Identity and access
Tenant
Administer an organization's identity and access: users, guests, groups, roles, applications, sign-in logs, the audit log and the sign-in policy.
Tenant at https://tenant.cactive.com.au is where owners and administrators run their organization's identity and access. Your own account (profile, password, passkeys, sessions, devices, keys) stays at https://id.cactive.com.au.
Tenant is for owners and admins (tenant:read to look, tenant:write to change). A custom role can give someone else either. Everyone else who opens it is told they don't have access.
Overview
The organization's name, slug, logo and contact address, its plan, member and app counts, the sign-in policy, and recommendations computed from its data:
- owners and administrators without a passkey, and members who sign in with a password alone
- a single owner, or many administrators for the organization's size
- invites waiting for more than 14 days
- keys and sign-in client secrets that expire within 30 days (or have)
- guests whose access has ended, and members who haven't signed in for 90 days
Each links to the page that fixes it.
Users
Users lists members with their role (and the role a group gives them, when higher), title, department, how they sign in (passkey, authenticator app, text code, password only), their last sign-in and whether they're blocked or a guest. Search by name, email, title or department, and filter by role, status, sign-in age or two-step sign-in. Export CSV downloads the list.
Invite
Invite sends an email with a link (7 days by default). Choose the role, title and department, the groups the person joins, and whether they're a guest: someone from outside the organization, who can be a developer or viewer, with access that ends after 7 to 365 days (or never). Only owners invite owners.
From CSV invites up to 200 people at once, one per line as email,role,title,department (a header row is optional). Each line succeeds or fails on its own: someone who's already a member, an unknown role or a bad address is reported and the rest are sent. Inviting an address again replaces its pending invite. Invites lists pending ones with Resend (a new link) and Revoke.
Change, block, end sessions, remove
Open someone to:
- change their role, title, department or, for guests, when their access ends. Only owners change owners, nobody assigns a role above their own, and the last owner can't be demoted.
- Block sign-in: they stay a member but can't get into this organization. No new tokens are issued for it, and open apps, the API, MCP clients, the phone assistant and the keys they created stop reaching it within 30 seconds. Their account and other organizations aren't affected. Unblocking asks them to sign in again; their keys work again.
- End sessions: sign-ins from before now stop reaching this organization (they sign in again, Apple devices signed in to its mailboxes too; app passwords keep working), and MCP clients they connected here are disconnected. Optionally also revoke the keys they created here (API, MCP and command-line git keys).
- Remove: they lose access at once, and so do the keys they created here (until they're restored). For 30 days Users → Removed restores them with their role, attributes, groups and app assignments; Delete now forgets them sooner.
Their page also lists their groups, custom roles, assigned apps, browser sessions (device, method, place), the keys they created here and their recent sign-ins.
Groups
Groups are the organization's teams. Each has owners (who manage its members, also from their account at https://id.cactive.com.au) and members. A group can give its members:
- a role: administrator, developer or viewer. Members get the higher of their own role and their groups'. Owner is only given to people directly.
- custom roles
- write access to a Serverless App Service or repository, on top of their role (see team access)
- access to apps that require assignment
Adding someone to a group, or taking them out, counts as giving or taking its role and custom roles, so the same rules apply, also to a group's owners in https://id.cactive.com.au. A demotion or a group change applies within seconds, also to open sessions and to the keys the person made.
Owner-only changes
Some changes are for owners, made by themselves in Tenant, never by an administrator, a key (even one an owner made), Caity or an MCP client:
- making, changing, blocking or removing an owner
- the sign-in policy, exporting the organization's data, and deleting the organization
- restricted repositories' access lists, and adding people to a group on one
- who reaches a mailbox an owner uses
- in the platform organization, giving administrator (it carries platform access)
Refused attempts are recorded in the audit log (member.escalation_refused).
Roles
Roles shows the built-in roles with every permission (scope) they hold, and who has each, directly or through a group. See Roles and scopes.
Custom roles are named sets of scopes added on top of a holder's role, for people who need one thing without a broader role: a helpdesk that can read the directory and invite people, an auditor who reads the audit log. Assign them to members or groups. You can only put scopes you hold into a role, assign it, change it or delete it. Deleting a role takes its scopes from everyone holding it. An organization can have up to 50.
Applications
Applications lists:
- Sign-in clients of the organization's Serverless App Services (Sign in with), with their redirect URIs and secret expiry. Assignment required lets only the people and groups you assign sign in: everyone else is sent back to the app with
access_denied, and existing sign-ins stop at their next refresh. Rotate replaces the secret with one that lasts 30 days to 2 years, or never; an expired secret is refused at the token endpoint. - Keys of the organization (API, MCP and agent keys) with who created them, their last use and expiry.
- MCP clients members connected to this organization, with the permissions each gave. Disconnect removes it for everyone.
Sign-in policy
The policy decides what a sign-in needs to reach this organization:
- Require: any sign-in, a passkey or two-step sign-in (a password followed by a code from an authenticator app, a backup code, a code by text or a request approved on a phone), or a passkey only.
- Allowed methods: password, passkey, or both.
- Sign-ins last at most: hours after which a sign-in stops reaching the organization and the person signs in again.
- Grace period: when tightening the policy, up to 90 days in which members who don't meet it keep access and are told what to set up.
It's enforced when ID issues tokens for every app, the command line and MCP clients: an organization the sign-in doesn't meet is left out and listed with the reason. People see why on their account page at https://id.cactive.com.au, with what to do (add a passkey or an authenticator app, turn on text codes, sign in again). The command line and MCP clients have no browser sign-in, so the person's enrollment (a passkey, an authenticator app, or text codes on) counts instead. Only owners change the policy, and an owner who doesn't meet a stricter one yet has to give a grace period. Who it leaves out lists the members who don't meet it.
Sign-in logs and audit log
Sign-in logs list members' sign-ins and failed attempts at ID, newest first: result (a locked address shows as Locked), method, address, approximate place and device. Filter by member or result.
Audit log is the organization's audit log with its daily export, moved here from Cloud. Every change in Tenant is recorded (member.*, team.*, role.*, policy.update, oauth_client.*).
API and MCP
Everything here is in the API under /v1/orgs/:orgId/tenant (reference). MCP clients with tenant:read get tenant_overview, tenant_users_list, tenant_user_get, tenant_groups_list, tenant_group_get, tenant_roles_list, tenant_sign_ins and tenant_policy_get; with tenant:write also tenant_invite, tenant_user_update, tenant_user_block, tenant_user_unblock, tenant_user_revoke_sessions and tenant_group_member_set (tools).