
Table of contents
User Provisioning is the step where WorkSights aligns your connected Google Workspace or Microsoft 365 environment with your WorkSights workspace. When your domain is connected, WorkSights imports users directly from your directory and presents them for administrative review.
Provisioning ensures WorkSights reflects the real structure of your organization — who is included, how identities map, and which accounts should participate in dashboards and reporting.
WorkSights uses four provisioning states to define how each imported identity is handled.
Provisioning States
New
A new WorkSights profile will be created for this person.
Link
The imported identity matches an existing WorkSights profile and will be connected to it. Used when an employee already exists in WorkSights or when consolidating multiple email addresses.
Blocked
The user will be excluded from WorkSights.
Useful for service accounts, external identities, test mailboxes, or any account that should not appear in dashboards.
Already Linked
WorkSights automatically recognizes and matches this identity to an existing WorkSights profile. No action is required.
These states ensure that every imported identity is intentionally reviewed and placed in the correct category.
How WorkSights Matches Users
WorkSights compares imported identities to existing profiles based on:
- Primary email address
- Domain alignment
If a match is found, the user appears as Already Linked.
If no match exists, the user appears as New until reviewed by an administrator.
Administrators can choose Link when an imported email belongs to an employee who already exists in WorkSights but uses a different address or profile. This prevents duplicates and keeps reporting consistent.
Provisioning and Roles
After provisioning is complete, administrators can assign each user a role that defines their level of access inside WorkSights.
WorkSights provides standard roles (Member, Manager, Executive, Technical Admin, Owner). Organizations may also create custom roles such as Engineer, Consultant, Contractor, or any title that reflects their internal model.
Custom roles help categorize users but do not replace permission levels.
Role assignment helps set the proper visibility for each user but does not define hierarchy — reporting lines are established separately in Assign Manager Relationships.
Provisioning and Activity Processing
A user begins displaying activity in WorkSights once they are provisioned:
- Email metadata (subject, recipients, timestamps)
- Calendar events
- Additional activity such as Teams messages, SharePoint/OneDrive interactions, Google Calendar and login events
WorkSights assigns timezone and scheduling context using available metadata.
Users who are Blocked or not yet approved do not appear in dashboards and do not have activity processed.
Directory Sync and Ongoing Updates
WorkSights stays synchronized with your Google Workspace or Microsoft 365 environment. When changes occur in your directory:
- New employees appear as New in provisioning and await administrative review
- Users removed from your connected directory lose login access in WorkSights
- Administrators may re-map users, adjust roles, or block accounts at any time
Provisioning can be revisited whenever your organization changes.
Next Steps
After completing User Provisioning, continue to Assign Manager Relationships. This step defines your organization’s reporting lines and ensures dashboards in WorkSights reflect your real hierarchy.
