Skip to main content

Administration and Governance

Tenant access and governance controls

Administration and Governance encompasses the organizational structure, access control mechanisms, compliance infrastructure, and system settings that enforce security and operational control across your Docupath tenant. This includes organization hierarchies, role-based access control (RBAC), user management, activity logging, regional configuration, and platform limits. These systems work together to ensure that governance, compliance, and access control are consistently applied across all users, documents, and workflows within your organization.

How It Works

Organization Hierarchy

Organizations form the backbone of your tenant structure, enabling multi-level governance and automation scoping:

  • Parent Organization: The primary entity representing your company or holding group

  • Sub-Organizations: Branches, departments, or subsidiaries that inherit parent settings while allowing granular control

When creating a parent organization, you configure:

  • Organization Name: Identifier for your entity

  • Urgent Flag: Optional feature that automatically marks all incoming documents as high priority

  • Self-Service Access: When enabled, restricts document visibility to users explicitly mapped to that organization

Sub-organizations inherit all settings from their parent but can override configurations at their level. Notably, each sub-organization can assign one Overriding Trading Party, which automatically sets the Primary Party for all documents routed into that sub-organization.

Organizations serve as scoping boundaries for key automation features including Instruction Builds, Transformations, Rejections, and Enrichment rules.

Role-Based Access Control (RBAC)

Docupath uses role-based access control to define user capabilities within the system:

Role

Capabilities

Notes

Admin

Full access to all system settings, documents, user management, and integrations

Standard role

Manager

Broad visibility into workflows and usage insights; monitoring capabilities; no access to Instruction Builds

Standard role

Reviewer

Review, edit, approve, and reject documents

Standard role

Validator

Edit and validate documents (cannot approve or reject)

-

Reviewer & Validator

Combines Reviewer and Validator capabilities

-

Adding Users: Navigate to Settings → Manage Users → Add User, then enter Name, Email, and assign Role. Optionally, assign the user to a specific Organization (which restricts their document visibility if Self-Service Access is enabled).

System Settings

Configuration options available under system settings:

  • Branding: Upload a custom logo (recommended: SVG or 300×120 px PNG)

  • Data Retention: Set the maximum retention period in days (note: deletion is irreversible)

  • Global Rejection Notification Emails: Configure email addresses to receive rejection notifications

  • Duplicate Document Handling: Choose between "Reject and Flag" or "Mark as Pending Review"

Activity Logs

Docupath maintains a tamper-evident audit trail capturing all key system actions:

Captured Events:

  • Document Lifecycle: Uploads, approvals, rejections, reprocessing

  • Configuration & Security: System settings updates, API credential changes

  • User Administration: Role assignments, profile edits, invitation status

Log Interface:

  • Date Range Picker for temporal filtering

  • Search Bar for keyword-based queries

  • Log Table with expand controls to view before/after values for each change

  • Log retention is tied to your tenant's data retention policy

Regions & Countries

Regions allow you to group countries into business-defined organizational units (e.g., Nordics, LATAM, DACH) for operational purposes:

  • Used as filters in Review Screen, Usage Insights, and Instruction Builds

  • Enable regional compliance and reporting workflows

Tenant Access & Multi-Tenancy

  • Access URL: yourOrganization.docupath.app (subdomain-based)

  • SSO: Google and Microsoft login supported

  • Multi-Tenant Isolation: Data is never shared across tenants; storage is region-aligned per tenant

Supported Configurations & Options

Organization Settings

  • Parent organizations with multiple sub-organizations

  • Organizational overriding trading parties for automatic document routing

  • Inheritance with granular override capability at sub-organization level

User Management

  • Role assignment at tenant level or organization level

  • Self-Service Access mode to restrict visibility by organization membership

  • Email-based user invitations with role provisioning

Data Governance

  • Configurable retention windows (irreversible deletion)

  • Optional urgent flagging for all organization documents

  • Optional duplicate document handling policies

Branding & Customization

  • Logo upload with SVG or PNG format support

  • Subdomain-based tenant isolation

Other Technical Specifications

Data Storage & Compliance

  • Region-Aligned Storage: Data stored in region matching tenant configuration

  • Audit Trail: All activity logged with timestamps and before/after value tracking

  • Data Isolation: Complete multi-tenant isolation with no cross-tenant data sharing

Integration Points

SSO & Authentication

  • Google and Microsoft identity providers supported

  • Subdomain-based tenant access enables seamless enterprise integration

Organization-Scoped Automation

Organizations serve as integration points for:

  • Instruction Builds: Route-based document processing instructions scoped to organizations

  • Transformations: Data transformation rules scoped to organizational context

  • Rejections: Rejection policies and routing scoped to organizations

  • Enrichment: Data enrichment rules scoped to organizations

Activity Log Integration

  • Audit logs available for integration with compliance and security monitoring systems

  • Tamper-evident design ensures logs are suitable for regulatory reporting

Known Limitations & Edge Cases

Organization Management

  • Circular Hierarchies: Sub-organizations cannot be organized into circular dependency structures; hierarchy must remain tree-structured

  • Trading Party Override: Only one Overriding Trading Party per sub-organization; documents receive the organizational override, not user-level overrides

  • Inheritance Specifics: Parent organization settings are inherited but only at the time of sub-organization creation; subsequent parent changes do not retroactively update child organizations

User Access & Self-Service

  • Self-Service Visibility: Users assigned to organizations with Self-Service Access enabled only see documents they uploaded or documents assigned to their organization; this can create isolated silos if not carefully planned

  • Role Limitations: Manager role explicitly cannot access Instruction Builds; this is a design limitation for security purposes

  • Validator Role: Validator role cannot approve or reject - only edit and validate; this distinction prevents validators from completing final document disposition

Data Retention

  • Irreversible Deletion: Once the retention window expires, deleted data cannot be recovered

  • Global Setting: Max retention period is a tenant-wide setting; organizational or user-level retention exceptions are not supported in standard configurations

Regions

  • Filtering Only: Regions are purely organizational filters and do not enforce data residency, access control, or document routing; ensure compliance requirements are met through other means

  • No Auto-Routing: Region assignment is for reporting and filtering - not for automatic document assignment or routing decisions

Platform Limits

  • User Capacity: 500 user limit per tenant; additional users require tenant expansion

  • Organization Depth: Two-level hierarchy (parent + sub-organizations); deeper nesting is not supported

  • Alternate Names: Limited to 20 alternate names per organization; required for complex organizational rebranding scenarios

Did this answer your question?