About Security in App management
Use Security in App management when a Global Administrator needs to review identity and API access across the AlloyScan instance.
This is different from the Site-level Security section, which manages users, App registrations, and SSO providers for the current Site.
Note: This page covers instance-level administration in App management. It is used by Global Administrators.
Menu path
Admin Center > App management > Security
The Security group contains:
- Users
- App registrations
- SSO providers
Scope
| Surface | Scope | Typical actor |
|---|---|---|
| Security | One current Site | Site Administrator |
| App management > Security | Whole instance | Global Administrator |
Instance-level Security is primarily useful in multi-site deployments where the same instance hosts many tenant Sites.
Global Users
The global Users page lets a Global Administrator review users at the instance level. On deployments that expose all-site visibility, the page includes a mode such as Show site users.
When all-site visibility is enabled, the grid adds a Site column so the administrator can see which Site each user belongs to and navigate back to the Site-level context.
Global App registrations
The global App registrations page works the same way for API clients. When all-site visibility is available, a control such as Show site registrations exposes site-scoped registrations and adds a Site column.
Use this view for cross-tenant diagnostics, for example when an expired API client triggers banners or notification events and the owning Site must be identified.
Global SSO providers
Global SSO providers are the instance-scope control surface for the built-in Microsoft and Google providers. A Global Administrator can allow or disallow each provider for the instance. Opening a provider shows its current settings in a read-only view. Site Administrators can only enable providers that the instance has allowed.
Important constraints
- Instance-level Security visibility is not a third role model. The shipped Site roles remain Administrator and User.
- Global all-site views are for instance-level oversight. Site Administrators manage Site users and App registrations from the Security section of their Admin Center.