Skip to content
Open the portal
Using the portal

The Settings page

Portal users5 min read

Name, company, industry, size, use cases, stack and the custody region chosen at sign-up. The region cannot be changed: keys and records do not move between regions. To move custody entirely, see taking custody.

Everyone in the workspace, with their role, when they joined and their last sign-in. Owners and admins can Invite: enter a work email and choose a role. Owners may grant admin, engineer or auditor; admins may grant engineer or auditor. Nobody grants owner.

The invitee receives an email with a link that works for seven days and once. Opening it shows the workspace and the role; the person confirms the invited address with a one-time code and joins. A forwarded link is useless to anyone who cannot read the invited mailbox. Pending invitations are listed with Resend and Revoke. A workspace may have 25 pending invitations and send 20 per hour.

Roles can be changed from the same table (never your own, never the owner’s, and an admin cannot change another admin). Removing a member takes effect on their next request; what they created stays, with their name on it. The permission matrix.

Ingest keys for agents and collectors. New key shows the key once; the table shows a name, the last four characters, when it was created and last used. Revoke stops it immediately. Keys can write records and upload originals and read nothing. Engineers, admins and owners manage keys.

An auditor sees every page and every record and can export anything. Every control that would change state is hidden, and if reached by other means the server refuses it before any route runs. A Read-only chip in the header says so.