Manage Tenant
Manage Tenant
The Manage Tenant area is the central administration area of the AppNavi Portal. Use it to manage tenant-wide settings, applications, users, workspaces, contracts, authentication, Discovery, APIs, and other tenant-level features.
This page helps you understand what each administration area is used for, what you need before configuring it, and where to find the detailed configuration guide.
Important: The options available in Manage Tenant depend on your role, tenant configuration, and the features enabled for your tenant.
Required Role
You need the Tenant Owner role to manage tenant-level configuration and perform administrative tasks across the tenant.
Some administration functions can also be performed by users with Workspace Owner permissions. The permissions available to Workspace Owners depend on the workspace and the operation being performed.
For example:
- Tenant Owner can manage tenant-wide settings and create workspaces.
- Workspace Owner can administer users according to their assigned permissions.
- Workspace roles control access to workspace content and functionality.
- A user can belong to multiple workspaces and have a different role in each workspace.
If you cannot see a Manage Tenant option or cannot perform an operation, first check your assigned role and permissions.
Prerequisites
Before configuring your tenant, make sure that:
- You can sign in to the AppNavi Portal.
- You have the required Tenant Owner or applicable administrative permissions.
- Your AppNavi tenant is active.
- The feature you want to configure is available for your tenant.
- Any external services required by the feature are already prepared.
Some configurations require information from another system.
For example, configuring Single Sign-On requires an application to be registered with your Identity Provider and requires information such as the Client ID, Client Secret, redirect URI, and required scopes.
Manage Tenant Overview
Open Manage Tenant from the left navigation menu.
The available administration areas can include:
- Settings
- Applications
- Users
- Workspaces
- Contracts
- Discovery Settings
- Client API
- OAuth
- AI Settings
- Profile
The exact tabs displayed can vary depending on your tenant configuration and enabled features. The Manage Tenant area was introduced to centralize tenant-related administration in one location.
Administration Areas
Use the following overview to determine where to perform a specific administration task.
| Area | Purpose | Typical use |
|---|---|---|
| Settings | Configure tenant-wide behavior | Authentication, security, AI, Discovery, Client API, notifications |
| Applications | Manage applications configured in the tenant | Create, edit, and manage applications |
| Users | Manage users and their access | Add users, invitations, passwords, MFA |
| Workspaces | Organize content and permissions | Create workspaces and assign roles |
| Contracts | View contracts available to the tenant | Review contract details and assigned applications |
| Discovery Settings | Configure App Discovery | Enable Discovery and select its data source |
| Client API | Manage API clients | Create API credentials and assign permissions |
| OAuth | Configure Portal and Avatar SSO | Enter Identity Provider configuration |
| AI Settings | Configure tenant-level AI functionality | Enable available AI features |
| Profile | Manage your own account | Personal account settings |
Settings
Use Settings to configure functionality that applies at the tenant level.
Settings are grouped into logical sections so that related configuration can be managed together.
Basic Settings
Basic settings can include:
- Expert Mode — Allows advanced users to write custom code within applications.
- Organizational Unit — Enables organizational units for reporting and management.
- Client API — Enables the Client API configuration.
- Currency — Defines the currency used by supported financial or transactional features.
The default currency is EUR.
AI Settings
Use AI settings to enable available AI functionality for the tenant.
The available options depend on the AI features enabled for your tenant.
Authentication Settings
Authentication settings control how users authenticate and how tenant access is secured.
Available settings include:
- Multi-Factor Authentication
- Auto Logout
- Domain Restrictions
- Identity Connect
- Single Sign-On
- Authentication Provider
- Authorization, Token, and UserInfo URIs
- Scopes and Claim Fields
- Client ID and Interactive Mode
- Issuer URL
- Client Secret
- Authentication Context Class Reference
Some settings apply to Portal and Avatar authentication, while Identity Connect is used with the AppNavi Chromium extension.
Guidance Settings
Guidance settings can include:
- Enable Content Import
- Content Providers
Content Import allows supported content from external providers to be imported into the Guidance module.
Discovery Settings
Use Discovery Settings to enable App Discovery and select the source used to collect discovery data.
Available data sources include:
- Extension
- Defender API
Additional Discovery configuration becomes available when App Discovery is enabled.
Email Notifications
You can configure email recipients for different types of tenant notifications.
Available notification groups include:
- Release and Update Notification Emails
- Legal Communication Emails
- Security and Data Protection Contacts
Up to five email addresses can be entered for each notification group.
Configuring Tenant Settings
To change a tenant-level setting:
- Open Manage Tenant.
- Select Settings.
- Locate the required configuration section.
- Enable, disable, or update the required setting.
- Enter any additional information required by the setting.
- Click Save Changes.
- Verify that the saved value or setting is displayed correctly.
- Test the affected functionality if the change affects authentication, application behavior, or another user-facing feature.
Tip: Some settings expose additional configuration areas only after they are enabled.
For example, enabling Client API makes the Client API tab available.
Applications
Use the Applications tab to manage the applications configured for your tenant.
Applications are the containers in which AppNavi functionality such as avatars, routes, and other application-specific content is configured.
The Applications list provides information such as:
- Application name
- Assigned workspaces
- Assigned modules
- Application status
- Application owner
The Tenant Owner can add, edit, and delete applications.
Create an Application
To create an application:
- Open Manage Tenant.
- Select Applications.
- Click the Add icon.
- Enter the required application information.
- Select the workspace.
- Enter the application URL.
- Define the URL pattern where AppNavi should appear.
- Select the application owner.
- Configure the required application options.
- Click Save Changes.
Application configuration can include the application language, avatar position, avatar visibility, code execution mode, guide size, analytics, modules, custom design, and custom code.
Application Defaults
Some application settings have predefined defaults:
| Setting | Default |
|---|---|
| Language | Browser language |
| Avatar Position | Bottom-Left |
| Avatar Visibility | Visible |
| Code Execution Mode | Dynamic |
| Avatar Guide Size | Minimized |
| Application Disabled | Disabled |
| Custom Design | Disabled |
| Custom Code | Disabled |
These defaults are documented in the application creation guide.
Users
Use the Users tab to manage users who have access to the AppNavi Portal.
Users with Tenant Owner and Workspace Owner permissions can administer users according to their assigned permissions.
You can:
- Add users
- Assign workspaces
- Assign workspace roles
- Assign Tenant Owner access
- Enable MFA when tenant MFA is enabled
- Resend invitations
- Reset passwords
- Download the user list
Add a User
To add a user:
- Open Manage Tenant.
- Select Users.
- Open the three-dot menu.
- Select Add.
- Enter the user's first name.
- Enter the user's last name.
- Enter the user's email address.
- Enter the phone number if required.
- Select the user's language.
- Select the required workspace.
- Configure Tenant Owner and MFA options if applicable.
- Click Save.
At least one workspace must be selected when creating a user.
After the user is created, AppNavi sends an email containing a confirmation link. The user must complete the registration process before accessing their account.
Workspaces
Workspaces provide a logical separation of AppNavi content and access within a tenant.
Workspace data can include:
- Routes
- News
- Learning collections
- Users
- Hotspots
- Other workspace-specific content
A user can belong to one or more workspaces and can have a different role in each workspace.
Create a Workspace
Only Tenant Owners can create workspaces.
To create a workspace:
- Open Manage Tenant.
- Select Workspaces.
- Click the + icon.
- Enter the workspace title.
- Enter a description if required.
- Click Save Changes.
Workspace Roles
Workspace permissions determine what a user can access and manage.
Available roles include:
- Tenant Owner
- Workspace Owner
- Contributor
- Translator
A user can have different roles in different workspaces.
Contracts
Use the Contracts tab to view contracts available within the tenant.
You can:
- View contracts by type.
- Search for a contract using its ID or title.
- Expand a contract to view the applications assigned to it.
- Search using the ID or title of an assigned application.
Use this area when you need to verify which applications are associated with a contract.
Discovery Settings
Use Discovery Settings to configure App Discovery for the tenant.
App Discovery helps identify frequently used web applications that do not yet have an AppNavi application configured.
Enable App Discovery
To enable App Discovery:
- Open Manage Tenant.
- Select Discovery Settings.
- Enable App Discovery.
- Select the required data source.
- Configure any additional Discovery settings that become available.
- Save the changes.
Available data sources include:
- Extension
- Defender API
When App Discovery recording is enabled, additional Discovery options become available.
Client API
Use Client API when an external system needs to access AppNavi data through the Public API.
Prerequisite
The Client API setting must first be enabled under Manage Tenant → Settings.
Enable Client API
- Open Manage Tenant.
- Select Settings.
- Locate the Client API setting.
- Enable it.
- Click Save Changes.
- Open the new Client API tab.
The Client API tab becomes available after Client API is enabled.
Create an API Client
- Open the Client API tab.
- Open the three-dot menu.
- Select Add.
- Enter a meaningful title.
- Enter a description.
- Select the modules and API permissions required by the client.
- Click Create.
- Copy the generated Client ID and Client Secret.
- Store the Client Secret securely.
The Client Secret is displayed only once. If it is lost, a new API client must be created. A tenant can create up to five API clients.
Security Consideration
Treat the Client Secret as a sensitive credential.
Do not store it in source code, public documentation, screenshots, or other locations where unauthorized users could access it.
Getting Started with Public API
OAuth
Use the OAuth tab to configure Single Sign-On for the AppNavi Portal and Avatar.
The OAuth configuration becomes available after Enable Single Sign-On (SSO) is enabled in Manage Tenant → Settings.
Prerequisites
Before configuring SSO, make sure that:
- You have Tenant Owner or Tenant Admin access.
- Your AppNavi tenant is active.
- An application has been registered with your Identity Provider.
- You have the required Client ID.
- You have the required Client Secret.
- You have the required redirect or callback URI.
- You have the required scopes.
- You have the required Identity Provider endpoints.
Supported Identity Providers documented by AppNavi include Microsoft Entra ID and Okta.
Configure SSO
- Open Manage Tenant.
- Select Settings.
- Open the Authentication section.
- Enable Single Sign-On.
- Click Save Changes.
- Open the newly available OAuth tab.
- Enter the required Identity Provider information.
- Save the configuration.
- Test the SSO login flow.
The required configuration can include:
- Callback URI
- Authorization URI
- Token URI
- UserInfo URI
- Issuer
- Client ID
- Client Secret
- Scopes
- Authentication settings
- Claim fields
The exact values must come from your Identity Provider configuration.
Validate SSO
After configuring SSO:
- Open the AppNavi login page.
- Select Login with SSO.
- Complete authentication with your Identity Provider.
- Confirm that you are redirected back to AppNavi.
- Confirm that you are logged in successfully.
AI Settings
Use AI Settings to configure AI functionality available at the tenant level.
The available options depend on the AI features enabled for your tenant.
Before enabling an AI feature, review the related feature documentation to understand:
- What data is used.
- Which users can access the feature.
- Whether additional configuration is required.
- How the feature affects the tenant.
Profile
Use Profile to manage settings related to your own AppNavi user account.
Profile changes apply to your individual account and do not change tenant-wide configuration.
Defaults and Configuration Behavior
Some Manage Tenant settings have documented default values.
Examples include:
| Configuration | Default / Initial State |
|---|---|
| Currency | EUR |
| MFA | Disabled until activated |
| Auto Logout | Configured through Authentication settings |
| Domain Restrictions | Disabled until configured |
| Client API | Disabled until enabled |
| App Discovery | Disabled until enabled |
| Single Sign-On | Disabled until enabled |
| Application Custom Design | Disabled |
| Application Custom Code | Disabled |
Not every setting has a fixed default value. Where a setting does not have a documented default, configure it according to your organization's requirements.
Configuration Dependencies
Some administration areas become available only after another setting has been enabled.
| Feature | Prerequisite |
|---|---|
| OAuth | Enable Single Sign-On in Settings |
| Client API | Enable Client API in Settings |
| User MFA | Enable MFA at tenant level |
| Additional Discovery settings | Enable App Discovery |
| Application Custom Design | Enable Custom Design for the application |
| Application Custom Code | Enable Custom Code for the application |
For example, enabling Client API creates the Client API tab, where API clients can then be created and managed.
Similarly, enabling Single Sign-On makes the OAuth tab available for Identity Provider configuration.
Security Considerations
Manage Tenant contains settings that can affect authentication, authorization, application access, and external integrations.
Consider the following before making changes:
Authentication
Changes to MFA, SSO, Identity Connect, or other authentication settings can affect how users sign in.
Test authentication changes with an appropriate administrator account before applying them broadly.
Domain Restrictions
Domain restrictions can limit which email domains are permitted to access or create users.
Verify the required domains before saving the configuration.
API Credentials
Client Secrets provide access to configured Public API permissions.
Store them securely and do not expose them in screenshots, documentation, source code, or public repositories.
Application Security
Application-level security features such as Origin Security restrict which origins can access application resources. Origin Security is configured at the application level and can define up to 10 allowed origin patterns.
External Identity Providers
When configuring SSO or Identity Connect, verify that URLs, client credentials, scopes, and claims match the configuration in your Identity Provider.
Validation
After completing a Manage Tenant configuration, validate the change before considering the configuration complete.
Use the following general validation process:
- Confirm that the configuration was saved successfully.
- Reopen the configuration and verify the saved values.
- Confirm that any dependent tab or setting is now available.
- Test the affected functionality.
- Test with an appropriate user role when permissions are involved.
- Verify that existing functionality has not been unintentionally affected.
For authentication changes, test both the intended authentication method and any existing login method that should remain available.
For application changes, open the configured application and verify that AppNavi behaves according to the selected settings.
Quick Navigation
Use this table to quickly find the administration area for a specific task.
| I want to... | Go to |
|---|---|
| Configure tenant-wide settings | Manage Tenant → Settings |
| Configure MFA | Manage Tenant → Settings → Authentication |
| Configure Auto Logout | Manage Tenant → Settings → Authentication |
| Restrict access by domain | Manage Tenant → Settings → Authentication |
| Configure Identity Connect | Manage Tenant → Settings → Authentication |
| Enable Single Sign-On | Manage Tenant → Settings → Authentication |
| Configure SSO / OAuth | Manage Tenant → OAuth |
| Enable Client API | Manage Tenant → Settings |
| Create an API client | Manage Tenant → Client API |
| Create an application | Manage Tenant → Applications |
| Edit an application | Manage Tenant → Applications |
| Manage users | Manage Tenant → Users |
| Create a workspace | Manage Tenant → Workspaces |
| Manage workspace roles | Manage Tenant → Users / Workspaces |
| Review contracts | Manage Tenant → Contracts |
| Configure App Discovery | Manage Tenant → Discovery Settings |
| Configure AI functionality | Manage Tenant → AI Settings |
| Manage your own account | Manage Tenant → Profile |
Troubleshooting
I cannot see a Manage Tenant tab
Check the following:
- Confirm that you are signed in with the required role.
- Confirm that the feature is available for your tenant.
- Check whether the feature must first be enabled in Settings.
- Refresh the AppNavi Portal after enabling a feature.
- If the option is still unavailable, contact your AppNavi administrator or support team.
A new configuration tab is not displayed
Some tabs are created only after their corresponding feature is enabled.
For example:
- Client API appears after Client API is enabled.
- OAuth appears after Single Sign-On is enabled.
- Additional Discovery options become available after App Discovery is enabled.
My configuration was saved but the behavior did not change
Check that:
- The setting was actually saved.
- The expected dependent configuration was completed.
- You refreshed the affected application or page.
- The feature is enabled for the correct application or workspace.
- Your user has the required permissions.
Related Administration Guides
Updated 11 days ago