Skip to content
Docs
foxborne.comRequest a pilot

Invite, change and remove access

Add people to Foxborne, change their role, remove them and set the session policy, all from the Access page. Each change is recorded in the audit log with the admin who made it.

How-toEvery deploymentAdminMarkdown
On this page10

Membership usually arrives through SCIM from your identity provider. The Access page covers the rest: inviting someone, changing a role, removing access at once and setting how long a session lasts.

Before you start#

  • You need the Admin role. Only admins hold Manage hosting, keys and access.
  • Single sign-on is in place. Invited people sign in through your identity provider.

The Members table#

Go to Access. The Members tab lists everyone with access.

ColumnWhat it shows
PersonAvatar, name and job title
EmailThe person's work email
RoleOne of the five roles
Sign-inSingle sign-on, or Local, hardware key for the break-glass account, which also carries a Break-glass chip
Two-factorOn, or Pending first sign-in
US personAsserted or Not asserted, as your identity provider reports it
Last activeA relative time, or an Invited chip

Each row ends with an actions button that opens Change role and Remove access. The note under the table reads: Removing someone in the identity provider removes them here within five minutes. US person status comes from the identity provider and gates evidence marked EXPT.

Invite someone#

  1. Open the invite dialog

    Select Invite, at the top of every tab on Access. The Invite someone dialog opens.

  2. Enter the email and role

    Enter the person's Work email and choose their Role. The list holds the five roles and starts at Investigator.

  3. Send the invitation

    Select Send invitation. The console confirms Invitation sent to and the address. The audit log records Invited user, with the address as the object and the role as the detail.

An address that is not a valid email gets a red outline, and the dialog stays open. The invited person appears with an Invited chip under Last active and Pending first sign-in under Two-factor. Both change once they sign in through your identity provider.

With SCIM on, adding someone to a Foxborne group in the identity provider works as well. See SCIM provisioning.

Change a role#

  1. Open Change role

    On Members, open the person's actions and choose Change role. The dialog Change role for and their name opens, with the note Takes effect on their next request.

  2. Pick the new role

    Select one of the five role cards. Each card shows the role's name and description, as Roles and permissions lists them.

  3. Save

    Select Save. The console confirms the person's new role, and the audit log records Changed role with the person and the role. If you pick the role they already hold, the dialog closes and nothing changes.

Remove access#

  1. Open Remove access

    On Members, open the person's actions and choose Remove access.

  2. Read the confirmation

    The dialog asks Remove and the person's name. It explains: They lose access at once. Their notes, edits and audit entries stay, attributed to them.

  3. Confirm

    Select the red Remove access button. The console confirms the removal, and the audit log records Removed user with the detail Access revoked.

With SCIM on, remove the person in your identity provider as well, so the two lists agree.

Set the session policy#

The Sessions panel on the Sign-in tab holds the session policy.

SettingExample valueChoices in the dialog
Idle timeout30 minutes15 minutes, 30 minutes or 1 hour
Longest session12 hours8 hours, 12 hours or 24 hours
Two-factorRequired for everyoneNot in the dialog
Networks10.0.0.0/8 and the VPN rangeAllowed networks, a list of address ranges
  1. Open the session policy

    Select Edit on Sessions. The Session policy dialog opens.

  2. Choose the limits

    Choose the Idle timeout and the Longest session. List the Allowed networks as address ranges separated by commas, such as 10.0.0.0/8, 172.20.0.0/16.

  3. Save

    Select Save. The console confirms Session policy saved. The audit log records Changed session policy on Access, with a detail such as 30 minutes idle, 12 hours max.

Two-factor is required for everyone, and the dialog has no setting for it.

Break-glass access#

The Break-glass access panel on the Sign-in tab names the local account kept for when the identity provider is down. Its two rules are fixed:

  • Every break-glass sign-in is audited and raises an alert in your SIEM.
  • Requires a hardware security key. Passwords alone are refused.

Break-glass access on the single sign-on page shows how the account signs in.

Check the result#

  • Members shows the new person, the new role or the removal.
  • The audit log's Administration filter lists the Invited user, Changed role, Removed user and Changed session policy entries, each with the admin who made it.
  • The Sessions panel shows the new Idle timeout and Longest session.

Troubleshoot#

The invite dialog stays open. The Work email field has a red outline because the address is not a valid email. Correct it and select Send invitation again.

An invited person still shows Invited. They have not signed in yet. Two-factor reads Pending first sign-in until they do.

Someone cannot open export-controlled evidence. Their US person column reads Not asserted. The status comes from the identity provider, not from this page: see Export-controlled evidence.

The identity provider is down. Sign in with the break-glass account and its hardware security key, as Single sign-on describes.

Next#