Organization Control
Signature and configuration error reference
Common signature-resolution and configuration errors with administrator actions.
Full preview and platform diagnostics can show the following error categories. Include the category, affected sender, approximate UTC time, and relevant preview warning when escalating. Do not include message content or secrets.
| Category | What it means | What to do |
|---|---|---|
invalid_sender_identity | Sigora cannot use the selected sender identity. | Correct the sender source or test with a valid sender. |
no_base_template_assignment | No active Base Template assignment matches the sender. | Add one suitable user, group, or domain assignment. |
ambiguous_base_user_assignment | More than one direct user assignment matches. | Keep one intended direct user assignment. |
ambiguous_base_group_evaluation_order | Matching group assignments use the same evaluation order. | Give the matching group assignments distinct orders. |
ambiguous_base_domain_assignment | More than one domain assignment matches. | Keep one intended domain assignment. |
base_template_not_published | The selected Base Template is not published. | Publish a valid draft. |
base_assignment_template_type_invalid | A Base Template assignment points to a Module. | Select a published Base Template. |
addon_template_not_published | A selected Module is not published. | Publish or correct the Module assignment. |
addon_assignment_template_type_invalid | A Module assignment points to a Base Template. | Select a published Module. |
ambiguous_addon_evaluation_order | Matching Module assignments have a conflicting order. | Set a distinct order or remove the duplicate assignment. |
group_membership_unavailable | Microsoft group membership could not be checked. | Review tenant connectivity and retry after service is restored. |
Correct the configuration in the portal, then use full preview and a controlled message to verify the outcome. If a tenant save succeeds but domain refresh does not, correct the Microsoft Graph issue and run a domain refresh rather than recreating the tenant.