Skip to main content
Version: 4.1 (2026 H2)

Users, Profiles and Organizations


Concept​

Users​

A user in primedocs typically represents a person within the organization, i.e., an employee who uses primedocs is stored as a "User" in the database.

The assignment is done using the so-called "Primary SID". Depending on the authentication method, this corresponds either to the Active Directory "PrimarySid" (in the format S-1-5-…) or the Entra ID "objectId" (in the format of a GUID).

However, a user does not necessarily have to be associated with a real person. There can also be technical user accounts.

The following properties are associated with a user:

  • Title
  • PrimarySid
  • Group memberships, which are loaded via the so-called PrincipalConnector
  • Defined user fields, which can be synchronized from other sources via the User synchronization.

Additionally, a user can have one or more profiles.

Profiles​

A profile is associated with both a user and an organizational unit. It allows, for example, a user with multiple roles within the company to represent these roles within primedocs.

In primedocs, documents are always generated via a profile. This ensures the connection between user data and organizational data.

A profile can also be shared with other users, allowing, for instance, another employee to use the profile for document generation as well. A share can additionally include an editing right that allows the authorised person to maintain the profile (data fields, signatures, organizational unit); without that right, the share is read-only. The editing right is granted independently of usage: it only allows editing, not using the profile. Deleting, re-sharing and setting the default profile remain reserved for the owner or administrators.

Organisation unit selection for shared profiles

For another person's profile with write access, the permitted organisation units of the profile owner apply. The editor's permissions do not determine this selection. In the Desktop Client, this assignment requires a connection to the primedocs server and is not available in offline mode.

A profile has the following properties:

  • Title
  • Assignment to a user
  • Assignment to an organization

The profile always contains the corresponding user and organizational fields. However, these can be overridden at the profile level if necessary.

The profile itself can be shared with other users either manually or automatically via profile sharing policies.

Field inheritance​

Fields are inherited — from a parent organizational unit to its children, from the user and the organizational unit to the profile, and from the default language to the other document languages. The complete rules, including field locks, are described under Field inheritance and field locks.

Three states are distinguished per field definition and document language:

StateMeaning
InheritedNo own value is stored on the profile. The value comes from the user, the organizational unit or the default language and follows changes to the source value.
Own valueA value is stored on the profile. It overrides the inherited value; changes to the source value no longer apply.
Deliberately emptyAn empty value is stored on the profile. It also overrides the inherited value — the field stays empty although an inherited value exists. For image fields this is how a profile without a signature image is run (functional mailbox, departmental signature).

The own value can be reset in primedocs Web; inheritance then applies again. This holds for text, selection and image fields.

note

The "deliberately empty" state is set in primedocs Web. In the Web Admin, fields only offer "own value" and resetting to the inherited value.

Organizations​

Organizational units represent the structure of the company. They can be organized in a hierarchical structure and can be assigned permissions.

Permissions ensure that only authorized users can assign a specific organizational unit to a profile.

An organizational unit has the following properties:

  • Title
  • If part of a hierarchy: the ID of the parent organizational unit
  • Defined organization fields

Organizational units can also be created and managed automatically in primedocs using the Organization synchronization.

Color Themes and Fonts​

In addition to standard fields (such as text, images, or checkbox values), organizational units support two special field types: Color Theme and Font Theme. Both are stored as XML on the organizational unit and, like all other fields, are inherited by subordinate organizational units. If multiple themes are defined, users can choose between them in the Office ribbon.

  • Color Theme: defines the CI/CD color palette (accent and hyperlink colors as well as specific chart colors). For the structure, attributes and a complete example, see Color themes.
  • Font Theme: defines the fonts (MajorFont / MinorFont, additional Fonts) and bullet styles. For the structure, attributes and a complete example, see Font themes.