People work together in organizations. Everyone in one is an admin or a member, and a member can be limited to some of its projects.
Organizations
Your first sign-in takes you to New Organization. Later, Add organization in the sidebar's organization menu makes another one, or the CLI:
1sigillo orgs create --name my-company
Whoever creates an organization is its admin. Its name can't be changed yet.
On Organization settings, in the sidebar:
Leave organization takes you out, and your API tokens for its projects stop working. Only a new invitation brings you back. The last admin can't leave.
Delete this organization, for admins, deletes every project in it, with their environments, secrets, history, access, invitations and API tokens. It asks you to type the organization's name.
Admins and members
Member
Admin
Create projects and environments, read and change secrets
In the projects they can open
Everywhere
Rename or delete a project or environment
When it has no admin-only or protected environment
Invite, change roles, remove people, set project access
No
Yes
Auto-join, an environment's Min Role and protection, deleting the organization
No
Yes
Admins always reach every project. In an organization with a protected environment, admin actions also take the admin's passkey: see admin actions.
Invite people
On the organization's Members page, in the sidebar, an admin clicks Invite member, optionally ticks Limit to specific projects and picks them, and clicks Generate invite link. Share the link with the people you invite:
They sign in first, so the sign-in allowlist must let them in, and then click Join organization.
They join as members, with the projects the invite names, or all of them.
The link works for everyone who has it, as often as it's used, for 7 days. It can't be withdrawn earlier: it stops working when it expires, or when the admin who made it leaves, is removed or stops being an admin.
Someone who left or was removed gets back in only with an invitation made after that.
Auto-join by email domain
With auto-join, anyone who signs in with a verified email address of your domain joins the organization as a member on their next page load, with access to every project. An admin turns it on when creating the organization, or later on Organization settings → Auto-join by email domain.
The domain is the one of the admin's own email address, which must be verified.
Public email domains such as gmail.com or outlook.com can't be used.
Only one organization can auto-join a domain.
Someone who left or was removed isn't added again: only a new invitation brings them back.
Limit a member to some projects
The Members page lists everyone in the organization, with their role and projects. Members see the list too, including everyone's email address, but can't change it.
An admin clicks a member's Projects cell to choose Full access to all projects, or the projects they may open. A member with none sees no projects.
Admin-only environments
Set Min Role to Admin on the Environments tab, and members can't open the environment's secrets or its history, rename or delete it, or rename or delete its project. A member can't create a token for the whole project either, and any token reaches the environment only while its creator is an admin.
Change roles and remove people
On the Members page, an admin changes a role in the Role column. An organization always keeps at least one admin. When an admin becomes a member, the invite links they made are deleted, their machine tokens no longer reach protected environments, and their trust rules stop working until another admin renews them.
The trash icon removes someone from the organization. Their API tokens and trust rules for its projects go with them (renew a rule first to keep it), and so do the invite links they made; the secrets they wrote stay. For everything else to do when someone leaves, see when someone leaves.
Who can sign in
By default anyone with a Google account can sign in to your instance. The sign-in allowlist limits it to the addresses and domains you list. Someone taken off it is signed out on their next request, and their API tokens stop working.
If your team is a Google Cloud organization, through Google Workspace or Cloud Identity, create the Google OAuth client in a project that belongs to it and set its audience to Internal (Google Auth Platform → Audience). Google then only signs in members of your organization, before Sigillo's own list is checked.
Your sessions
Sessions, in the user menu, lists the browsers and CLI logins signed in as you, with their device, IP address and sign-in time. End signs one out, End all other sessions all but the current one. A login ends after 7 days without use, and 30 days after its sign-in however often it's used; the CLI then asks you to run sigillo login again. The list only shows for a sign-in less than a day old: sign in again to see it.