Platform administration
Platform admins see an Administration section in the Hub's sidebar
(/admin): Overview, Organizations, Users, Invitations
and Audit log. Other users who open these pages are sent to
Products.
Platform admins are global admins in every product. Keep the group small and make sure each of them uses two-factor authentication.
Overview
Overview counts Users, Active users, Platform admins, Organizations, Active organizations and Open invitations. Access by product shows, per product, how many organizations have it and how many users have a role in it. The page refreshes every 30 seconds.
Products in beta
Products lists every product with its status. A product in Beta is open to platform admins only:
- the Hub issues its sign-in tokens to platform admins only, so nobody else can open it, even with a role in it;
- organizations and their users do not see it, neither in the launcher nor in the product lists of the organization and member pages;
- platform admins see it in the launcher grayed out, with a Beta badge.
Release to organizations opens a beta product to the organizations
that have it enabled and to their users with a role in it; Put in beta
takes it back to platform admins only. Organizations keep their products
and roles either way. Both ask for confirmation and are recorded in the
audit log (product.update).
Entrosity Edge, Entrosity Sphere and Entrosity Matrix start in beta. A new product is also registered disabled until it is deployed: a disabled product is hidden from everyone and cannot be given to organizations (Running Entrosity Sphere → Rollout).
Organizations
Administration → Organizations lists every organization with its Slug, Status, Products, number of Members and when it was Created. Search by name or slug, and filter by status (Active, Suspended). Choose a name to open the organization.
Create an organization
Choose Create organization and fill in:
| Field | Meaning |
|---|---|
| Name | The customer's name, 1 to 200 characters. |
| Slug | A short unique name, filled in from the name. 3 to 40 characters: lowercase letters, digits and hyphens. It cannot be changed later. A slug in use is refused (slug_taken). |
| Products | The products the organization has, for example Entrosity Axis. |
| Require two-factor authentication | Members must set up two-factor authentication before they can open products. |
| First organization admin (optional) | An e-mail address. This person is invited as organization Admin with the most privileged role in every selected product (Axis: Tenant admin). |
Choose Create organization. The organization page opens. Without a first admin, invite members from that page.
With Entrosity Axis selected, the organization appears in Axis as a tenant within about a minute.
Edit an organization
On the organization page, Details has:
- Name;
- Require two-factor authentication before members open a product: members without two-factor authentication are refused by every product until they set it up, and cannot turn it off while they belong to the organization (Your account).
Choose Save. The slug is shown but cannot be changed.
Below, Members and Pending invitations work as for organization admins (Organization members).
Suspend and reactivate
Choose Suspend in Details and confirm.
On the Hub:
- members cannot open the organization's products; its cards in Products are dimmed and marked Suspended;
- no one can be invited to it, and its open invitation links stop working;
- its two-factor requirement no longer applies;
- no data is deleted.
In Axis, within about a minute, the tenant is suspended: its users are signed out of it, its API closes, its agents and connectors are disconnected, and its data is kept. See Tenants.
To undo it, choose Reactivate and confirm. Members get their access back. Axis agents and connectors of the tenant reconnect when their service starts again (at the next reboot, or by starting the service); they do not need to enroll again.
Products per organization
Products on the organization page has one checkbox per product.
- Enable a product by ticking it. Then give members roles in it (Edit on a member, or the user's Access).
- Disable a product by clearing it and confirming Disable. Members lose access to it for this organization.
Disabling a product removes every member's role in it for this organization. Enabling it again does not bring the roles back: grant them again.
Disabling Entrosity Axis for an organization suspends its Axis tenant, with the effects described above; Axis keeps the tenant's data. Enabling Axis again reactivates the tenant.
Users
Administration → Users lists every Entrosity account: User, Status, Platform admin, number of Organizations and Last sign-in. Search by name or e-mail, filter by status (Active, Disabled, Deleted) and by Platform admins or Not platform admins. Deleted users appear only with the Deleted filter.
Choose a user to open their page. The header shows their e-mail, status, whether two-factor authentication is on, and their last sign-in.
Details
- Name.
- Status: Active, or Disabled (cannot sign in). Disabling signs the user out everywhere, in the Hub and in every product; their memberships and roles are kept, so setting them Active again restores their access.
- Platform admin (manages the platform, global admin in every product).
Choose Save. You cannot disable or demote yourself (self_change),
and the Hub must keep at least one active platform admin
(last_platform_admin).
Access
Access edits all of the user's organizations at once. Each row is one organization with the user's Organization role and a role (or No access) for each product that organization has, each role next to its product's name.
- Add organization… adds a row, as Member with no product roles.
- The bin icon removes the user from that organization.
- Save access applies every change together.
Removing or demoting the last active admin of an organization is refused
(last_org_admin).
Sessions and account
- Sign out everywhere ends every session of the user, in the Hub and in every product. They can sign in again.
- Reset authentication helps a user who cannot sign in: see Reset authentication.
- Delete user signs the user out and removes all their memberships and roles. The record is kept for the audit log, and products keep showing the name on past actions. The e-mail address becomes free for a new account. This cannot be undone. You cannot delete yourself, nor the last active platform admin.
Changes to users reach Axis within about a minute.
Reset authentication
Use it when a user lost the phone with their authenticator app and their recovery codes, or when their password may be known to someone else. Choose Reset authentication, tick what to reset and choose Reset:
| Option | What happens |
|---|---|
| Reset two-factor authentication | Two-factor authentication is turned off. The user's authenticator app and recovery codes stop working; they sign in with their password only and can set it up again on Your account. Offered only when two-factor authentication is on. |
| Reset password | The current password stops working at once and any sign-in lockout is cleared. The user gets an e-mail with a link to choose a new password, valid for 24 hours; after that they use Forgot your password? on the sign-in page. Older reset links stop working. Offered only for Active users. |
Both are ticked when available. Either way the user is signed out everywhere, in the Hub and in every product.
If an organization of the user requires two-factor authentication, they must set it up again before they can open its products (they can still sign in to the Hub).
You cannot reset your own authentication (self_reset): change your
password and two-factor authentication on Your account.
The audit log records the reset as user.reset_auth, with what was reset.
Invitations
Administration → Invitations lists every open invitation, newest first: E-mail, Organization, Organization role, Product roles, Platform admin, when it Expires and when the person was Invited. Revoke cancels an invitation.
Choose Invite to invite someone:
- Enter the E-mail address.
- Tick Platform admin, choose an Organization (optional), or both. Only active organizations are listed.
- With an organization, choose the Organization role and a role in each of its products.
- Choose Send invitation.
The link is valid for 7 days. An invitation that would grant nothing
new is refused (already_member, already_platform_admin).
Audit log
Administration → Audit log records every change to accounts, organizations and access, and every sign-in, newest first: When, Actor, Action, Resource and Organization. Details shows the IP address, request ID, and the state before and after the change.
Filter by Action (the exact name, for example user.update),
Organization, From and To, then choose Filter.
| Actions | Recorded when |
|---|---|
auth.login, auth.login_failed, auth.logout | Sign-in, failed sign-in (with the reason), sign-out. |
auth.password_change, auth.password_reset_requested, auth.password_reset | Password changes and resets. |
auth.totp_enable, auth.totp_disable | Two-factor authentication turned on or off. |
auth.session_revoke, auth.refresh_reuse_detected, auth.session_revoked_inactive | A session ended from Sessions, or by the Hub (a stolen session token was reused, or the user is no longer active). |
auth.step_up | A product asked for the password before a sensitive action. |
user.update, user.update_profile, user.set_access, user.revoke_sessions, user.reset_auth, user.delete, user.bootstrap_admin | User administration and profile changes. |
organization.create, organization.update, organization.suspend, organization.reactivate, organization.product_enable, organization.product_disable | Organization administration. |
member.update, member.remove | Members page changes. |
invitation.create, invitation.accept, invitation.revoke | Invitations. |
First platform admin
A new installation has no platform admin. Create the first one on the
server with platform-server bootstrap-admin, typing the password (at
least 12 characters) on standard input:
platform-server bootstrap-admin --email [email protected] --password-stdin
With the production compose file, in /opt/entrosity/deploy:
docker compose -f docker-compose.prod.yml --env-file .env run --rm platform \
bootstrap-admin --email [email protected] --password-stdin
--name sets the display name (default Administrator). The command only
works while no platform admin exists (bootstrap_done). Then sign in at
the Hub, set up two-factor authentication, and invite the other platform
admins from Invitations.
Axis installations that signed users in themselves were moved to the Hub
with import-rmm, which copied their users and made their global admins
platform admins (Moving Entrosity Hub);
it needs an Axis database from before migration 0013.