Changing the Robot identity
Who is this article for?
Users wishing to remove the generic Ideagen Internal Audit (Aura) account from their system
IT Administrator permissions are required.
This article describes how to safely deactivate the old-style Pentana Robot staff user.
1. Overview
In v4.2 and earlier, the Robot (and later the Web UI) were configured as 'real' users in the system. When implementing, you would:
- Add a staff user (called something like "Pentana Robot").
- Allocate that user an identity.
The identity would be same as the Windows service Log on As (and for the Web UI, for the application pool identity). - Grant the user full permissions.
The users would see a generic user.
This caused issues as:
- We provided an extra free licence to support this setup (e.g., 51 users for a 50-user system), which was difficult for both customers and Ideagen to manage.
- User was visible in the application, so administrators could accidentally revoke permissions or deactivate it, leading to Robot job failures.
To address this in later releases, we introduced a SYSTEM user to use for the same purpose. As a result:
- No additional licence is needed; we now provide the correct number of licences.
- Application administrators cannot disrupt the Robot by changing permissions.
2. Changing the identity
If you are using v5.2 or later you can deactivate the Robot staff user by moving the identity to the SYSTEM user, thus matching the current way of doing things.
To change the identity:
- Go to Admin.
- Click Staff.
- Select the Identity.
- Change the Identity by adding X to the end.
- Click Save.
- Launch App Manager.
- Connect to the correct instance.
- Switch to the Tasks tab.
- Select Manage System Identities.
- Click Add Identity.
- Type in the service user’s Windows username into the new line.
- Click Apply.
- Restart the Robot server.
You can then deactivate the old Pentana Robot staff user.
You will not be able to delete the Pentana Robot user, because it has previously accessed the system and so has entries in the login log.