Skip to content

Manage login methods and merge duplicate accounts

This page is for organization owners, admins and member admins who keep each member on a single account. It covers how members add and remove their own login methods, and how an admin merges two accounts that belong to the same person.

In Actagate, each member is one row in the Members list. Requests, approvals, grants and approval group memberships belong to that row.

Every login method is a way into that row. One row can hold all of the following.

Login method What the row holds
Email link The row’s email address
Slack login The row’s Slack ID
SSO The IdP user ID for each connection. One row can hold several

Whichever way a person signs in, they land on the same row. The same person can still end up with two rows, for example:

  • A row imported from Slack and a row invited by email have different email addresses, so they became separate rows
  • First-login provisioning (JIT) created a new row because the IdP email address differs from the existing row

Use the steps in “Merge duplicate accounts” to combine the two rows into one.

Each member adds and removes their own login methods under Login methods in Settings (/ws/settings). Every role can use it. Nobody can change another member’s login methods there.

[Screen: Login methods in Settings]

Login methods lists each SSO connection you have added, with Remove next to it, and an “Add ” button for each active connection. Your email address and Slack do not appear here and cannot be removed.

  1. Sign in the way you usually do and open Settings (/ws/settings). Login methods shows an “Add ” button
  2. Click “Add ”. The IdP sign-in page opens
  3. Sign in to the IdP. You return to Settings and see “Login method added.”

Adding a method does not change your current session. To have your session count as an SSO login, sign out and sign in again with SSO.

Owners and admins are not linked automatically on their first SSO login. If you are an owner or admin, add SSO with these steps first.

  1. In Settings (/ws/settings) > Login methods, click Remove next to the connection
  2. You see “Login method removed.” and the connection disappears from the list

You cannot remove your last login method. If removing it would leave no way to sign in, you see “You must keep at least one login method.” and nothing changes. Which methods count as a remaining way in depends on whether SSO is required.

State What counts as a remaining way in
SSO is not required Another SSO login method on an active connection, or the row’s email address or Slack ID
SSO is required Another SSO login method on an active connection. For owners only, the row’s email address also counts

Login methods on disabled connections do not count.

Message Cause and fix
This identity is already linked to an account. That IdP account is linked to a different row. If both rows belong to the same person, ask an admin to merge them
Identity verification failed. Try again. Actagate could not confirm the response from the IdP. Click “Add ” again
This connection is unavailable. The connection was disabled or its settings changed. Ask an admin to check the connection
Your account is disabled. Your row is disabled
Login method not found. The login method was already removed. Reload the page

When the same person has two rows, an admin combines them under Merge accounts on the Members page (/ws/members). A merge cannot be undone. Before you start, decide which row to keep and which Slack ID to keep.

[Screen: Merge accounts form]

Merge accounts has Source account, Keep account, Slack ID to keep, Role after merge and a Merge button. Role after merge appears only for owners and admins, who can assign roles.

  1. Open Members (/ws/members). Merge accounts appears below Invite members
  2. In Source account, choose the row to remove. This row is disabled after the merge. Your own row is not in this list
  3. In Keep account, choose the row to keep
  4. If both rows have different Slack IDs, choose one in Slack ID to keep. Otherwise leave it at Keep current value
  5. To change the role, choose it in Role after merge. To keep the role, leave it at Keep current value and the kept row’s role stays
  6. Click Merge. You see “Accounts merged.” and the source row shows “Merged into ” and Disabled

After the merge, all sessions and login links of both rows expire. Both people (or the one person behind both rows) must sign in again. If you chose your own row as the kept row, you are signed out too.

Only roles that can manage members (Owner, Admin, Member admin) can merge. The roles of the source and kept rows limit what each of them can do.

Who merges Roles allowed for the source and kept rows Role after merge
Owner (owner) Any role Any role. If the source or kept row is an owner, only owner
Admin (admin) Catalog admin, Member admin, Auditor, Member (not owner or admin) Any role from the same set
Member admin (member_admin) Both rows must be Member (member) Stays member (Role after merge is not shown)
Catalog admin, Auditor, Member Cannot merge (Merge accounts is not shown) None
  • If the source row, the kept row or the role after merge is Admin (admin), only an owner can merge. A merge moves every way in (email address, SSO and Slack ID) to the kept row
  • When the source row is an owner, choose owner in Role after merge. Otherwise you see “Choose a role that preserves owner access.”
  • When the kept row is an owner, the role after merge is also owner
  • You cannot use your own row as the source. To clean up your own rows, choose your own row as the kept row. Ask an owner for any merge that involves an admin row
  • Disabled rows and rows that were already merged cannot be chosen
Item After the merge
Source row Not deleted. It stays as a disabled row with its email address and Slack ID cleared
Email address The kept row’s email address is used. If the kept row has none, the source row’s address moves over
Slack ID If only one row has a Slack ID, the kept row gets it. If both have different IDs, the one chosen in Slack ID to keep. The other Slack ID can no longer sign in
SSO login methods All move to the kept row. The kept row may end up with two IDs on the same connection
Role The role chosen in Role after merge. If none is chosen, the kept row’s role
Requests, approval steps, grants, attachments, comments, manager settings All move to the kept row
Approval groups, approval cards, stamps, report subscriptions Move to the kept row. If both rows have the same item, the kept row’s record stays
Delegations between the two rows Revoked, because they would become delegations to oneself
Kept row’s manager Cleared if the source row was the manager
Sessions and login links Revoked for both rows
Audit log Past records are not rewritten. They keep the source row’s ID

A merge can make the requester and the approver the same row. For example, the source row is the requester and the kept row is the approver of that request. The merged person cannot approve that step.

  • The web app shows “You are not an approver for this step” and Slack shows “You are not the approver for this step.”
  • The step stays pending and is not reassigned to someone else automatically
  • If the step belongs to an approval group, other members of the group can approve it

Before merging, check whether the two rows have pending requests between them.

When a merge fails, the reason appears at the top of the Members page and neither row changes.

Message Cause
Choose two different accounts. The same row was chosen as the source and the kept row
You cannot merge your own account as the source. Your own row was chosen as the source
Disabled or merged accounts cannot be merged. One of the rows is disabled or already merged
Choose the Slack ID to keep. Both rows have different Slack IDs and none was chosen in Slack ID to keep, or the chosen Slack ID belongs to neither row
Choose a role that preserves owner access. The merge involves an owner row and the role after merge is not owner
You cannot assign that role. The merge is outside “Allowed merges” above
The item was not found or belongs to another organization. A row was not found

A merge appends user.merged to the audit log, with the IDs of the source row, the kept row and the person who merged.

Adding and removing login methods are recorded as sso.identity_linked and sso.identity_unlinked.