Organization and users¶
Each organization is a separate workspace at its own subdomain (<org>.gxpvalidate.app). Every row of validation data belongs to exactly one organization, and the database itself (PostgreSQL row-level security) prevents one organization from reading or writing another's data.
Organization roles¶
Organization roles decide who manages the workspace. What a person can do inside a validated system is set separately, by system roles.
| Role | Can |
|---|---|
| Owner | Everything an admin can, plus make other people owners. The person who created the organization is its first owner. |
| Admin | Manage users and invitations, organization settings, single sign-on, billing, and membership of every system. |
| Member | Use the app: create systems and work in the systems they are given roles in. |
| Reader | For people who only need to look, such as auditors. Give them no signing roles on systems. |
Nobody can change their own role or deactivate themselves, and only an owner can change another owner.
Invitations¶
Owners and admins invite people from Users (in the main menu):
- Enter the email address and choose a role: Admin, Member or Reader. You cannot invite someone directly as an owner; promote them after they join.
- The invitee receives an email with a link that is valid for 7 days.
- If the organization uses SSO, the link sends them to your identity provider. Otherwise they create a password.
An email address can belong to only one organization. Open invitations can be revoked from the same page.
Deactivating users¶
Deactivate a user rather than deleting them: their signatures and audit-trail entries must stay attributable. A deactivated user cannot sign in.
Organization settings¶
Organization (in the main menu) holds:
- Name of the organization.
- Email domain (for example
example.com), used to route people to your SSO on the shared sign-in page. See Single sign-on. - Session timeout: minutes of inactivity before a session ends (default 30, EU Annex 11 ยง12). Signatures always re-authenticate regardless of this setting.
- SSO enabled / enforced. See Single sign-on.