Identity & tenants
Master tenant
When an HGE ID exists in several tenants, it has to be clear who may maintain that person's name and email address. That is exactly what the master tenant settles: it is the one tenant that owns the identity.
#Which tenant is the master
- Every HGE ID has exactly one master tenant
- It is determined automatically when the HGE ID is created — it is the first tenant
- Only the master tenant's administration can change name and email
- Changes are propagated to every other tenant automatically
A green Master badge marks the status in the user profile; administration can see it in the user detail view.
#What other tenants may do
A tenant that is not the master still manages the same person fully — just not their identity.
| Area | Non-master tenant |
|---|---|
| Name and email | Read-only, with a note "changeable by the master tenant only" |
| Roles and groups | Fully manageable |
| Assigned assets | Fully manageable |
| Licence settings | Fully manageable |
| Revoking membership | Possible at any time |
That is the deliberate split: who someone *is* belongs to the identity. What someone *may do at your place* belongs to your tenant.
#Transferring the master
Master status can move:
- Automatically — if the person is removed from the master tenant, the status passes to the next tenant, ordered by creation date
- Manually — via Transfer master in the user detail view
#Removing versus deleting
Two operations worth keeping apart:
- Remove from tenant — only the membership in *this* tenant ends. The HGE ID lives on, and master status transfers automatically if needed
- Delete globally — the HGE ID is deleted entirely. This is possible from the master tenant only
Caution
Deleting globally takes effect across every tenant the person belongs to. Normally you want the local removal — it ends access to your tenant without reaching into anyone else's.
Was this helpful?
Suggest an edit