> ## Documentation Index
> Fetch the complete documentation index at: https://help.dingtalk.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Account Authorization Management

> This article explains how to configure user account authorization, including batch authorization and automatic authorization, with support details for the Free plan, Basic edition, Professional edition, and Dedicated edition. It also covers the features and step-by-step operations for account authorization management.

User account authorization is available only to organization admins. It controls which users within the organization can access the YiDA platform.

| **Feature**             | **Free plan** | **Basic edition** | **Professional edition** | **Dedicated edition** |
| ----------------------- | ------------- | ----------------- | ------------------------ | --------------------- |
| Batch Authorization     | Supported     | Supported         | Supported                | Supported             |
| Automatic Authorization | Not supported | Supported         | Supported                | Supported             |

## Overview

YiDA account authorization management helps organization admins control which users can access the YiDA platform. On the user account authorization page, view organization-level account data such as purchased accounts, unassigned accounts, and assigned accounts. It supports multiple ways to query user authorization status, batch authorization, batch freezing, and automatic authorization.

The account data fields are defined as follows:

* Purchased accounts: The number of accounts that come with the purchased platform edition (Basic edition, Professional edition, and so on). This value reflects the account quota of your current edition. For details, see **YiDA editions**.
* Unassigned accounts: The number of purchased accounts minus the number of assigned accounts.
* Assigned accounts: The number of accounts with authorization enabled in user account authorization.

The user list shows all accounts under the organization. Accounts with authorization enabled can access the YiDA platform; accounts without authorization cannot.

* Authorization toggle: Enable or disable authorization for accounts under the organization.
* Batch Authorization: Select multiple accounts and authorize them in bulk.
* Batch freeze: Select multiple accounts and disable authorization in bulk.
* Search by name: Search the authorization list by account name.
* Filter by department: Filter accounts in the list by department.
* Authorization status management: Filter accounts in the authorization list by **Enabled** or **Frozen**.

## Procedure

Follow these steps to configure YiDA access authorization for users in your organization.

<Steps>
  <Step title="Step 1">
    Sign in to the [YiDA workbench](https://www.yidaapps.com/workPlatform) as an admin.
  </Step>

  <Step title="Step 2">
    Click the **Platform management** button in the upper-right corner to open the platform management page.
  </Step>
</Steps>

<Steps>
  <Step title="In the left navigation menu, click Account authorization management." />

  <Step title="Select the target department on the left, select the users to authorize, and then click Batch Authorization.">
    <Note>
      Supported authorization (or freeze) methods include **All Organization members**, **All Search results**, **Selected on current page**, **All members of current and sub-departments**, **All members of current Department**, **By DingTalk role**, and **Batch import user IDs**.
    </Note>
  </Step>
</Steps>

## Automatic Authorization (Paid Feature)

Previously, admins had to enable authorization manually, which could not guarantee real-time availability. To address this pain point and reduce admin workload for unlimited-user editions, YiDA now supports **automatic authorization**.

Once automatic authorization is configured, every user who accesses YiDA is granted access permissions automatically.

<Note>
  Keep the following in mind when using automatic authorization:

  * After you enable automatic authorization, it takes a short time for account authorization status in the list to update. If the status does not update immediately, do not worry — this does not affect user access. Users are granted authorization automatically the first time they access the YiDA platform.
  * Existing accounts that have not been authorized will not be granted authorization automatically.
  * Once the organization reaches the account limit of its edition, no new users will be granted automatic authorization.
</Note>

Automatic authorization supports the following methods:

* Automatic authorization for all organization members

If you choose to automatically authorize all organization members, each user is granted authorization the first time they access the YiDA platform after the setting takes effect. Their **Authorization status** changes to **Authorized**, and the **Authorization source** shows as **Organization-wide automatic Authorization**.

* Automatic authorization by department

Select the departments to be automatically authorized. Members of those departments are granted authorization the first time they access the YiDA platform after the setting takes effect. Their **Authorization status** changes to **Authorized**, and the **Authorization source** shows as **Department automatic Authorization**.

* Automatic authorization by DingTalk role

Select the DingTalk roles to be automatically authorized. Users with those roles are granted authorization the first time they access the YiDA platform after the setting takes effect. Their **Authorization status** changes to **Authorized**, and the **Authorization source** shows as **DingTalk role automatic Authorization**.

<Note>
  Authorization priority is: **Manual Authorization** > **Organization-wide automatic Authorization** > **Automatic Authorization by Department or DingTalk role**.

  * If an admin manually freezes a user's authorization, automatic authorization no longer applies to that user.

  * If a user leaves a department or DingTalk role that has automatic authorization, their authorization is revoked.

  * If a user is authorized through **Manual Authorization** by an admin or through **Organization-wide automatic Authorization**, they are no longer affected by the third scenario.
</Note>

## FAQ

* Q: After enabling automatic authorization, I still see an "unauthorized" message when accessing YiDA. What should I do?

After enabling automatic authorization, if you still see an "unauthorized" message when accessing YiDA, sign out and sign in again.

* Q: If YiDA only has form submission permissions configured, do users still need account authorization? Yes. To submit a form, a user must first be granted account authorization, and then be added to the corresponding form permission group. For permission group configuration, see the new permission group configuration guide.
* Q: Why do the number of assigned accounts and the actual number of authorized accounts differ? Assigned accounts do not include employees who have left the organization. If the assigned account count exceeds the total in the assignment details, some employees who left before the automatic revocation feature was released still have active authorization. Switch the filter to **Authorized**. The **Authorized** account list shows former employees who are still authorized. Freeze their accounts to resolve the discrepancy.

<Note>
  Automatic authorization revocation is now supported for employee departures and department changes:

  * When an authorized account leaves the organization, the user's YiDA authorization is automatically revoked.
  * For users authorized through **Automatic Authorization by Department or DingTalk role**, if their department or DingTalk role changes and they are no longer in an automatically authorized department or role, their YiDA authorization is automatically frozen.
</Note>
