Lucid has released a new group management experience. This new organizational groups feature offers enhanced flexibility in user management by allowing license settings in Lucid to be configured and applied at the group level. For instance, you can automatically assign licenses to users within your engineering group while requiring users in your sales team to request a license.
Accounts with SCIM enabled weren’t automatically migrated to the new experience as there are required steps to ensure continued functionality with your Okta SCIM integration. This article walks you through the process of prepping your Okta SCIM instance and Lucid account to successfully migrate to the new organizational groups experience.
If you are setting up SCIM for your account for the first time, refer to our Enable Okta SAML and SCIM in Lucid article. The migration instructions found in this article are only relevant to accounts that were using SCIM in Lucid prior to October 22nd, 2024.
Plan availability: Enterprise only.
- Available on FedRAMP accounts.
- Read the Lucid Plans article for more information about what is available on your account or the Upgrade your Lucid account article for instructions to upgrade.
Prepare the Okta app
Before you can migrate to the new organizational group experience in Lucid, you must ensure that your Okta SCIM instance is properly configured. This migration guide is for accounts that:
- Have previously connected your Okta environment to Lucid
- Have been using SCIM to push users
- Have been using SCIM to license and delicense users in Lucid
You must be using the Lucid application for SCIM provisioning in order to migrate to the Lucid organizational groups experience. Follow the instructions found in our Enable Okta SAML and SCIM in Lucid article if you aren’t yet using SCIM.
After enabling the organizational groups feature, user licensing will be managed solely through your organizational group settings in Lucid. If we receive a SCIM request that attempts to modify an individual Lucid user’s license values, no changes will be made to that user’s license values in Lucid.
Migrate to the new Lucid app
If you previously used the Lucidchart app, you need to know how to migrate to the new Lucid app. To access the new SCIM attributes, even if you are currently using the Lucid app, you have to add a new instance of the Lucid app in your Okta org. If you already have an existing instance of the Lucidchart app or the Lucid app, follow the steps below to migrate from that old instance to a newly updated instance of the Lucid app.
- Log in to your Okta org as an admin.
- Open the Admin UI.
- Select Applications from the navigation menu on the left side.
- Click Applications from the dropdown options.
- Click Browse App Catalog.
- Search for and select the Lucid app.
- Click Add integration from the top-right corner.
- Follow the flow and set up the settings as needed.
- Click Done.
- Turn off all provisioning in your old app by disabling "Create Users," "Update User Attributes," and "Deactivate Users."
- Configure the new application, including Provisioning of “Create Users,” "Update User Attributes,” and “Deactivate Users.”
- Provisioning should proceed without issues. If there is a “Not Found” on the discovery aspect, those users will need to be removed from the Okta app and re-added to force an External ID re-map.
- Go back to your Admin Dashboard.
- Open your old app instance.
- This is the previous Lucidchart or Lucid app you added before adding a new one in step 4.
- Go to the Provisioning tab.
- Select Integration.
- Click Edit.
- Uncheck the box for “Enable API Integration”.
- Click Save.
- You must now deactivate and delete your old app instance and begin using the new app you added.
Reconfigure the Lucid app
Enable SCIM organizational groups in Lucid
For this stage of the migration, you need account owner or account admin access to Lucid. If you aren’t assigned one of those admin roles, reach out to the admin for your Lucid account to be assigned one of these roles before proceeding with the following steps.
To enable SCIM organizational groups:
- Log in to Lucid.
- Select Admin from the left-hand menu.
- Click App integration from the left-hand navigation menu.
- From the dropdown menu, click General.
- Locate the SCIM tile and click Settings.
- You will be prompted by the instructions at the top of the page to enable SCIM for organizational groups.
- Under action item 1, click Enable SCIM for org groups.
- Then return to this article and continue with the reconfiguration of your Lucid (All Products) app. When you are finished, you will return to the SCIM page in Lucid, and under action item 2, click Lucid app reconfigured.
Locate the Lucid app in Okta
The majority of the changes that you’ll be making will be from within the Lucid app in Okta. To locate this app, follow these instructions:
- Log in to Okta as an admin.
- Select Applications from the left-hand navigation menu.
- From the dropdown menu, click Applications.
- Under your “Active” integrations, select the Lucid app.
Customize push groups
To create new or update existing push groups to successfully work with Lucid organizational groups, follow these steps:
- Select the Push Groups tab from the menu at the top of the Lucid app page in Okta.
- Click + Push Groups.
- From the dropdown options, select Find groups by name.
- We recommend customizing licensing groups.
- These groups will be used to assign a user a license in Lucid based on their membership to the group.
- Removing users from a licensing group will delicense them to free up licenses for others to use.
- Click Save & Add Another if you need to add another group.
- Click Save when you’ve added your last group.
Note: You can have as many license user groups as you want, but because a user can only belong to one organizational group, each user can also only belong to one push group at a time across all groups.
Unlink pushed groups
If you have any push groups that were previously assigned between your Okta applications and Lucid account, you will need to unlink them so that you can later re-assign them to appear in Lucid as organizational groups. To do so:
- Navigate to the push groups page in Okta.
- Select Active under the “Push Status” column.
- From the dropdown options, select Unlink pushed group.
Manage assignments
To ensure that group assignments function properly, follow these steps:
- From the Lucid app in Okta, select the Assignments tab from the menu at the top of the page.
- Under “Filters” on the left-hand side, click Groups.
- Click
the delete icon to the far right of your licensed user groups.
- If you have an “All Users” group assigned, we recommend that you keep it assigned.
- This group (which most likely has a customized name for your company) is typically used to assign all users at your company to this Okta application so they can sign in and see the Lucid tiles within the main Okta applications page.
View Okta groups as organizational groups in Lucid
Check that you are seeing the expected Okta groups as organizational groups in Lucid, which is confirmation that the migration was successful. To access the organizational groups page in Lucid, follow these steps:
- Navigate back to the Lucid admin panel.
- Select Groups from the left-hand navigation menu.
- From the dropdown menu, click Organizational groups.
You can expect to see your Okta groups as organizational groups on this page of the Lucid admin panel.
Note: Any users that aren’t added to one of the organizational groups you created to license users will instead be added to the “Default organizational group” automatically. You shouldn't see your All Users group (or any other applicable groups) in Okta from organizational groups in Lucid since it wasn't set up as a push group.
Configure license settings for each group
You’re now ready to configure the license settings for each of your organizational groups. This ensures that users are licensed or delicensed appropriately when they are added to or removed from one of these groups.
To access license settings, follow these steps:
- Navigate to the Lucid admin panel.
- Select License settings from the left-hand navigation menu.
- From the dropdown menu, click Lucid Suite settings.
- Proceed to the appropriate set of steps below to customize license settings for each organizational group.
Configure license settings for licensed users group:
- Click your desired licensing group from the list of organizational groups on the left-hand side of the licensing page.
- Under the “Access eligibility” section, select Eligible for full access.
- Under “Customized eligibility criteria”, select Instant access.
- Click Save changes.
Note: These settings make it so any users added to this group via SCIM automatically receive a Lucid Suite license. Removing a user from a license group will delicense the user, which allows you to free up licenses for others to use.
You have now completed all the steps to reconfigure the Lucid app. License settings will now be managed via the organizational groups created via SCIM.
Tip: Return to the SCIM integration page in Lucid to complete the second action item to finalize enabling the organizational groups experience.
Deactivate users
In some cases, you may want to fully deactivate users via SCIM, rather than just delicensing them by removing them from a licensing group in Okta. This will ensure that these users can no longer sign in to Lucid under this account, even as limited-access users. A deactivation via SCIM will additionally trigger a delicense automatically.
When deactivating a user, their documents will be automatically transferred to another user on your Enterprise account. The document transfer will occur 24 hours after delicensing via SCIM.
By default, the account owner will be the recipient of the documents that are automatically transferred upon delicensing or deleting a user. You can change the recipient of the transferred documents by navigating to the SCIM integration settings in the Lucid admin panel and selecting Modify default owner to the right-hand side of the email address. See the screenshot below for reference.
Clicking Modify default owner redirects you to the “Compliance settings” page of the admin panel where you can change the default document owner on your account. Refer to Lucid admin panel: Compliance settings article for additional details.
FAQ
Can I still configure licensing for an individual user on the organizational groups experience?
No. This new experience optimizes allowing license settings in Lucid to be configured and applied at the group level.
After enabling the organizational groups feature, user licensing will be managed solely through your organizational group settings in Lucid. If we receive a SCIM request that attempts to modify an individual Lucid user’s license values, no changes will be made to that user’s license values in Lucid.
Give feedback on this article
Have feedback about this article? Tell us about your experience here.