What is Check User?
The Check User mode is a cross-group search tool that lets administrators look up a specific user and see every Authorization Group they belong to — including their role within each group and the source of each membership. It provides a complete group membership profile for a single user in a single view.
Access to Check User is restricted to Founders and users with the manage_auth_groups permission.
Opening Check User
From the Manage Authorization Groups home page, click Check user in the top action bar. This opens the search form.
Searching for a user
You can search by any combination of the following fields:
| Field | Description |
|---|---|
| Personal code | The user's HR identifier (numeric ID in the master data). |
| Username | The user's login username (partial match supported). |
| Last name | Partial match on surname. |
| First name | Partial match on given name. |
| Email address | Partial match on the registered email address. |
| Structure | Filter by the user's assigned department or organizational unit. |
Click Search to retrieve matching users. Select the target user from the results to load their group membership profile.
Reading the membership profile
The membership profile table lists every group the user belongs to (as a member or as a delegate), filtered to groups you are authorized to see. For each group, the table shows:
| Column | Description |
|---|---|
| Code | The group acronym, linked to the group detail view. |
| Name | The full group name. |
| Roles | Whether the user is a Responsible or a Delegate for the group. Empty if neither. |
| Source | How the user came to be a member — see below. |
| Actions | Quick link to open the group detail view. |
Membership source types
| Source badge | Meaning |
|---|---|
| Explicit / Manual | The user was added manually by a responsible or delegate. |
| Calculated rule | The membership was generated by a calculated rule set. |
| Inherited | The membership was inherited from a child group via the group-of-groups synchronization. |
| Internal calculation | The membership was generated by an internal system calculation and is not synchronized to external provisioning systems. |
Visibility limitations
The results are filtered to groups you are authorized to manage. If the user belongs to groups you do not have access to, those groups will not appear in the profile. The manage_auth_groups permission or Founder access is required to see all groups without restriction.