Platform
Users and organisations Beta
Everything belongs to an organisation. People are named inside it, not globally, so your usernames are yours and do not collide with anyone else's.
The organisation
An organisation has a twelve-digit identifier and a name. The identifier is what you type when signing in, alongside your username, because a username is only unique within an organisation.
Whoever registers the organisation becomes its root user. There is exactly one root, and the constraint is enforced by the database rather than by a screen.
Platform roles
| Role | Can do |
|---|---|
| root | Everything an admin can, and is the account that registered the organisation. One per organisation. |
| admin | Invite and disable people, manage boxes, grant and revoke access to boxes, reset a second factor. |
| member | Sign in, and reach the boxes they have been made a custodian of. Nothing else. |
A platform role is not access to a box. Being an admin lets you decide who reaches a box; it does not put you on it. That separation is deliberate, and it is covered in access to a box.
What a user record holds
| Field | Notes |
|---|---|
| username | Lowercase letters and digits, unique within the organisation. |
| Unique within the organisation. Used for invitations, password setting and security notices. | |
| full name | For display, so a trail names a person rather than a handle. |
| password | Stored as an argon2id hash, and empty until the person sets it through an emailed link. |
| second factor | Stored encrypted, with the date it was enrolled. See two-factor. |
| status | invited, active, or disabled. |
| last sign-in | So an unused account is visible. |
The lifecycle
- Invited. An admin adds a username and an email. No password exists yet, so the account cannot be used.
- Set password. The person follows a single-purpose emailed link and chooses a password. Proving control of the inbox is what makes the account theirs.
- Active. They can sign in. Admins must enrol a second factor at their first sign-in.
- Disabled. Sign-in stops immediately and existing sessions are revoked. The record stays, because the trail refers to it and history must keep naming the right person.
Accounts are disabled rather than deleted for that last reason. If someone leaves, disable them and revoke their access; the evidence they produced keeps its author.
Sessions
A platform session is a cookie backed by a server record, with an expiry, a last-seen time, a revoked marker, and a flag recording whether the second factor was satisfied. Revoking a session takes effect immediately, because the record is checked rather than trusted from the cookie alone.
A box session is separate, lasts eight hours, slides while you work, and is created only by a valid ticket.