enTrail

Platform

Users and organisations Beta

Everything belongs to an organisation. People are named inside it, not globally, so your usernames are yours and do not collide with anyone else's.

The beta console is live at demoplatform.entrail.io. Registration is open: create an organisation, add people, and try the sign-in described here. It is a beta environment, not production — it is for trying the system, so do not put anything in it you would need to rely on later. Evidence that has to stand up belongs on a box of your own.

The organisation

An organisation has a twelve-digit identifier and a name. The identifier is what you type when signing in, alongside your username, because a username is only unique within an organisation.

Whoever registers the organisation becomes its root user. There is exactly one root, and the constraint is enforced by the database rather than by a screen.

Platform roles

RoleCan do
rootEverything an admin can, and is the account that registered the organisation. One per organisation.
adminInvite and disable people, manage boxes, grant and revoke access to boxes, reset a second factor.
memberSign in, and reach the boxes they have been made a custodian of. Nothing else.

A platform role is not access to a box. Being an admin lets you decide who reaches a box; it does not put you on it. That separation is deliberate, and it is covered in access to a box.

What a user record holds

FieldNotes
usernameLowercase letters and digits, unique within the organisation.
emailUnique within the organisation. Used for invitations, password setting and security notices.
full nameFor display, so a trail names a person rather than a handle.
passwordStored as an argon2id hash, and empty until the person sets it through an emailed link.
second factorStored encrypted, with the date it was enrolled. See two-factor.
statusinvited, active, or disabled.
last sign-inSo an unused account is visible.

The lifecycle

  1. Invited. An admin adds a username and an email. No password exists yet, so the account cannot be used.
  2. Set password. The person follows a single-purpose emailed link and chooses a password. Proving control of the inbox is what makes the account theirs.
  3. Active. They can sign in. Admins must enrol a second factor at their first sign-in.
  4. Disabled. Sign-in stops immediately and existing sessions are revoked. The record stays, because the trail refers to it and history must keep naming the right person.

Accounts are disabled rather than deleted for that last reason. If someone leaves, disable them and revoke their access; the evidence they produced keeps its author.

Sessions

A platform session is a cookie backed by a server record, with an expiry, a last-seen time, a revoked marker, and a flag recording whether the second factor was satisfied. Revoking a session takes effect immediately, because the record is checked rather than trusted from the cookie alone.

A box session is separate, lasts eight hours, slides while you work, and is created only by a valid ticket.