Administrators can manage a Vault’s VeevaID settings as well as register new VeevaID users. VeevaID Partners can also register their apps and gain access to the VeevaID API, support, and security best practices.

VeevaID Usage Best Practices

VeevaID is designed for external users who work with multiple sponsors or CROs.

Other types of users who should not use VeevaID include:

  • External users who already have a Vault login. These users should use cross-domain authentication.
  • Internal users within your organization. VeevaID does not allow users with a username that matches the Vault’s domain. For example, VernBio’s domain is @vernbio.com, therefore, username domains for VeevaID users in the VernBio Vault cannot be “@vernbio.com”. These users should use SSO with your enterprise identity provider for the best end-user experience by reducing the number of logins they need to remember.

Managing VeevaID Settings in Vault

Administrators can manage individual Vault settings for VeevaID from Admin > Settings > Vault Settings > VeevaID Settings.

The following information is available on the VeevaID Settings page:

  • VeevaID Name: The name used when referencing the current Vault on the VeevaID portal. This field defaults to the product family name.
  • VeevaID Description: A description of the Vault used on the VeevaID portal. This field defaults to a product family description.
  • Company Name: The name of the company associated with this Vault. This field defaults to the Vault’s sponsor name.

Select Edit to modify these fields. If you attempt to clear any of these fields, Vault resets them to their defaults.

Registering VeevaID Users

To register a VeevaID user:

  1. Navigate to the Admin > Users & Groups > Vault Users page and select Register VeevaID User from the Actions menu.
  2. In the Register VeevaID User dialog, enter the user’s email address.
  3. Click Search.
  4. Select Invite User to VeevaID.
  5. Enter the user’s First Name and Last Name.
  6. Select the Language, Locale, and Timezone.
  7. Select the License Type and Security Profile. Vault automatically assigns the VeevaID Security Policy for the new user. If the License Type field is not visible, manage application-specific licensing in the next step.
  8. Optional: Select a license value for each application. You must select a license value for at least one application. Some license values may be unavailable depending on the application.
  9. Select Send Invite. This sends an email to the user to complete the registration process. You will receive an email notification when the user has completed their registration.

Additional Security Settings

Once a VeevaID user has an active account in a Vault, all other security permissions depend upon that Vault’s configuration. This can include permission sets, lifecycle roles, and atomic security. For the session duration, VeevaID users will follow the setting in the Vault they are in. If they are on the VeevaID portal and not active in a Vault, their session duration is 30 minutes.

VeevaID Account Updates

When a VeevaID user’s account details such as their email or Last Name change, the user must first initiate the update process in the VeevaID portal. Once updated in the portal, the new details are updated upon log in to each individual application.

  • When the user has access to multiple applications on the same domain, their log-in to one application synchronizes the new details across all applications on that domain.
  • When a Vault user has an associated Person record, the new User details are additionally populated on the Person.

Troubleshooting

In the event a user does not receive an invitation or otherwise cannot access a particular Vault via VeevaID, Vault Admins should first check the target Vault for an invitation record with the correct Registrant Email via Business Admin > Objects > VeevaID invites: Vault User Creations.

When the target Vault does not have the expected invitation record, this means the user was not properly registered or otherwise did not meet invitation criteria.

When there is an invitation with the correct email, options for diagnosing issues include reviewing:

  • The registration email status.
  • The invitation’s Vault User Creation value. When “Pending”, this means the Vault sent a registration email at some point. In this case, it is possible that either:
    • The user did not complete the registration process to create their VeevaID, or
    • The user self-registered for VeevaID (separate from the invitation) and has not accepted the invitation. In this scenario, you can resend the VeevaID registration email from the invitation.

Checking the VeevaID Registration Email Status

Vault allows you to check the status of VeevaID registration emails through the VeevaID invites: Vault User Creation object (veevaid_invite_vault_user_creation__sys). You can use this feature to find more details on VeevaID registration emails, such as the date and time it was sent, when it expires, and whether the user recieved it.

To check a VeevaID registration email status:

  1. Navigate to Business Admin > All VeevaID invites: Vault User Creations.
  2. Click an ID in the Name column to open the record detail page.
  3. Click All Actions > Email Registration Status.

The Email Registration Status dialog opens and contains details on the VeevaID registration email’s status. You can also access this action by clicking All Actions next to the ID in the Name column.

Resending a VeevaID Registration Email

To resend a VeevaID registration email:

  1. Navigate to Business Admin > All VeevaID Invites: Vault User Creations.
  2. Click an ID in the Name column to open the record detail page.
  3. Click All Actions > Resend Registration Email.

This action is also available from the Email Registration Status dialog if the status is Failed. You can also access this action by clicking All Actions next to the ID in the Name column.

Limitations

When a user self-registers prior to receiving any invitations, they are still granted a VeevaID account. However, these users are not granted access to any applications until they accept at least one valid, non-expired invitation.

Similarly, when a user self-registers but all pending invitations are expired, they are still granted a VeevaID account, but cannot access any applications until an Admin re-sends an invitation and the user successfully logs in to at least one application.

Just-in-Time & Immediate User Creation

In most cases, users only need to register once to establish their VeevaID for all intended applications, regardless whether the invitation has expired. However, some applications handle this differently, depending on whether it uses just-in-time (JIT) or immediate user creation.

Most applications use JIT registration, where Vault tracks registrations within a Person record and only creates a User record once the user successfully registers. In contrast, SiteVault and EDC immediately create User records upon invitation, and then update that record once the user successfully registers.

This means that a user invited to two applications using a mixture of creation methods cannot simultaneously gain access to both applications, unless the JIT-based invitation has not yet expired. For example, a user invited to both Site Connect (JIT) and SiteVault (immediate) cannot gain access to both applications unless the Site Connect invitation is not yet expired.