Skip to main content

Guest login for process publications

Written by Jetmir Abdija

This article explains how SSO login works for non-BlueDolphin users in the Process Portal (Published BPMN 2.0 diagrams) and the Legacy Process Portal.

If the Legacy Process Portal (official diagrams, legacy BPMN) is enabled and in use in your organization, see If the Legacy Process Portal is also enabled at the end of this article.

The most common cause of guest login failures is sharing the wrong URL. See Share the right link below.

How SSO login works for non-BlueDolphin users

When someone opens a process publication link, BlueDolphin follows the standard authentication flow:

  1. BlueDolphin redirects the user to your identity provider (IdP) for single sign-on.

  2. The IdP checks whether the user is allowed to access BlueDolphin, based on the access groups configured on your IdP.

  3. If the user is not allowed, BlueDolphin denies the request.

  4. If the user is allowed, BlueDolphin reads the roles assigned to that user.

This produces one of two outcomes:

  • The user has one or more roles. The roles are applied immediately and the user works in BlueDolphin as normal.

  • The user has no roles. The user is treated as a guest user and can only view published processes.

NOTE: Every authenticated organizational user who signs in through SSO can enter the Process Portal, even without a BlueDolphin license. Guest users do not consume a license.

Guest users are not created manually

There is no manual step in Admin > Users, and BlueDolphin does not send an email invitation. Any user in an IdP access group that permits BlueDolphin access becomes a guest user on their first sign-in to a valid entry point

NOTE: SCIM usually configures user access based on the IdP access groups. When SCIM has been set up to use the same access groups as the IDP, all users will be created in BlueDolphin. When a certain group only needs official process access, do not assign group-role mapping in SCIM for that access group.

BlueDolphin automatically provisions a guest account the first time the person authenticates through SSO on a valid entry-point URL. Share the correct link to enable access.

Share the right link

A guest account is not created when someone is granted IdP access.

It is created the first time that person lands on one of two specific entry-point URLs.

Any other URL fails with:

Authentication failed, account not found

The two valid first-time entry points

Replace <tenant-name> with your tenant name, and <process-id> with the ID of the published process.

All published processes:

https://bluedolphin.app/<tenant-name>/processes/browser

One specific published process:

https://bluedolphin.app/<tenant-name>/processes/browser/<process-id>/published

The /published suffix is required on the per-process form. Without it, the guest account is not created and sign-in fails.

Do not share the deep link from the address bar

When an editor opens a published diagram in BlueDolphin, the URL shown in their browser address bar is a deep link that looks like this:

https://bluedolphin.app/<tenant-name>/processes/browser/<process-id>

This deep link is missing the /published suffix. It does not create the guest user, and a first-time guest who opens it gets "Authentication failed, account not found".

Do not copy this URL from BlueDolphin and pass it on to guests.

Sending a guest straight to https://bluedolphin.app/<tenant-name>/processes/portal fails for the same reason.

First visit provisions, later visits redirect

Guest access is a two-step behaviour. This is why a link that failed for a colleague yesterday may appear to work for them today.

  1. First visit. The guest lands on one of the two URLs above, authenticates through SSO, and BlueDolphin provisions the guest user.

  2. Every visit after that. The guest user now exists, so any of the process publication URLs work — including the deep link. The user is redirected to:

https://bluedolphin.app/<tenant-name>/processes/portal

Because of this, always distribute one of the two entry-point URLs, even to an audience where some people have already signed in.

Entry points to the Process Portal

Entry point

Result

Bookmarks

Bookmarks created from BPMN 2.0 diagrams always reopen in the Process Portal.

Direct Process Portal URL

Generic login URL (/login)

Users who sign in without a bookmark or a specific portal route land on their default start page.

Guests, who have no other access, are taken to the Process Portal.

First-time guests must still arrive on one of the two entry-point URLs described above.

Verify a Guest user was created

  • Insights shows the guest user after their first successful sign-in.

  • Admin > Users lists all users and their assigned roles. A user listed there with no role is a guest user.

mceclip0.png

What a Guest user sees

A guest user can:

  • View published processes in the Process Portal.

  • View official processes in the Legacy Process Portal, if that add-on is enabled.

A guest user cannot:

  • Create, edit, or comment on any object or diagram.

  • Open any other part of BlueDolphin.

If a guest needs to work in the tenant rather than only view processes, an administrator can assign them a role under Admin > Users.

If the Legacy Process Portal is also enabled

Skip this section if your organization only uses the Process Portal.

The Legacy Process Portal contains official diagrams in the legacy BPMN format. Where a user lands depends on how they got there, and no cross-redirection occurs between the two portals.
​
If a guest user (a user without an assigned role) logs in, the following screen appears.

mceclip1.png

Entry point

Result

Legacy BPMN bookmark

Opens the Legacy Process Portal.

BPMN 2.0 bookmark

Opens the Process Portal.

Direct Legacy Process Portal URL

Direct Process Portal URL

Generic login URL (/login)

Users who sign in without a bookmark or a specific portal route land on their default start page.

Bookmarks always reopen the original format. Both direct URLs remain active for backward compatibility.

IMPORTANT: Guest provisioning is confirmed only for the two Process Portal entry-point URLs under Share the right link.

Route every first-time guest through one of those two URLs, even when the processes they need are in the Legacy Process Portal. Once the guest account exists, the Legacy Process Portal URL and all other process publication links work normally.

Troubleshooting

Symptom

Cause

Fix

"Authentication failed, account not found" on a first visit

The link was not one of the two valid entry-point URLs

Re-share the link as /processes/browser, or as /processes/browser/<process-id>/published.

The link works for some people but not others

It works for those already have a guest account from an earlier visit.

First-time guests still need a valid entry-point URL.

Share one of the two entry-point URLs to the whole audience.

Guest reaches the IdP but is denied

The user is not in an IdP access group that permits BlueDolphin access.

Add the user to the appropriate access group on your IdP.

Guest sees full BlueDolphin instead of the portal

The user has a role assigned.

Remove the role under Admin > Users if the user should be a guest.

Did this answer your question?