Skip to main content

Login and User Authentication

Accessing your Docupath tenant using email credentials and/or SSO via Google or Microsoft

Docupath provides secure tenant access through email/password authentication or single sign-on (SSO) via Google or Microsoft. Each organization operates on a dedicated subdomain (yourOrganization.docupath.app) with isolated data and user management. First-time users receive a guided walkthrough to orient them with the platform interface.

How It Works

Accessing Your Tenant

Your Docupath workspace is accessible at a unique subdomain URL in the format yourOrganization.docupath.app. This subdomain is created during initial organization setup and remains constant throughout your organization's use of the platform. All users within your organization log in through the same subdomain URL.

Email and Password Authentication

Traditional email/password login requires users to enter their registered email address and password credentials. Passwords must meet standard security requirements (minimum 8 characters, mixed case, numbers, and special characters recommended).

If you forget your password, use the "Forgot Password" link on the login screen to reset it via email verification. Password reset links expire after 24 hours for security purposes.

Single Sign-On (SSO) Integration

Docupath supports SSO through Google and Microsoft identity providers, allowing users to log in using their existing organizational credentials. During first-time SSO login, users are prompted to authorize Docupath to access their email and profile information.

SSO integration is configured at the organization level rather than per user. Once enabled, users can choose to log in via "Sign in with Google" or "Sign in with Microsoft" buttons on the login screen.

First-Time Login Walkthrough

New users accessing Docupath for the first time are guided through an interactive onboarding experience. This walkthrough introduces core concepts including the document review interface, status definitions, navigation patterns, and key workflows. Users can skip the walkthrough at any time; once skipped, it cannot be accessed again. The walkthrough is role-specific, highlighting features and permissions relevant to the user's assigned role.

Session Management and Security

Login sessions remain valid for up to 7 days. After this period, users will need to log in again. While a user is active, their session is automatically refreshed in the background, ensuring uninterrupted access to the platform.

Users can manually log out from the account menu in the top-right corner. When logging out, all session data is cleared and the user is redirected to the login screen. If a user logs in from a new device or browser, they may be prompted to verify their identity for security purposes.

Multi-User Organization Structure

Your Docupath tenant can accommodate up to 500 users across parent and sub-organization structures. Each user must have a unique email address. Anyone who can manage users, which is admins and managers, invites new users by email from the Users tab under Settings → Manage Users & Roles, and invitations expire after 7 days if not accepted.

Each user is assigned exactly one role. Five system roles are built in: Admin (full access to every module), Manager (everything an admin can do apart from managing roles, Billing & Payments, and the Country and Global tabs of the four per-tab configuration modules), Reviewer (reviews documents and approves or rejects them), Validator (validates documents) and Reviewer and Validator (both). Users with the Reviewer, Validator or Reviewer and Validator role can also reprocess and download documents, but not delete them. System roles are read-only templates, so where none of them fits, an admin builds a named custom role on the Roles tab and assigns it to as many users as needed. Role-based access controls ensure users only see the documents and features their role allows.

The four per-tab configuration modules are Instruction Builds, Transformations, Rejections and Customize Captured Fields. A manager has the Organization and Trading Party tabs of those modules only, while the Country and Global tabs stay with admins.

Supported Configurations and Options

Feature

Details

Session Duration

Up to 7 days; automatically refreshed while active

Password Reset

Email-based verification, 24-hour link expiration

SSO Providers

Google Workspace, Microsoft 365, Microsoft Entra ID

Invite Expiration

7 days

Other Technical Specifications

Specification

Value

Inactivity Timeout

24 hours

Password Reset Link Validity

24 hours

Maximum User Accounts Per Tenant

500

Login Rate Limiting

5 failed attempts per 15 minutes (IP-based)

Notes

  • Microsoft 365 and Entra ID Integration: Organizations using Microsoft 365 or Entra ID can configure SSO for seamless employee authentication using their existing Microsoft credentials.

  • User Invitation System: Admins and managers invite new users by email from the Users tab; invitations trigger automated emails containing a unique signup link.

  • Role-Based Access Control (RBAC): A user's role determines which features, documents, and actions are available upon login. Navigation follows read access, so the menu shows only the modules the role can at least view, while unavailable actions inside a module are greyed out rather than hidden. Sub-organizations can restrict visibility of parent organization data based on user assignment.

  • SSO Email Mismatch: If a user's SSO email address does not match their registered Docupath email, they will be treated as a new user. Administrators should ensure email consistency before enabling SSO.

  • Session Timeout on Mobile: Mobile app sessions may timeout sooner if the app is backgrounded for extended periods. Users will be prompted to re-authenticate.

  • Password Reset Delays: Password reset emails may take up to 5 minutes to arrive. Users should check spam folders if a reset email is not received.

  • Sub-Organization Isolation: Users assigned to a sub-organization cannot access documents or data from other sub-organizations unless their account is also mapped to those organizations on the Users tab.

  • No Guest Account Access: Docupath does not support temporary guest accounts. All users must have active accounts with assigned roles.

Did this answer your question?