Skip to content

Organization and users

Each organization is a separate workspace at its own subdomain (<org>.gxpvalidate.app). Every row of validation data belongs to exactly one organization, and the database itself (PostgreSQL row-level security) prevents one organization from reading or writing another's data.

Organization roles

Organization roles decide who manages the workspace. What a person can do inside a validated system is set separately, by system roles.

Role Can
Owner Everything an admin can, plus make other people owners. The person who created the organization is its first owner.
Admin Manage users and invitations, organization settings, single sign-on, billing, and membership of every system.
Member Use the app: create systems and work in the systems they are given roles in.
Reader For people who only need to look, such as auditors. Give them no signing roles on systems.

Nobody can change their own role or deactivate themselves, and only an owner can change another owner.

Invitations

Owners and admins invite people from Users (in the main menu):

  1. Enter the email address and choose a role: Admin, Member or Reader. You cannot invite someone directly as an owner; promote them after they join.
  2. The invitee receives an email with a link that is valid for 7 days.
  3. If the organization uses SSO, the link sends them to your identity provider. Otherwise they create a password.

An email address can belong to only one organization. Open invitations can be revoked from the same page.

Deactivating users

Deactivate a user rather than deleting them: their signatures and audit-trail entries must stay attributable. A deactivated user cannot sign in.

Organization settings

Organization (in the main menu) holds:

  • Name of the organization.
  • Email domain (for example example.com), used to route people to your SSO on the shared sign-in page. See Single sign-on.
  • Session timeout: minutes of inactivity before a session ends (default 30, EU Annex 11 ยง12). Signatures always re-authenticate regardless of this setting.
  • SSO enabled / enforced. See Single sign-on.