Knowledge Base - Smart Flows

Individual User Authentication (IUA)

Overview

Individual User Authentication (IUA) lets a connector act on behalf of the user who is running a flow, instead of acting under the single identity that was used to configure the connector.

When IUA is enabled, all runtime operations of that connector that take place in an interactive user context are executed by the active user. Each user authenticates once with their own account in the external system, and Smart Flows stores a token for them, so that they are not asked to authenticate again for every operation.

This keeps document automation governed: what a user can see and change in the external system is decided by that user's own permissions, and the actions are recorded under their own account.

IUA also decides who owns what a flow creates. Many blocks add something to the connected system, such as an eSignature envelope in Docusign, a file in Microsoft SharePoint, or an attachment in Salesforce. When the flow runs under the account of the user, that user becomes the owner of the new item, instead of the connector identity. Many systems grant people more access to the items they created themselves than to items created by someone else, so users can work with the results of their flows just as they work with anything else they created.

Permissions

IUA involves two audiences, and this article is split accordingly.

Task

Minimal permission

Where

Enable IUA on a connector and set the non-interactive mode

Administrators

Project Console

Review and revoke the stored tokens of any user

Administrators

Project Console

Configure expiration notifications

Administrators

Project Console

Authenticate with your own account

Every user who runs a flow

Flow Execution Panel

Review, renew, or revoke your own tokens

Every user who runs a flow

Flow Execution Panel

Note: Users cannot see or change the tokens of other users, and they cannot enable or disable IUA.

Glossary

Term

Meaning

Individual User Authentication (IUA)

A connector setting that makes runtime operations run under the account of the active user.

Connector identity

The account that was used to configure the connector. Used when IUA is not enabled, and in some non-interactive situations.

Active user

The user who is running the flow execution.

User authentication

The stored token that links one user to one connector.

Interactive user context

A flow execution that is running for a user, so that Smart Flows can prompt that user.

Non-interactive mode

The behavior of the connector when a flow execution has no active user, or when the active user has no valid token.

Connectors That Support IUA

  • Experlogix Documents

  • Microsoft Dynamics 365 CE

  • Microsoft Dynamics 365 Business Central

  • Salesforce

  • Microsoft SharePoint

  • Docusign

  • HTTP(s) – Only when the authentication type of the connector is OAuth.

Connectors that are not in this list always use the connector identity.

How IUA Works

When IUA is enabled on a connector, a flow execution follows this sequence:

  1. The flow execution reaches an action that requires an authenticated user of the external system.

  2. Smart Flows checks whether a valid token is stored for the active user.

  3. If there is no valid token, the user is prompted to authenticate with their own account in the external system.

  4. Smart Flows stores the token, so that the user is not asked to authenticate again for every operation.

  5. The action, and every following action of that connector in the same context, is executed by the active user.

  6. The user is prompted to authenticate again whenever the token has expired or has been revoked.

Not every flow execution has an active user that Smart Flows can prompt. For those executions, the Non-interactive mode setting of the connector decides what happens.

Enabling IUA on a Connector

When a connector that supports IUA is created, user authentications are enabled, and the non-interactive mode is set to Pause flows and wait for the user to authenticate.

Note: Individual User Authentication requires the plugin to use the Authorization code OAuth flow. If a plugin's OAuth flow is set to Client credentials in Control panel > Settings > Plugin settings, individual user authentication is not supported because connector operations execute under the application identity rather than an active user identity.

Permissions: Administrators only

To review or change the setting:

  1. Log in to the Smart Flows Project Console.

  2. Open Control panel > Connectors and select the connector.

  3. Open the User authentications tab, which shows the Manage individual user authentications settings.

  4. Select or clear Enable user authentications for this connector.

  5. If user authentications are enabled, review the non-interactive mode and change it if the default does not suit you. The options are not available while user authentications are disabled.

  6. Save your changes.

The same tab lists the users who have already authenticated for this connector.

Non-interactive Mode

A flow execution runs in one of two modes:

  • Interactive: a user is going through the steps of the flow in the Flow Execution Panel, so a prompt appears in front of someone who can respond to it.

  • Non-interactive, also called batch: the flow runs in the background, for example because it was started by an automated process or by an agentic workflow, so nobody is there to respond to a prompt.
    The non-interactive mode tells the connector what to do instead. It applies whenever no user authentication is available during the flow execution:

Option

What it does

Fallback to connector user

The operation is executed under the connector identity.

Fallback to connector user and generate a warning on the flow execution

The operation is executed under the connector identity, and a warning is added to the flow execution.

Pause flows and wait for the user to authenticate

The flow execution is paused until the user authenticates. This is the default.

End flow with error

The flow execution ends with an error.

Note: the two fallback options mean that the action is performed under the connector identity, and therefore with the permissions of that identity, not those of the user.

Managing Stored User Tokens

Administrators can review and revoke the tokens that users have stored. The same list is available in three places:

Permissions: Administrators only

Location

Shows

Control panel > User authentications

Every user authentication in the project.

The User authentications tab of a connector

The users who have authenticated for that connector.

The User authentications tab of a user

The connectors that user has authenticated for.

The list shows the User name, the Expires on date, the Status, and whether the authentication is Enabled. In Control panel > User authentications, a Connector column is shown as well. Last Refreshed and Created at are available as additional columns.

The status has three values:

Status

Meaning

Connected

A valid token is stored.

Disconnected

No valid token is stored. The user is prompted the next time an action requires an authenticated user.

Unavailable

Individual user authentication is not available for this combination of user and connector.

To revoke a stored token:

  1. Open Control panel > User authentications
    or
    open the User authentications tab of the connector or of the user.

  2. Select the user authentication.

  3. Select Revoke.

The user is prompted to authenticate again the next time an action requires an authenticated user.

What Users See

With IUA enabled, a user is prompted to authenticate with their own account whenever an interactive action during a flow execution requires an authenticated user and they have no valid token.

Minimal permissions: Users who run flows.

To authenticate when the prompt appears:

  1. Start a Flow execution as usual.

  2. When the flow reaches a step that needs authentication, Smart Flows shows the message "This step requires you to authenticate with" followed by the name of the connection.

  3. Select Connect with, followed by the name of the connection, and sign in with your own account.

  4. Continue the flow execution.

You are not prompted again for as long as your token remains valid.

Note: If an administrator opens a flow execution that another user started, they see "This flow is waiting for authentication for user", followed by the name of that user. Only the user who started the execution can authenticate for it.

Administrators also see the option “Never ask me to connect, always use connector identity instead”. When it is selected, the actions are performed under the identity of the connector rather than the account of the user.

Managing Your Own Connections

To review, renew, or remove your stored tokens:

  1. Open Flow Execution Panel > Settings.

  2. Select My connected apps.

  3. Select the name of a connection to expand it.

Each connection shows a Connect button, which you use to connect for the first time or to renew an expired token, and a Disconnect button, which removes the stored token.
Disconnect is not available when there is no connection.
When a valid token is stored, the connection is marked Connected!, and the expiration date of the token is shown.

After you disconnect, you are prompted again the next time an action requires an authenticated user.