Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

Teams and access

People work together in organizations. Everyone in one is an admin or a member, and a member can be limited to some of its projects.

Organizations

Your first sign-in takes you to New Organization. Later, Add organization in the sidebar's organization menu makes another one, or the CLI:
sigillo orgs create --name my-company
Whoever creates an organization is its admin. Its name can't be changed yet.
On Organization settings, in the sidebar:
  • Leave organization takes you out, and your API tokens for its projects stop working. Only a new invitation brings you back. The last admin can't leave.
  • Delete this organization, for admins, deletes every project in it, with their environments, secrets, history, access, invitations and API tokens. It asks you to type the organization's name.

Admins and members

MemberAdmin
Create projects and environments, read and change secretsIn the projects they can openEverywhere
Rename or delete a project or environmentWhen it has no admin-only or protected environmentAlways; a protected one takes a passkey
API tokensCreate their own, delete their ownAlso delete anyone's, and create machine tokens and trust rules
History: changesIn the environments they can openEverywhere, and purge old values
History: reads of protected environmentsNoYes
Invite, change roles, remove people, set project accessNoYes
Auto-join, an environment's Min Role and protection, deleting the organizationNoYes
Admins always reach every project. In an organization with a protected environment, admin actions also take the admin's passkey: see admin actions.

Invite people

On the organization's Members page, in the sidebar, an admin clicks Invite member, optionally ticks Limit to specific projects and picks them, and clicks Generate invite link. Share the link with the people you invite:
  • They sign in first, so the sign-in allowlist must let them in, and then click Join organization.
  • They join as members, with the projects the invite names, or all of them.
  • The link works for everyone who has it, as often as it's used, for 7 days. It can't be withdrawn earlier: it stops working when it expires, or when the admin who made it leaves, is removed or stops being an admin.
Someone who left or was removed gets back in only with an invitation made after that.

Auto-join by email domain

With auto-join, anyone who signs in with a verified email address of your domain joins the organization as a member on their next page load, with access to every project. An admin turns it on when creating the organization, or later on Organization settings → Auto-join by email domain.
  • The domain is the one of the admin's own email address, which must be verified.
  • Public email domains such as gmail.com or outlook.com can't be used.
  • Only one organization can auto-join a domain.
  • Someone who left or was removed isn't added again: only a new invitation brings them back.

Limit a member to some projects

The Members page lists everyone in the organization, with their role and projects. Members see the list too, including everyone's email address, but can't change it.
An admin clicks a member's Projects cell to choose Full access to all projects, or the projects they may open. A member with none sees no projects.

Admin-only environments

Set Min Role to Admin on the Environments tab, and members can't open the environment's secrets or its history, rename or delete it, or rename or delete its project. A member can't create a token for the whole project either, and any token reaches the environment only while its creator is an admin.

Change roles and remove people

On the Members page, an admin changes a role in the Role column. An organization always keeps at least one admin. When an admin becomes a member, the invite links they made are deleted, their machine tokens no longer reach protected environments, and their trust rules stop working until another admin renews them.
The trash icon removes someone from the organization. Their API tokens and trust rules for its projects go with them (renew a rule first to keep it), and so do the invite links they made; the secrets they wrote stay. For everything else to do when someone leaves, see when someone leaves.

Who can sign in

By default anyone with a Google account can sign in to your instance. The sign-in allowlist limits it to the addresses and domains you list. Someone taken off it is signed out on their next request, and their API tokens stop working.
If your team is a Google Cloud organization, through Google Workspace or Cloud Identity, create the Google OAuth client in a project that belongs to it and set its audience to Internal (Google Auth Platform → Audience). Google then only signs in members of your organization, before Sigillo's own list is checked.

Your sessions

Sessions, in the user menu, lists the browsers and CLI logins signed in as you, with their device, IP address and sign-in time. End signs one out, End all other sessions all but the current one. A login ends after 7 days without use, and 30 days after its sign-in however often it's used; the CLI then asks you to run sigillo login again. The list only shows for a sign-in less than a day old: sign in again to see it.