Administration and Governance encompasses the organizational structure, access control mechanisms, compliance infrastructure, and system settings that enforce security and operational control across your Docupath tenant. This includes organization hierarchies, role-based access control (RBAC), user management, activity logging, regional configuration, and platform limits. These systems work together to ensure that governance, compliance, and access control are consistently applied across all users, documents, and workflows within your organization.
How It Works
Organization Hierarchy
Organizations form the backbone of your tenant structure, enabling multi-level governance and automation scoping:
Parent Organization: The primary entity representing your company or holding group
Sub-Organizations: Branches, departments, or subsidiaries that inherit parent settings while allowing granular control
When creating a parent organization, you configure:
Organization Name: Identifier for your entity
Urgent Flag: Optional feature that automatically marks all incoming documents as high priority
Self-Service Access: When enabled, restricts document visibility to users explicitly mapped to that organization
Sub-organizations inherit all settings from their parent but can override configurations at their level. Notably, each sub-organization can assign one Overriding Trading Party, which automatically sets the Primary Party for all documents routed into that sub-organization.
Organizations serve as scoping boundaries for key automation features including Instruction Builds, Transformations, Rejections, and Enrichment rules.
Role-Based Access Control (RBAC)
Docupath uses role-based access control to define user capabilities within the system:
Role | Capabilities | Notes |
Admin | Full access to all system settings, documents, user management, and integrations | Standard role |
Manager | Broad visibility into workflows and usage insights; monitoring capabilities; no access to Instruction Builds | Standard role |
Reviewer | Review, edit, approve, and reject documents | Standard role |
Validator | Edit and validate documents (cannot approve or reject) | - |
Reviewer & Validator | Combines Reviewer and Validator capabilities | - |
Adding Users: Navigate to Settings → Manage Users → Add User, then enter Name, Email, and assign Role. Optionally, assign the user to a specific Organization (which restricts their document visibility if Self-Service Access is enabled).
System Settings
Configuration options available under system settings:
Branding: Upload a custom logo (recommended: SVG or 300×120 px PNG)
Data Retention: Set the maximum retention period in days (note: deletion is irreversible)
Global Rejection Notification Emails: Configure email addresses to receive rejection notifications
Duplicate Document Handling: Choose between "Reject and Flag" or "Mark as Pending Review"
Activity Logs
Docupath maintains a tamper-evident audit trail capturing all key system actions:
Captured Events:
Document Lifecycle: Uploads, approvals, rejections, reprocessing
Configuration & Security: System settings updates, API credential changes
User Administration: Role assignments, profile edits, invitation status
Log Interface:
Date Range Picker for temporal filtering
Search Bar for keyword-based queries
Log Table with expand controls to view before/after values for each change
Log retention is tied to your tenant's data retention policy
Regions & Countries
Regions allow you to group countries into business-defined organizational units (e.g., Nordics, LATAM, DACH) for operational purposes:
Used as filters in Review Screen, Usage Insights, and Instruction Builds
Enable regional compliance and reporting workflows
Tenant Access & Multi-Tenancy
Access URL:
yourOrganization.docupath.app(subdomain-based)SSO: Google and Microsoft login supported
Multi-Tenant Isolation: Data is never shared across tenants; storage is region-aligned per tenant
Supported Configurations & Options
Organization Settings
Parent organizations with multiple sub-organizations
Organizational overriding trading parties for automatic document routing
Inheritance with granular override capability at sub-organization level
User Management
Role assignment at tenant level or organization level
Self-Service Access mode to restrict visibility by organization membership
Email-based user invitations with role provisioning
Data Governance
Configurable retention windows (irreversible deletion)
Optional urgent flagging for all organization documents
Optional duplicate document handling policies
Branding & Customization
Logo upload with SVG or PNG format support
Subdomain-based tenant isolation
Other Technical Specifications
Data Storage & Compliance
Region-Aligned Storage: Data stored in region matching tenant configuration
Audit Trail: All activity logged with timestamps and before/after value tracking
Data Isolation: Complete multi-tenant isolation with no cross-tenant data sharing
Integration Points
SSO & Authentication
Google and Microsoft identity providers supported
Subdomain-based tenant access enables seamless enterprise integration
Organization-Scoped Automation
Organizations serve as integration points for:
Instruction Builds: Route-based document processing instructions scoped to organizations
Transformations: Data transformation rules scoped to organizational context
Rejections: Rejection policies and routing scoped to organizations
Enrichment: Data enrichment rules scoped to organizations
Activity Log Integration
Audit logs available for integration with compliance and security monitoring systems
Tamper-evident design ensures logs are suitable for regulatory reporting
Known Limitations & Edge Cases
Organization Management
Circular Hierarchies: Sub-organizations cannot be organized into circular dependency structures; hierarchy must remain tree-structured
Trading Party Override: Only one Overriding Trading Party per sub-organization; documents receive the organizational override, not user-level overrides
Inheritance Specifics: Parent organization settings are inherited but only at the time of sub-organization creation; subsequent parent changes do not retroactively update child organizations
User Access & Self-Service
Self-Service Visibility: Users assigned to organizations with Self-Service Access enabled only see documents they uploaded or documents assigned to their organization; this can create isolated silos if not carefully planned
Role Limitations: Manager role explicitly cannot access Instruction Builds; this is a design limitation for security purposes
Validator Role: Validator role cannot approve or reject - only edit and validate; this distinction prevents validators from completing final document disposition
Data Retention
Irreversible Deletion: Once the retention window expires, deleted data cannot be recovered
Global Setting: Max retention period is a tenant-wide setting; organizational or user-level retention exceptions are not supported in standard configurations
Regions
Filtering Only: Regions are purely organizational filters and do not enforce data residency, access control, or document routing; ensure compliance requirements are met through other means
No Auto-Routing: Region assignment is for reporting and filtering - not for automatic document assignment or routing decisions
Platform Limits
User Capacity: 500 user limit per tenant; additional users require tenant expansion
Organization Depth: Two-level hierarchy (parent + sub-organizations); deeper nesting is not supported
Alternate Names: Limited to 20 alternate names per organization; required for complex organizational rebranding scenarios
