Organization Control
Manage organization access and preferences
Manage local users, authentication, organization preferences, and contact details.
Use this area to manage local users, sign-in options, and organization preferences. To review users, you need users.view. To change users, roles, or authentication, you need users.edit. To invite a user, you need users.invite.
Users and authentication
Create local-user invitations from Users. The recipient completes the invitation through the link in their email. Invitations require a configured organization domain. Use the platform organization-management process, not this page, to create an organization’s first owner.
Sigora supports local accounts and configured external identity providers, including LDAP, Entra OIDC, and Entra SAML. Treat identity-provider changes as security-sensitive. Restrict redirect URLs, issuer details, certificates, and client secrets to the trusted provider. Test a change with a non-owner account before changing a working sign-in method for the whole organization.
Users can update their own profile, email address, password, TOTP enrollment, and portal preferences. Protected changes may require an email MFA confirmation and are recorded in the audit log. Never ask another user to provide an MFA code.
Organization preferences
Use Preferences to manage organization-wide signature behavior. You need config.preferences. Changes are audited and can take a short time to reach message-processing Nodes. After a material change, verify it with a preview and a controlled message.
| Setting | Default and valid values | Effect and caution |
|---|---|---|
| Identify sender for signature | envelope or from_header | Selects the identity used for signature lookup. from_header can represent an on-behalf-of user, so test delegated-mail scenarios carefully. |
| Timezone | UTC or any timezone listed by the UI | Organization default for signature date/time output. Portal timestamps use the viewer browser timezone. |
| Signature fail action | send_without_signature or reject | Choose whether a message that cannot be signed is relayed unchanged or rejected. reject can interrupt mail flow. |
Contact details on the same page can be used in signature templates. Keep one address marked as primary before removing another. For each address, choose a phone type of primary, secondary, or fax.
To verify a change, open full signature preview and inspect the affected address or phone value. Then send a controlled test message. If the result is not as expected, confirm that the change was saved, the timezone is valid, and the correct address remains primary. Allow a short time for the change to reach all Nodes before escalating.