Manage login methods and merge duplicate accounts
This page is for organization owners, admins and member admins who keep each member on a single account. It covers how members add and remove their own login methods, and how an admin merges two accounts that belong to the same person.
One account per person
Section titled “One account per person”In Actagate, each member is one row in the Members list. Requests, approvals, grants and approval group memberships belong to that row.
Every login method is a way into that row. One row can hold all of the following.
| Login method | What the row holds |
|---|---|
| Email link | The row’s email address |
| Slack login | The row’s Slack ID |
| SSO | The IdP user ID for each connection. One row can hold several |
Whichever way a person signs in, they land on the same row. The same person can still end up with two rows, for example:
- A row imported from Slack and a row invited by email have different email addresses, so they became separate rows
- First-login provisioning (JIT) created a new row because the IdP email address differs from the existing row
Use the steps in “Merge duplicate accounts” to combine the two rows into one.
Add or remove your own login methods
Section titled “Add or remove your own login methods”Each member adds and removes their own login methods under Login methods in Settings (/ws/settings). Every role can use it. Nobody can change another member’s login methods there.
[Screen: Login methods in Settings]
Login methods lists each SSO connection you have added, with Remove next to it, and an “Add
Add a login method
Section titled “Add a login method”- Sign in the way you usually do and open Settings (
/ws/settings). Login methods shows an “Add” button - Click “Add
”. The IdP sign-in page opens - Sign in to the IdP. You return to Settings and see “Login method added.”
Adding a method does not change your current session. To have your session count as an SSO login, sign out and sign in again with SSO.
Owners and admins are not linked automatically on their first SSO login. If you are an owner or admin, add SSO with these steps first.
Remove a login method
Section titled “Remove a login method”- In Settings (
/ws/settings) > Login methods, click Remove next to the connection - You see “Login method removed.” and the connection disappears from the list
You cannot remove your last login method. If removing it would leave no way to sign in, you see “You must keep at least one login method.” and nothing changes. Which methods count as a remaining way in depends on whether SSO is required.
| State | What counts as a remaining way in |
|---|---|
| SSO is not required | Another SSO login method on an active connection, or the row’s email address or Slack ID |
| SSO is required | Another SSO login method on an active connection. For owners only, the row’s email address also counts |
Login methods on disabled connections do not count.
When adding or removing fails
Section titled “When adding or removing fails”| Message | Cause and fix |
|---|---|
| This identity is already linked to an account. | That IdP account is linked to a different row. If both rows belong to the same person, ask an admin to merge them |
| Identity verification failed. Try again. | Actagate could not confirm the response from the IdP. Click “Add |
| This connection is unavailable. | The connection was disabled or its settings changed. Ask an admin to check the connection |
| Your account is disabled. | Your row is disabled |
| Login method not found. | The login method was already removed. Reload the page |
Merge duplicate accounts
Section titled “Merge duplicate accounts”When the same person has two rows, an admin combines them under Merge accounts on the Members page (/ws/members). A merge cannot be undone. Before you start, decide which row to keep and which Slack ID to keep.
[Screen: Merge accounts form]
Merge accounts has Source account, Keep account, Slack ID to keep, Role after merge and a Merge button. Role after merge appears only for owners and admins, who can assign roles.
- Open Members (
/ws/members). Merge accounts appears below Invite members - In Source account, choose the row to remove. This row is disabled after the merge. Your own row is not in this list
- In Keep account, choose the row to keep
- If both rows have different Slack IDs, choose one in Slack ID to keep. Otherwise leave it at Keep current value
- To change the role, choose it in Role after merge. To keep the role, leave it at Keep current value and the kept row’s role stays
- Click Merge. You see “Accounts merged.” and the source row shows “Merged into
” and Disabled
After the merge, all sessions and login links of both rows expire. Both people (or the one person behind both rows) must sign in again. If you chose your own row as the kept row, you are signed out too.
Allowed merges
Section titled “Allowed merges”Only roles that can manage members (Owner, Admin, Member admin) can merge. The roles of the source and kept rows limit what each of them can do.
| Who merges | Roles allowed for the source and kept rows | Role after merge |
|---|---|---|
Owner (owner) |
Any role | Any role. If the source or kept row is an owner, only owner |
Admin (admin) |
Catalog admin, Member admin, Auditor, Member (not owner or admin) |
Any role from the same set |
Member admin (member_admin) |
Both rows must be Member (member) |
Stays member (Role after merge is not shown) |
| Catalog admin, Auditor, Member | Cannot merge (Merge accounts is not shown) | None |
- If the source row, the kept row or the role after merge is Admin (
admin), only an owner can merge. A merge moves every way in (email address, SSO and Slack ID) to the kept row - When the source row is an owner, choose
ownerin Role after merge. Otherwise you see “Choose a role that preserves owner access.” - When the kept row is an owner, the role after merge is also
owner - You cannot use your own row as the source. To clean up your own rows, choose your own row as the kept row. Ask an owner for any merge that involves an admin row
- Disabled rows and rows that were already merged cannot be chosen
What moves and what goes away
Section titled “What moves and what goes away”| Item | After the merge |
|---|---|
| Source row | Not deleted. It stays as a disabled row with its email address and Slack ID cleared |
| Email address | The kept row’s email address is used. If the kept row has none, the source row’s address moves over |
| Slack ID | If only one row has a Slack ID, the kept row gets it. If both have different IDs, the one chosen in Slack ID to keep. The other Slack ID can no longer sign in |
| SSO login methods | All move to the kept row. The kept row may end up with two IDs on the same connection |
| Role | The role chosen in Role after merge. If none is chosen, the kept row’s role |
| Requests, approval steps, grants, attachments, comments, manager settings | All move to the kept row |
| Approval groups, approval cards, stamps, report subscriptions | Move to the kept row. If both rows have the same item, the kept row’s record stays |
| Delegations between the two rows | Revoked, because they would become delegations to oneself |
| Kept row’s manager | Cleared if the source row was the manager |
| Sessions and login links | Revoked for both rows |
| Audit log | Past records are not rewritten. They keep the source row’s ID |
Pending approval steps after a merge
Section titled “Pending approval steps after a merge”A merge can make the requester and the approver the same row. For example, the source row is the requester and the kept row is the approver of that request. The merged person cannot approve that step.
- The web app shows “You are not an approver for this step” and Slack shows “You are not the approver for this step.”
- The step stays pending and is not reassigned to someone else automatically
- If the step belongs to an approval group, other members of the group can approve it
Before merging, check whether the two rows have pending requests between them.
Messages when a merge fails
Section titled “Messages when a merge fails”When a merge fails, the reason appears at the top of the Members page and neither row changes.
| Message | Cause |
|---|---|
| Choose two different accounts. | The same row was chosen as the source and the kept row |
| You cannot merge your own account as the source. | Your own row was chosen as the source |
| Disabled or merged accounts cannot be merged. | One of the rows is disabled or already merged |
| Choose the Slack ID to keep. | Both rows have different Slack IDs and none was chosen in Slack ID to keep, or the chosen Slack ID belongs to neither row |
| Choose a role that preserves owner access. | The merge involves an owner row and the role after merge is not owner |
| You cannot assign that role. | The merge is outside “Allowed merges” above |
| The item was not found or belongs to another organization. | A row was not found |
Audit log records
Section titled “Audit log records”A merge appends user.merged to the audit log, with the IDs of the source row, the kept row and the person who merged.
Adding and removing login methods are recorded as sso.identity_linked and sso.identity_unlinked.