Docupath provides secure tenant access through email/password authentication or single sign-on (SSO) via Google or Microsoft. Each organization operates on a dedicated subdomain (yourOrganization.docupath.app) with isolated data and user management. First-time users receive a guided walkthrough to orient them with the platform interface.
How It Works
Accessing Your Tenant
Your Docupath workspace is accessible at a unique subdomain URL in the format yourOrganization.docupath.app. This subdomain is created during initial organization setup and remains constant throughout your organization's use of the platform. All users within your organization log in through the same subdomain URL.
Email and Password Authentication
Traditional email/password login requires users to enter their registered email address and password credentials. Passwords must meet standard security requirements (minimum 8 characters, mixed case, numbers, and special characters recommended).
If you forget your password, use the "Forgot Password" link on the login screen to reset it via email verification. Password reset links expire after 24 hours for security purposes.
Single Sign-On (SSO) Integration
Docupath supports SSO through Google and Microsoft identity providers, allowing users to log in using their existing organizational credentials. During first-time SSO login, users are prompted to authorize Docupath to access their email and profile information.
SSO integration is configured at the organization level rather than per user. Once enabled, users can choose to log in via "Sign in with Google" or "Sign in with Microsoft" buttons on the login screen.
First-Time Login Walkthrough
New users accessing Docupath for the first time are guided through an interactive onboarding experience. This walkthrough introduces core concepts including the document review interface, status definitions, navigation patterns, and key workflows. Users can skip the walkthrough at any time; once skipped, it cannot be accessed again. The walkthrough is role-specific, highlighting features and permissions relevant to the user's assigned role.
Session Management and Security
Login sessions remain valid for up to 7 days. After this period, users will need to log in again. While a user is active, their session is automatically refreshed in the background, ensuring uninterrupted access to the platform.
Users can manually log out from the account menu in the top-right corner. When logging out, all session data is cleared and the user is redirected to the login screen. If a user logs in from a new device or browser, they may be prompted to verify their identity for security purposes.
Multi-User Organization Structure
Your Docupath tenant can accommodate up to 500 users across parent and sub-organization structures. Each user must have a unique email address. Anyone who can manage users, which is admins and managers, invites new users by email from the Users tab under Settings → Manage Users & Roles, and invitations expire after 7 days if not accepted.
Each user is assigned exactly one role. Five system roles are built in: Admin (full access to every module), Manager (everything an admin can do apart from managing roles, Billing & Payments, and the Country and Global tabs of the four per-tab configuration modules), Reviewer (reviews documents and approves or rejects them), Validator (validates documents) and Reviewer and Validator (both). Users with the Reviewer, Validator or Reviewer and Validator role can also reprocess and download documents, but not delete them. System roles are read-only templates, so where none of them fits, an admin builds a named custom role on the Roles tab and assigns it to as many users as needed. Role-based access controls ensure users only see the documents and features their role allows.
The four per-tab configuration modules are Instruction Builds, Transformations, Rejections and Customize Captured Fields. A manager has the Organization and Trading Party tabs of those modules only, while the Country and Global tabs stay with admins.
Supported Configurations and Options
Feature | Details |
Session Duration | Up to 7 days; automatically refreshed while active |
Password Reset | Email-based verification, 24-hour link expiration |
SSO Providers | Google Workspace, Microsoft 365, Microsoft Entra ID |
Invite Expiration | 7 days |
Other Technical Specifications
Specification | Value |
Inactivity Timeout | 24 hours |
Password Reset Link Validity | 24 hours |
Maximum User Accounts Per Tenant | 500 |
Login Rate Limiting | 5 failed attempts per 15 minutes (IP-based) |
Notes
Microsoft 365 and Entra ID Integration: Organizations using Microsoft 365 or Entra ID can configure SSO for seamless employee authentication using their existing Microsoft credentials.
User Invitation System: Admins and managers invite new users by email from the Users tab; invitations trigger automated emails containing a unique signup link.
Role-Based Access Control (RBAC): A user's role determines which features, documents, and actions are available upon login. Navigation follows read access, so the menu shows only the modules the role can at least view, while unavailable actions inside a module are greyed out rather than hidden. Sub-organizations can restrict visibility of parent organization data based on user assignment.
SSO Email Mismatch: If a user's SSO email address does not match their registered Docupath email, they will be treated as a new user. Administrators should ensure email consistency before enabling SSO.
Session Timeout on Mobile: Mobile app sessions may timeout sooner if the app is backgrounded for extended periods. Users will be prompted to re-authenticate.
Password Reset Delays: Password reset emails may take up to 5 minutes to arrive. Users should check spam folders if a reset email is not received.
Sub-Organization Isolation: Users assigned to a sub-organization cannot access documents or data from other sub-organizations unless their account is also mapped to those organizations on the Users tab.
No Guest Account Access: Docupath does not support temporary guest accounts. All users must have active accounts with assigned roles.
