Mattermost Workspace Management, Permissions, & Troubleshooting Guide
Welcome to the centralized Mattermost Knowledge Base Directory. This guide covers workspace structure, role permissions, team/channel administration, mobile configuration, and common error resolution across IL2, IL4, and IL5 environments.
Prerequisites & Authorization Rules
- Just-In-Time (JIT) Provisioning Requirement
Before a user can be added to any team or channel, they must log into the target Impact Level (IL2, IL4, or IL5) Mattermost instance at least once. Mattermost uses JIT provisioning—accounts are not discoverable in user selection menus until the initial login is completed.
- Need-to-Know Access Approval
Platform One cannot determine operational "need to know." Access to restricted teams or channels must be approved by an authorized Team Admin (for teams) or Channel Admin (for channels) before access can be granted.
Step 1: Joining or Requesting Mattermost Workspaces
Joining an Existing Team
Public Teams: Open to all users within authorized email domains.
Private Teams: Requires an invite or manual addition by a Team Admin.
Domain Restrictions: If you receive a "domain not permitted" error, your Team Admin must update the allowed email domains via Team Settings > Allow only users with a specific email domain to join this team.
Requesting a New Team or Channel
Standard users cannot create top-level teams.
Submit Request: To request a new team or custom channel, submit a ticket via the Create a new Mattermost team or channel form on the P1 Support Hub.
Default Workspace Setup: Newly created teams automatically include two default channels: Town Square (team announcements) and Off-Topic (casual discussions).
Understanding Roles & Permissions
Mattermost utilizes four primary user tiers to balance workspace security and operational flexibility.
Step 2: Team & Channel Administration
Use these steps to manage access tiers within your assigned workspaces.
- Managing Team Administrators
Select the Team Name dropdown menu in the top-left corner.
Click Manage Members.
Locate the user, click their role dropdown, and select Make Team Admin (or Make Team Member to revoke privileges).
Note: If a team has no active Team Admins, submit a support ticket to the P1 Help Desk for administrative intervention.
- Managing Channel Administrators
Open the target channel and click the Channel Name dropdown menu.
Select Manage Members.
Locate the member, click their role dropdown, and select Make Channel Admin (or Make Channel Member).
Step 3: Mobile App Configuration
Supported App: All mobile operations must use the P1 ChatOps mobile app.
Deprecated App: The legacy standalone "Mattermost" app is unsupported and will fail to receive server push notifications.
Mobile Authentication: Logging into Mattermost IL4 via the P1 ChatOps app requires your standard username/password and MFA. AppGate client and CAC are not required for IL4 mobile access.
Common Troubleshooting & Error Resolution
Error: "Notifications cannot be received from this server" (Red Triangle Warning)
Cause: You are using the legacy, deprecated Mattermost mobile app.
Resolution: Uninstall the legacy app and install the official P1 ChatOps app.
Error: "Your account has not been granted access to this application group yet" / Blank Screen
Cause: Missing Keycloak IL group assignment or lack of an active Mattermost license for that specific IL environment.
Resolution: Ensure your account has logged in at least once. If the issue persists, contact your Onboarding Supervisor or Customer Success Team (CST) to verify license allocation.
Error: "An account with that username already exists" or SAML Attribute Failure
Cause: Your account authentication method is set to Email or GitLab instead of SAML, or required attributes (first/last name) are missing in Keycloak.
Resolution: Submit a P1 Support Hub ticket to convert your authentication method to SAML or update Keycloak profile attributes.
Error: "Your account is locked because of too many failed password attempts"
Cause: Applies only to legacy accounts set to Email authentication following repeated incorrect login attempts.
Resolution: Submit a ticket to the P1 Help Desk to sync your Keycloak mattermostid and unlock the account.
Account Deactivation / Inactivity (90 Days)
Cause: Accounts are automatically deactivated after 90 days of continuous inactivity.
Resolution: Simply log into the Mattermost instance via Keycloak. Active Keycloak status will automatically re-enable your Mattermost account.