider YYY |
| Branch ABC | Local authentication / local users |
| Branch DEF | LDAP authentication |
| Project Office | Identity Provider ZZZ |
Details:
After filtering users belonging to a particular group in the Bacularis interface, the administrator can select all or some of them and perform bulk actions.
For example, the administrator can assign a role to multiple users at once.
Bulk actions can be used to:
Bulk actions reduce the time and effort required to modify multiple user accounts individually.
Users can be assigned to organizations in several ways.
Users of all supported types, including local users, LDAP users, and identity provider users, can be assigned to or removed from organizations by editing their accounts on the Users page or by using bulk actions.
LDAP users can also be assigned to an organization while being imported into Bacularis.
In addition, users can be assigned automatically when user provisioning is enabled. If a user does not yet have a Bacularis account, the account can be created during the first login and automatically assigned to a selected organization.
| User type | Method of assigning to or removing from an organization |
|---|---|
| All user types | Edit the user account |
| All user types | Bulk action to add users to or remove users from an organization |
| LDAP users | Assign to an organization during LDAP user import |
| Identity provider and LDAP users | Automatically assign to an organization during first login |
Details: User provisioning documentation
Administrator accounts can be assigned within individual organizations.
These users are given roles that provide full administrative access to Bacularis. This makes it possible to have administrators associated with particular groups while still providing them with full access to Bacularis administrative functions.
Organization administrators are not restricted to managing only their own organization. Administrative roles provide access according to the permissions assigned to those roles.
If Bacularis organizations use authentication through identity providers, separate role mappings can be configured for each organization.
This makes it possible to use roles provided by an identity provider and map them to local Bacularis roles.
Each organization can independently map roles from its own IAM system to the local Bacularis role model.
| Organization | IAM role | Bacularis role |
|---|---|---|
| Dev Team | developers | devs |
| Support Team | support_team | support |
| Finance Team | finance_dep | finance, adm |
Details: Role mapping documentation
| Scenario | Organization model | Access model |
|---|---|---|
| Central IT + branch offices | Separate organization per office | Central administrators + limited local users |
| University departments | Organization per department | Shared or separate identity providers |
| Security/audit team | Dedicated auditor organization | Read-only access |
In this scenario, administrators from the central IT department can manage Bacularis with full access. They belong to an Administrators organization.
Employees working in branch offices belong to separate organizations such as Office 1A, Office 2B, Office 100, and others.
Their accounts can have limited access to selected Bacula resources, allowing them to sign in to Bacularis and access only the data associated with their own computers.
This enables users to restore their own data on demand without gaining access to the data of other employees.
Employees of individual university departments can belong to separate Bacularis organizations and use either the same identity provider or different identity providers.
Auditors can belong to a dedicated organization that groups users who require read-only access to the Bacularis interface.
This helps keep user management organized and separates auditor accounts from other users.
| Organization feature | What it controls |
|---|---|
| Organizations | Logical grouping of users |
| Authentication assignment | Authentication method used by a group |
| User provisioning | Automatic account and organization assignment |
| Bulk actions | Changes applied to multiple users |
| Organization role mapping | IAM-to-Bacularis role mapping per organization |
| Organization administrators | Full administrative access for selected users |
Organizations in Bacularis make it possible to reflect company teams, departments, and branch offices in the Bacularis user management structure.
Each organization can use its own authentication methods and role mappings, while users can be assigned manually, through bulk actions, or automatically during provisioning.
These features make it easier to manage larger numbers of users and keep user accounts organized into logical groups.
⇒ Part 1: Authentication and access control