Manage Tenant

Manage Tenant

The Manage Tenant area is the central administration area of the AppNavi Portal. Use it to manage tenant-wide settings, applications, users, workspaces, contracts, authentication, Discovery, APIs, and other tenant-level features.

This page helps you understand what each administration area is used for, what you need before configuring it, and where to find the detailed configuration guide.

Important: The options available in Manage Tenant depend on your role, tenant configuration, and the features enabled for your tenant.


Required Role

You need the Tenant Owner role to manage tenant-level configuration and perform administrative tasks across the tenant.

Some administration functions can also be performed by users with Workspace Owner permissions. The permissions available to Workspace Owners depend on the workspace and the operation being performed.

For example:

  • Tenant Owner can manage tenant-wide settings and create workspaces.
  • Workspace Owner can administer users according to their assigned permissions.
  • Workspace roles control access to workspace content and functionality.
  • A user can belong to multiple workspaces and have a different role in each workspace.

If you cannot see a Manage Tenant option or cannot perform an operation, first check your assigned role and permissions.


Prerequisites

Before configuring your tenant, make sure that:

  • You can sign in to the AppNavi Portal.
  • You have the required Tenant Owner or applicable administrative permissions.
  • Your AppNavi tenant is active.
  • The feature you want to configure is available for your tenant.
  • Any external services required by the feature are already prepared.

Some configurations require information from another system.

For example, configuring Single Sign-On requires an application to be registered with your Identity Provider and requires information such as the Client ID, Client Secret, redirect URI, and required scopes.


Manage Tenant Overview

Open Manage Tenant from the left navigation menu.

The available administration areas can include:

  • Settings
  • Applications
  • Users
  • Workspaces
  • Contracts
  • Discovery Settings
  • Client API
  • OAuth
  • AI Settings
  • Profile

The exact tabs displayed can vary depending on your tenant configuration and enabled features. The Manage Tenant area was introduced to centralize tenant-related administration in one location.


Administration Areas

Use the following overview to determine where to perform a specific administration task.

AreaPurposeTypical use
SettingsConfigure tenant-wide behaviorAuthentication, security, AI, Discovery, Client API, notifications
ApplicationsManage applications configured in the tenantCreate, edit, and manage applications
UsersManage users and their accessAdd users, invitations, passwords, MFA
WorkspacesOrganize content and permissionsCreate workspaces and assign roles
ContractsView contracts available to the tenantReview contract details and assigned applications
Discovery SettingsConfigure App DiscoveryEnable Discovery and select its data source
Client APIManage API clientsCreate API credentials and assign permissions
OAuthConfigure Portal and Avatar SSOEnter Identity Provider configuration
AI SettingsConfigure tenant-level AI functionalityEnable available AI features
ProfileManage your own accountPersonal account settings

Settings

Use Settings to configure functionality that applies at the tenant level.

Settings are grouped into logical sections so that related configuration can be managed together.

Basic Settings

Basic settings can include:

  • Expert Mode — Allows advanced users to write custom code within applications.
  • Organizational Unit — Enables organizational units for reporting and management.
  • Client API — Enables the Client API configuration.
  • Currency — Defines the currency used by supported financial or transactional features.

The default currency is EUR.

AI Settings

Use AI settings to enable available AI functionality for the tenant.

The available options depend on the AI features enabled for your tenant.

Authentication Settings

Authentication settings control how users authenticate and how tenant access is secured.

Available settings include:

  • Multi-Factor Authentication
  • Auto Logout
  • Domain Restrictions
  • Identity Connect
  • Single Sign-On
  • Authentication Provider
  • Authorization, Token, and UserInfo URIs
  • Scopes and Claim Fields
  • Client ID and Interactive Mode
  • Issuer URL
  • Client Secret
  • Authentication Context Class Reference

Some settings apply to Portal and Avatar authentication, while Identity Connect is used with the AppNavi Chromium extension.

Guidance Settings

Guidance settings can include:

  • Enable Content Import
  • Content Providers

Content Import allows supported content from external providers to be imported into the Guidance module.

Discovery Settings

Use Discovery Settings to enable App Discovery and select the source used to collect discovery data.

Available data sources include:

  • Extension
  • Defender API

Additional Discovery configuration becomes available when App Discovery is enabled.

Email Notifications

You can configure email recipients for different types of tenant notifications.

Available notification groups include:

  • Release and Update Notification Emails
  • Legal Communication Emails
  • Security and Data Protection Contacts

Up to five email addresses can be entered for each notification group.


Configuring Tenant Settings

To change a tenant-level setting:

  1. Open Manage Tenant.
  2. Select Settings.
  3. Locate the required configuration section.
  4. Enable, disable, or update the required setting.
  5. Enter any additional information required by the setting.
  6. Click Save Changes.
  7. Verify that the saved value or setting is displayed correctly.
  8. Test the affected functionality if the change affects authentication, application behavior, or another user-facing feature.

Tip: Some settings expose additional configuration areas only after they are enabled.

For example, enabling Client API makes the Client API tab available.


Applications

Use the Applications tab to manage the applications configured for your tenant.

Applications are the containers in which AppNavi functionality such as avatars, routes, and other application-specific content is configured.

The Applications list provides information such as:

  • Application name
  • Assigned workspaces
  • Assigned modules
  • Application status
  • Application owner

The Tenant Owner can add, edit, and delete applications.

Create an Application

To create an application:

  1. Open Manage Tenant.
  2. Select Applications.
  3. Click the Add icon.
  4. Enter the required application information.
  5. Select the workspace.
  6. Enter the application URL.
  7. Define the URL pattern where AppNavi should appear.
  8. Select the application owner.
  9. Configure the required application options.
  10. Click Save Changes.

Application configuration can include the application language, avatar position, avatar visibility, code execution mode, guide size, analytics, modules, custom design, and custom code.

Application Defaults

Some application settings have predefined defaults:

SettingDefault
LanguageBrowser language
Avatar PositionBottom-Left
Avatar VisibilityVisible
Code Execution ModeDynamic
Avatar Guide SizeMinimized
Application DisabledDisabled
Custom DesignDisabled
Custom CodeDisabled

These defaults are documented in the application creation guide.

Create your first Application


Users

Use the Users tab to manage users who have access to the AppNavi Portal.

Users with Tenant Owner and Workspace Owner permissions can administer users according to their assigned permissions.

You can:

  • Add users
  • Assign workspaces
  • Assign workspace roles
  • Assign Tenant Owner access
  • Enable MFA when tenant MFA is enabled
  • Resend invitations
  • Reset passwords
  • Download the user list

Add a User

To add a user:

  1. Open Manage Tenant.
  2. Select Users.
  3. Open the three-dot menu.
  4. Select Add.
  5. Enter the user's first name.
  6. Enter the user's last name.
  7. Enter the user's email address.
  8. Enter the phone number if required.
  9. Select the user's language.
  10. Select the required workspace.
  11. Configure Tenant Owner and MFA options if applicable.
  12. Click Save.

At least one workspace must be selected when creating a user.

After the user is created, AppNavi sends an email containing a confirmation link. The user must complete the registration process before accessing their account.

Manage Users


Workspaces

Workspaces provide a logical separation of AppNavi content and access within a tenant.

Workspace data can include:

  • Routes
  • News
  • Learning collections
  • Users
  • Hotspots
  • Other workspace-specific content

A user can belong to one or more workspaces and can have a different role in each workspace.

Create a Workspace

Only Tenant Owners can create workspaces.

To create a workspace:

  1. Open Manage Tenant.
  2. Select Workspaces.
  3. Click the + icon.
  4. Enter the workspace title.
  5. Enter a description if required.
  6. Click Save Changes.

Workspace Roles

Workspace permissions determine what a user can access and manage.

Available roles include:

  • Tenant Owner
  • Workspace Owner
  • Contributor
  • Translator

A user can have different roles in different workspaces.

Workspaces


Contracts

Use the Contracts tab to view contracts available within the tenant.

You can:

  • View contracts by type.
  • Search for a contract using its ID or title.
  • Expand a contract to view the applications assigned to it.
  • Search using the ID or title of an assigned application.

Use this area when you need to verify which applications are associated with a contract.


Discovery Settings

Use Discovery Settings to configure App Discovery for the tenant.

App Discovery helps identify frequently used web applications that do not yet have an AppNavi application configured.

Enable App Discovery

To enable App Discovery:

  1. Open Manage Tenant.
  2. Select Discovery Settings.
  3. Enable App Discovery.
  4. Select the required data source.
  5. Configure any additional Discovery settings that become available.
  6. Save the changes.

Available data sources include:

  • Extension
  • Defender API

When App Discovery recording is enabled, additional Discovery options become available.

App Discovery


Client API

Use Client API when an external system needs to access AppNavi data through the Public API.

Prerequisite

The Client API setting must first be enabled under Manage Tenant → Settings.

Enable Client API

  1. Open Manage Tenant.
  2. Select Settings.
  3. Locate the Client API setting.
  4. Enable it.
  5. Click Save Changes.
  6. Open the new Client API tab.

The Client API tab becomes available after Client API is enabled.

Create an API Client

  1. Open the Client API tab.
  2. Open the three-dot menu.
  3. Select Add.
  4. Enter a meaningful title.
  5. Enter a description.
  6. Select the modules and API permissions required by the client.
  7. Click Create.
  8. Copy the generated Client ID and Client Secret.
  9. Store the Client Secret securely.

The Client Secret is displayed only once. If it is lost, a new API client must be created. A tenant can create up to five API clients.

Security Consideration

Treat the Client Secret as a sensitive credential.

Do not store it in source code, public documentation, screenshots, or other locations where unauthorized users could access it.

Client API

Getting Started with Public API


OAuth

Use the OAuth tab to configure Single Sign-On for the AppNavi Portal and Avatar.

The OAuth configuration becomes available after Enable Single Sign-On (SSO) is enabled in Manage Tenant → Settings.

Prerequisites

Before configuring SSO, make sure that:

  • You have Tenant Owner or Tenant Admin access.
  • Your AppNavi tenant is active.
  • An application has been registered with your Identity Provider.
  • You have the required Client ID.
  • You have the required Client Secret.
  • You have the required redirect or callback URI.
  • You have the required scopes.
  • You have the required Identity Provider endpoints.

Supported Identity Providers documented by AppNavi include Microsoft Entra ID and Okta.

Configure SSO

  1. Open Manage Tenant.
  2. Select Settings.
  3. Open the Authentication section.
  4. Enable Single Sign-On.
  5. Click Save Changes.
  6. Open the newly available OAuth tab.
  7. Enter the required Identity Provider information.
  8. Save the configuration.
  9. Test the SSO login flow.

The required configuration can include:

  • Callback URI
  • Authorization URI
  • Token URI
  • UserInfo URI
  • Issuer
  • Client ID
  • Client Secret
  • Scopes
  • Authentication settings
  • Claim fields

The exact values must come from your Identity Provider configuration.

Validate SSO

After configuring SSO:

  1. Open the AppNavi login page.
  2. Select Login with SSO.
  3. Complete authentication with your Identity Provider.
  4. Confirm that you are redirected back to AppNavi.
  5. Confirm that you are logged in successfully.

Single Sign-On Setup Guide


AI Settings

Use AI Settings to configure AI functionality available at the tenant level.

The available options depend on the AI features enabled for your tenant.

Before enabling an AI feature, review the related feature documentation to understand:

  • What data is used.
  • Which users can access the feature.
  • Whether additional configuration is required.
  • How the feature affects the tenant.

Profile

Use Profile to manage settings related to your own AppNavi user account.

Profile changes apply to your individual account and do not change tenant-wide configuration.


Defaults and Configuration Behavior

Some Manage Tenant settings have documented default values.

Examples include:

ConfigurationDefault / Initial State
CurrencyEUR
MFADisabled until activated
Auto LogoutConfigured through Authentication settings
Domain RestrictionsDisabled until configured
Client APIDisabled until enabled
App DiscoveryDisabled until enabled
Single Sign-OnDisabled until enabled
Application Custom DesignDisabled
Application Custom CodeDisabled

Not every setting has a fixed default value. Where a setting does not have a documented default, configure it according to your organization's requirements.


Configuration Dependencies

Some administration areas become available only after another setting has been enabled.

FeaturePrerequisite
OAuthEnable Single Sign-On in Settings
Client APIEnable Client API in Settings
User MFAEnable MFA at tenant level
Additional Discovery settingsEnable App Discovery
Application Custom DesignEnable Custom Design for the application
Application Custom CodeEnable Custom Code for the application

For example, enabling Client API creates the Client API tab, where API clients can then be created and managed.

Similarly, enabling Single Sign-On makes the OAuth tab available for Identity Provider configuration.


Security Considerations

Manage Tenant contains settings that can affect authentication, authorization, application access, and external integrations.

Consider the following before making changes:

Authentication

Changes to MFA, SSO, Identity Connect, or other authentication settings can affect how users sign in.

Test authentication changes with an appropriate administrator account before applying them broadly.

Domain Restrictions

Domain restrictions can limit which email domains are permitted to access or create users.

Verify the required domains before saving the configuration.

API Credentials

Client Secrets provide access to configured Public API permissions.

Store them securely and do not expose them in screenshots, documentation, source code, or public repositories.

Application Security

Application-level security features such as Origin Security restrict which origins can access application resources. Origin Security is configured at the application level and can define up to 10 allowed origin patterns.

External Identity Providers

When configuring SSO or Identity Connect, verify that URLs, client credentials, scopes, and claims match the configuration in your Identity Provider.


Validation

After completing a Manage Tenant configuration, validate the change before considering the configuration complete.

Use the following general validation process:

  1. Confirm that the configuration was saved successfully.
  2. Reopen the configuration and verify the saved values.
  3. Confirm that any dependent tab or setting is now available.
  4. Test the affected functionality.
  5. Test with an appropriate user role when permissions are involved.
  6. Verify that existing functionality has not been unintentionally affected.

For authentication changes, test both the intended authentication method and any existing login method that should remain available.

For application changes, open the configured application and verify that AppNavi behaves according to the selected settings.


Quick Navigation

Use this table to quickly find the administration area for a specific task.

I want to...Go to
Configure tenant-wide settingsManage Tenant → Settings
Configure MFAManage Tenant → Settings → Authentication
Configure Auto LogoutManage Tenant → Settings → Authentication
Restrict access by domainManage Tenant → Settings → Authentication
Configure Identity ConnectManage Tenant → Settings → Authentication
Enable Single Sign-OnManage Tenant → Settings → Authentication
Configure SSO / OAuthManage Tenant → OAuth
Enable Client APIManage Tenant → Settings
Create an API clientManage Tenant → Client API
Create an applicationManage Tenant → Applications
Edit an applicationManage Tenant → Applications
Manage usersManage Tenant → Users
Create a workspaceManage Tenant → Workspaces
Manage workspace rolesManage Tenant → Users / Workspaces
Review contractsManage Tenant → Contracts
Configure App DiscoveryManage Tenant → Discovery Settings
Configure AI functionalityManage Tenant → AI Settings
Manage your own accountManage Tenant → Profile

Troubleshooting

I cannot see a Manage Tenant tab

Check the following:

  1. Confirm that you are signed in with the required role.
  2. Confirm that the feature is available for your tenant.
  3. Check whether the feature must first be enabled in Settings.
  4. Refresh the AppNavi Portal after enabling a feature.
  5. If the option is still unavailable, contact your AppNavi administrator or support team.

A new configuration tab is not displayed

Some tabs are created only after their corresponding feature is enabled.

For example:

  • Client API appears after Client API is enabled.
  • OAuth appears after Single Sign-On is enabled.
  • Additional Discovery options become available after App Discovery is enabled.

My configuration was saved but the behavior did not change

Check that:

  • The setting was actually saved.
  • The expected dependent configuration was completed.
  • You refreshed the affected application or page.
  • The feature is enabled for the correct application or workspace.
  • Your user has the required permissions.

Related Administration Guides


Did this page help you?