Inviting users
- Navigate to Organisation → Users
- Click Invite user
- Enter their work email and select an organisation role
- Click Send invite
Organisation roles
Clearance defaults by role
Each user’s effective clearance is the higher of their role default and any explicit override.
To override: Organisation → Users → (user) → Set Clearance.
Multi-membership
Users can belong to multiple Org Units. Each membership is explicit — there is no implicit access from admin roles or parent units. To manage memberships:- Navigate to Organisation → Users
- Click the user row menu → Manage memberships
- Add or remove Org Unit memberships in the dialog
Owner and Org Admin roles do not grant implicit file access. Admins must still hold explicit Org Unit membership to access files in rooms owned by that unit.
Removing people: disable, offboard, or remove
Enclave separates three distinct actions — pick the one that matches your intent. All are available from Organisation → Users → (user row menu).Disabling (freezing) a user
Use Disable account to immediately freeze an account — for example on suspected compromise or suspicious activity. Disabling a user:- Ends every live session instantly — active web sessions and open secure-room connections are terminated and the login token is revoked, so their next action lands them back on the sign-in screen.
- Blocks all future sign-ins until the account is re-enabled.
- Changes no data — files, room and Org Unit memberships, keys, and clearance are all left intact.
Disable does not remove the person from rooms or Org Units — it only locks the account. To remove a departing member’s access and identity, use Offboard or Remove below.
Offboarding a member
Use Offboard member when someone leaves the organisation. Offboarding preserves the organisation’s documents while erasing the individual:- Reassigns every document they owned to the organisation’s primary owner — business records are never destroyed.
- Anonymises their identity (name, email, avatar, credentials) to a tombstone and revokes their sessions.
- Crypto-shreds their zero-knowledge keys and removes them from all rooms and Org Units.
- Keeps a de-identified audit record for compliance (DPDP).
- Organisation → Users → (member) → Offboard member → Request offboarding. (You can also start it from Privacy & Compliance → Privacy Requests when a member has filed an erasure request — use Start offboarding.)
- A second eligible approver (a different Owner or Org Admin) opens Privacy & Compliance → Data-Rights Approvals and approves. Two approvals are required, and the requester cannot approve their own request.
- Once approved, the erasure runs automatically.
- For any Zero-Knowledge rooms the member belonged to, open the room’s Members tab and use the Rotate Key reminder to rotate the room key for forward secrecy.
Two-person approval means your organisation needs at least three eligible approvers (the requester plus two Owners/Org Admins) for offboard and remove to complete.
Removing a member (destroy & purge)
Use Remove user for a complete cleanup — for example a mistaken or test account, or when the organisation requires the person’s files destroyed rather than retained:- Destroys every file they owned (database records and stored objects) — unlike offboarding, their content is not reassigned.
- Crypto-shreds their keys, revokes sessions, anonymises the account, and removes them from all rooms and Org Units.
- Organisation → Users → (member) → Remove user → Request removal.
- A second eligible approver approves in Privacy & Compliance → Data-Rights Approvals.
- The cleanup runs once two approvals are recorded.