Overview#
Onboarding a hundred users one at a time is not a workflow, it is a support burden. The User Import/Export module handles bulk operations properly: CSV and JSON imports with automatic validation and duplicate detection, direct migration paths from Auth0 and AWS Cognito, GDPR-compliant data exports, and asynchronous job processing that handles large batches without timeouts.
This module is equally useful for periodic compliance operations, where point-in-time user data exports support audit evidence requirements and data subject access requests.
Key Features#
-
Bulk User Import: Import users from CSV or JSON files with automatic validation, duplicate detection, and role mapping. Configure organisation assignment, welcome email delivery, and password handling. Asynchronous processing with real-time progress tracking handles large imports with detailed error reporting and rollback capability. Uploaded files are checked against an allowlist of expected content types before any data is parsed, so mislabelled or unexpected file types are rejected at the boundary.
-
Migration Support: Direct migration paths from Auth0 and AWS Cognito with automatic field mapping. Import users from your existing identity provider and map roles, attributes, and metadata to the platform schema with minimal manual configuration.
-
Directory Import from Microsoft Entra ID and Google Workspace: For organisations that maintain their roster in a corporate directory, the platform's directory connectors provide a one-click alternative to file-based import. Connect your Microsoft Entra ID or Google Workspace tenant once, choose exactly which directory groups are in scope, review a staged diff of the proposed changes, and apply. Repeat imports are idempotent, duplicate email addresses are attributed to the correct existing person, and provisioning fails closed: if account creation fails, the import halts and reports rather than half-completing.
-
Flexible Export Options: Export user data in CSV for spreadsheet analysis or JSON for complete data with metadata. Filter exports by organisation, date range, active status, and role. Sensitive data controls ensure appropriate handling of personal information. Exports fail closed when the organisation context is blank or missing, guaranteeing every export is scoped to exactly one organisation and never silently spans tenant boundaries.
-
GDPR Data Export: Generate individual user data packages for GDPR right-to-data-portability requests. Complete exports include profile information, activity logs, session history, and audit trail entries in an encrypted, machine-readable format.
-
Asynchronous Job Processing: All import and export operations run as background jobs to prevent timeouts and enable progress tracking. Monitor job status with progress indicators, completion estimates, and detailed error logs. Job history is retained for 90 days.
-
Error Handling and Recovery: Detailed error reporting with row-level information for validation failures, duplicate detection, and format issues. Download error logs for review, correct source data, and retry failed imports. Rollback capability allows reversing completed imports within 24 hours.
Supported Formats#
| Format | Import | Export | Notes |
|---|---|---|---|
| CSV | Yes | Yes | Simple format for spreadsheet applications |
| JSON | Yes | Yes | Complete data with metadata and nested fields |
| Auth0 Export | Yes | - | Direct migration from Auth0 |
| AWS Cognito Export | Yes | - | Direct migration from Cognito |
| Microsoft Entra ID | Yes | - | Group-scoped directory connector import with staged review |
| Google Workspace | Yes | - | Group-scoped directory connector import with staged review |
Use Cases#
- Law enforcement agencies onboarding large teams after organisational mergers, with bulk import from existing directory exports and automatic role assignment.
- Government departments migrating from a legacy identity provider to the platform with automated field mapping that preserves user attributes and organisational assignments.
- Healthcare providers fulfilling GDPR right-to-data-portability requests with encrypted individual exports that satisfy regulatory timelines without manual data assembly.
- Financial institutions generating regular user data snapshots for compliance documentation and disaster recovery verification.
- Organisations restructuring by exporting current user data, modifying department and role assignments offline, and re-importing updated records efficiently.
- IT administrators keeping the workforce roster in Microsoft Entra ID or Google Workspace and periodically re-syncing selected directory groups, with a reviewable diff before anything is applied and no duplicate accounts on repeat imports.
Open Standards#
- SCIM 2.0 (RFC 7643 / RFC 7644): The platform's identity provisioning layer supports SCIM 2.0 for user synchronisation, complementing file-based import and export with standards-based user lifecycle management.
- GDPR (EU Regulation 2016/679): The module supports data subject access and data portability requests (Articles 15 and 20), generating encrypted, machine-readable export packages that help operators meet the response timelines in Article 12(3).
- JSON (RFC 8259): JSON is the primary structured data format for full-fidelity user import and export, carrying nested attributes, role assignments, and metadata between the platform and external systems.
- CSV (RFC 4180): Comma-separated value files conforming to RFC 4180 are supported for both import and export, using the text/csv media type, to ensure interoperability with spreadsheet applications and directory tooling.
- OAuth 2.0 (RFC 6749): All import and export integration endpoints are protected by OAuth 2.0 bearer tokens, with tenant-scoped organisation claims verified before any bulk operation is executed.
- JSON Web Token (RFC 7519): Access to import and export operations is authorised via RS256-signed JWTs carrying organisation and role claims, ensuring each bulk action is bound to a verified identity and audited accordingly.
Getting Started#
- Download Template: Get the CSV or JSON import template with field definitions and example records.
- Prepare Data: Populate the template with user records, ensuring email addresses are valid and roles match available options.
- Test Import: Import a small sample (10 to 20 users) to verify field mapping, role assignments, and login functionality.
- Full Import: Upload the complete file and monitor the background job progress through the real-time dashboard.
- Review Results: Check import statistics, download any error logs, and verify that imported users can access the platform.
Last Reviewed: 2026-07-16 Last Updated: 2026-07-16