Integrations
Restrict access to Abacus mandants
Choose whether to block a mandant in Didyma or prevent Didyma’s Abacus users from accessing it.
Access to an Abacus mandant can be restricted in Didyma or in Abacus itself. Choose the control based on whether the mandant still needs to be available to organization administrators in Didyma.
Block a mandant in Didyma
Block a mandant in the organization’s Abacus settings when it should remain available in Didyma but only organization administrators may link a client to it.
A blocked mandant can only be linked by an organization administrator. This prevents other staff members from creating a new Didyma client link to that mandant.
Use this for sensitive mandants that administrators still need to import from or manage through Didyma.
Client visibility is not enough
The All members or Limited setting controls who can see a particular Didyma client. It does not reserve an Abacus mandant for that client.
A staff member who cannot access the restricted Didyma client may still be able to create or open another Didyma client and link that client to the same Abacus mandant. For that reason, setting the original client to Limited is not sufficient when the mandant itself must be protected.
Block the mandant in Didyma whenever only administrators should be able to create the Abacus link. See Manage client permissions for the separate client visibility control.
Restrict access in Abacus
If Didyma does not need to access a mandant at all, enforce the restriction in Abacus. Configure the Abacus users or credentials used by Didyma so they only have access to the mandants that should be available through Didyma.
A mandant that is not available to Didyma’s Abacus users cannot be imported or linked successfully, regardless of the visibility of any Didyma client. Ask the Abacus administrator to maintain this access boundary rather than relying on a Didyma setting.
Choose the appropriate boundary
- Admins still need the mandant in Didyma: block the mandant in Didyma so only organization administrators can link it.
- Nobody needs the mandant in Didyma: do not grant Didyma’s Abacus users access to it in Abacus.
- Both controls are required: limit the Abacus users to the approved mandants and block especially sensitive mandants in Didyma.
Keep the Abacus permissions as narrow as practical. Do not broaden a user’s mandant access merely to make a connection test pass.