In eADM, core user data, group memberships, and access rights are typically managed automatically through synchronization with a source system, such as a Human Resource Management (HRM) platform. However, administrators may occasionally need to make manual exceptions to this automated data.
This guide explains how administrators can manually override user attributes, group memberships, and access rights directly within the eADM interface. All override actions are logged for auditing purposes and can be reverted if necessary.
Note: Any override action will take effect during the next scheduled synchronization cycle.
Finding a List of All Overrides
To see a complete overview of all overrides currently active for an organization, search for Override in the import log. This will return every logged override action across user attributes, group memberships, and access rights, making it easy to review what has been manually overridden without having to check each user individually.
Important: You must search in the import log from the last full sync, not a delta sync. A delta sync only processes users who have changed since the previous run, so its log will only contain override information for that subset of users. Only a full sync log covers all users in the organization, giving a complete and accurate list of overrides.
Overriding User Attribute Data
This feature allows administrators to change user attribute data that was originally imported from the source HRM system. For example, you can manually correct a user's name.
When an attribute is overridden, the system stores the manual entry and will no longer update that specific field with data from the HRM system.
For step-by-step instructions on applying and reverting an attribute override, see How to Override User Data in eADM.
Audit Information
The user interface provides a clear audit trail for all overrides. For each overridden value, you can see:
-
The manually entered value.
-
The date and time the override was performed.
-
The administrator who made the change.
The platform also provides an option to revert the change, which will restore the original value and re-enable automatic synchronization for that attribute.
Overriding Group Memberships
Administrators can manually remove a user from a group, even if the group membership was assigned automatically based on rules (e.g., position or department). This is useful for managing exceptions where a user should not have access to a resource typically granted to their role.
When an administrator marks a group membership for removal, the user will be removed from that group during the next synchronization. This action is logged, and the membership can be manually restored later if access needs to be reinstated.
Overriding Access Rights
Similar to group memberships, administrators can override specific access rights or roles that have been assigned to a user automatically. This allows for precise control over a user's permissions within integrated systems.
When an access right is overridden, it is marked for removal and will be revoked during the next synchronization. This action is logged for security and auditing, and the access right can be restored if the override was made in error.