Fetch the complete documentation index at: https://docs.arpia.ai/llms.txt. Use this file to discover all available pages before exploring further. Append .md to any documentation page URL to get its markdown version.

# 📘 Getting Started

Essential concepts and first steps for managing users and permissions in your ARPIA Workarea.

📘 Getting Started

Essential concepts and first steps for managing users and permissions in your ARPIA Workarea.

# Getting Started with User Management

Welcome! This section covers the foundational concepts you need to understand before managing users and permissions in ARPIA.

***

## 🎯 Who This Is For

This section is essential if:

* ✅ You just created your ARPIA Workarea
* ✅ You're the Super User or ADMIN
* ✅ You need to add team members and control their access
* ✅ You're new to ARPIA's permission system

***

## 📚 What You'll Learn

### [Understanding ARPIA's Permission System](https://docs.arpia.ai/docs/understanding-arpias-permission-system)

**Read this first** to understand the two core concepts:

* **Super User Profile** - Automatically created and assigned to the Workarea creator. Full, unrestricted access to everything in the Workarea.
* **Security Profiles** - Custom permission sets you must create for all other users.

> ❗ **Critical:** A new Workarea only has the Super User profile available by default. All other profiles must be created manually before adding users.

**Time to read:** 5 minutes

***

### [How to Create a New Workarea](https://docs.arpia.ai/docs/how-to-create-a-new-workarea)

**Understand Workareas** before setting up your team:

* How to create and switch between Workareas
* Owner vs Invited user types and how billing works
* Why user type matters when removing users

> 💳 **Note:** Workareas, users, and platform features are subject to credit consumption based on your organization's contracted plan. Review your plan before adding Workareas or users.

🔗 [Pricing @ ARPIA Platform](https://docs.arpia.ai/docs/billing-credit-management)

**Time to read:** 5 minutes

***

### [First-Time Workarea Setup](https://docs.arpia.ai/docs/first-time-workarea-setup)

**Step-by-step guide** to set up your Workarea for the first time:

1. Create Security Profiles (ADMIN, DEV, USER, VIEWER)
2. Add your team members
3. Assign profiles to grant access
4. Verify everything works

**Time to complete:** 30-45 minutes

***

### [Single Sign-On (SSO)](https://docs.arpia.ai/docs/single-sign-on-sso-arpia-platform)

**Optional but recommended** — connect ARPIA to your organization's Google Workspace or Microsoft 365 / Azure AD:

* No passwords to manage
* Login is automatic with your existing provider
* Login method is set per user at creation time

> ⚠️ **Note:** Your ARPIA link must be authorized in your organization's Whitelist before SSO can work. Ask your IT admin if unsure.

**Time to read:** 5 minutes

***

## 🚀 Quick Start Path

### If you just created your Workarea:

1. Start with [Understanding ARPIA's Permission System](https://docs.arpia.ai/docs/understanding-arpias-permission-system)
2. Then follow [First-Time Workarea Setup](https://docs.arpia.ai/docs/first-time-workarea-setup)
3. Create your first Security Profiles
4. Add your team and assign profiles
5. Optionally, configure [SSO](https://docs.arpia.ai/docs/single-sign-on-sso-arpia-platform) for passwordless login

### If your Workarea is already set up:

Skip to:

* [Security Profile](https://docs.arpia.ai/docs/security-profile) - Manage permission sets
* [Users](https://docs.arpia.ai/docs/users) - Manage users
* [SSO](https://docs.arpia.ai/docs/single-sign-on-sso-arpia-platform) - Switch users to SSO login

***

## 💡 Key Takeaway

Before you can effectively add users to ARPIA, you must:

1. ✅ Understand the Super User profile and how Security Profiles work
2. ✅ Create Security Profiles (none exist by default beyond Super User)
3. ✅ Decide on login method: Password or SSO (set per user at creation)
4. ✅ Then add users and assign profiles

> ⚠️ **Important for Admins:** If you need to switch an existing user to SSO, this must be done from the **Workarea where the user was originally created**.