Internal system
NIM internal access guide
The Internal system stores the users, groups, and memberships that NIM uses for its own access and App experiences.
The Internal system is a built-in target system. Unlike an external connector, it does not connect to a third-party application. Its users and groups are commonly used to control access to Apps and other NIM experiences.
How internal identities workDirect link to How internal identities work
| Internal data | Purpose |
|---|---|
| Users | NIM-managed accounts that can authenticate locally when local authentication is used. |
| Groups and memberships | Membership data that can support access control, including access to Apps. |
Disabled internal user accounts cannot sign in. Do not directly modify the Internal system database; use NIM configuration, mappings, jobs, or the supported management experience instead.
Internal user fieldsDirect link to Internal user fields
View these columns under Systems > internal > users > Columns.
| Field | Purpose |
|---|---|
ID | The identifier for the Internal user, automatically generated by NIM. Use it when updating an existing Internal user. |
Name | The user's username. |
Email | The user's email address. |
DisplayName | The name displayed for the user. |
ExternalID | An identifier used to relate the Internal user to a user in a connected directory system through an inter-system relation. |
Enabled | Determines whether the account can sign in to NIM. Disabled accounts cannot sign in. |
Description | A description of the account. |
AuthMethod | Restricts the authentication method for the user when defined. When undefined, any authentication method configured in NIM can be used. See the rules below. |
ChangePasswordAtLogon | Determines whether local authentication requires the user to change their password at sign-in. This applies to local authentication. |
ExternalID, then configure an inter-system relation to match the records. ID identifies the Internal user; ExternalID links that user to the directory identity.Authentication and accessDirect link to Authentication and access
NIM can authenticate users through local accounts or external identity providers. Choose the approach that matches your organization’s access and lifecycle requirements.
| Authentication approach | When it fits | Configuration |
|---|---|---|
| Local authentication | NIM-managed accounts are appropriate for the users who need access. | Create and maintain Internal users and their credentials. |
| LDAP | Your organization manages user identity through LDAP. | Configure LDAP |
| SAML single sign-on | Your organization uses an SSO identity provider. | Configure SAML |
AuthMethod rulesDirect link to AuthMethod rules
AuthMethod controls which authentication method an Internal user can use. It does not configure an identity provider or grant access to an App.
AuthMethod value | Sign-in behavior |
|---|---|
| Undefined | Any authentication method configured in NIM can be used. |
saml<configuration name> | Only the named SAML configuration can be used. For example, a SAML configuration named Entra uses samlEntra. |
| LDAP configuration name | Uses the named LDAP configuration. For example, a configuration named CorporateDirectory uses CorporateDirectory. The value is the configuration name; use LDAP only if that is the configuration's actual name. |
For LDAP, also set ExternalID to the connected directory user's identifier and configure the inter-system relation that links the Internal and directory user records. See Configure LDAP and Configure SAML for provider setup.
Account recoveryDirect link to Account recovery
Users can use the Forgot My Password experience when their internal user record has a valid email address. Administrators can update user data through mappings or App actions. If all administrator access is lost, contact Tools4ever Support.
In NIM log files, the Internal system may be called the Authorization system.
Manage internal users manually (optional)Direct link to Manage internal users manually (optional)
The optional NIM Account Management app provides a manual management experience for Internal users and groups. Administrators can edit user profiles, reset passwords, clear MFA status, enable or disable accounts, and manage group access.
Install it when you need manual account administration. The Internal system and the provisioning workflow below can be used without this app.
The wizard follows the app's README installation instructions.
Prepare the app filesDirect link to Prepare the app files
- Confirm the prerequisite Standard Item Library is available in your NIM environment.
- Download app.json from the app repository. Save the JSON file locally.
Start the app importDirect link to Start the app import
- In NIM Studio, open Configuration > Apps.
- Select Import, then choose the downloaded
app.jsonfile.
For screenshots and import details, see Import and Export Apps.
Complete the importDirect link to Complete the import
- Create each missing audit query shown during import.
- Complete the import after resolving the missing resources.
Finish setup and verify accessDirect link to Finish setup and verify access
- Return to Apps and clear the app's Exportable checkbox if it is selected.
- Review App access for the administrators who will manage Internal users.
- Test the app with a non-administrator account and confirm that the intended user changes work before using it for routine administration.
Automate internal user provisioningDirect link to Automate internal user provisioning
Use filters, mappings, and scheduled jobs to automate repeatable Internal user updates from source data. The workflow below shows how to configure, test, and schedule an update.
Create the source filterDirect link to Create the source filter
- Open Processing > Filters and select Add.
- Give the filter a descriptive name, such as
internal_users_password_reset. - Choose
internal.usersas the Start table. - Run the filter to review the current internal-user records.
- Add an expression that limits the result to the users you intend to update, then save the filter.
Check: review the results before saving. The filter should return only the intended users.
Configure the user-update mappingDirect link to Configure the user-update mapping
- Open Output > Mappings and select Add.
- Select Internal as the system, Users as the target, and
user_updateas the function. - Give the mapping a clear name, such as
internal_user_update. - Select the filter created in the previous step.
- Map the fields that should change. For an update, include the internal user
ID. - Map
emailto a valid address when users should be able to use password recovery. - Save the mapping.
Test and schedule the updateDirect link to Test and schedule the update
- Open the mapping’s Run tab.
- Select one representative user from the results.
- Select Run selected item and verify the updated user record.
- When the result is correct, create a job to run the mapping on the appropriate schedule.
Test one non-administrator account before applying a broad update. An incorrect user filter or mapping can affect access for many people at once.
Next stepsDirect link to Next steps
- Configure Apps and use internal groups for access where appropriate.
- Create mappings for broader lifecycle automation.
- Configure LDAP or SAML when external authentication is required.