Docupath provides secure tenant access through email/password authentication or single sign-on (SSO) via Google or Microsoft. Each organization operates on a dedicated subdomain (yourOrganization.docupath.app) with isolated data and user management. First-time users receive a guided walkthrough to orient them with the platform interface.
How It Works
Accessing Your Tenant
Your Docupath workspace is accessible at a unique subdomain URL in the format yourOrganization.docupath.app. This subdomain is created during initial organization setup and remains constant throughout your organization's use of the platform. All users within your organization log in through the same subdomain URL.
Email and Password Authentication
Traditional email/password login requires users to enter their registered email address and password credentials. Passwords must meet standard security requirements (minimum 8 characters, mixed case, numbers, and special characters recommended).
If you forget your password, use the "Forgot Password" link on the login screen to reset it via email verification. Password reset links expire after 24 hours for security purposes.
Single Sign-On (SSO) Integration
Docupath supports SSO through Google and Microsoft identity providers, allowing users to log in using their existing organizational credentials. During first-time SSO login, users are prompted to authorize Docupath to access their email and profile information.
SSO integration is managed by your Admin role user. Once enabled, users can choose to log in via "Sign in with Google" or "Sign in with Microsoft" buttons on the login screen.
First-Time Login Walkthrough
New users accessing Docupath for the first time are guided through an interactive onboarding experience. This walkthrough introduces core concepts including the document review interface, status definitions, navigation patterns, and key workflows. Users can skip the walkthrough at any time; once skipped, it cannot be accessed again. The walkthrough is role-specific, highlighting features and permissions relevant to the user's assigned role.
Session Management and Security
Login sessions remain valid for up to 7 days. After this period, users will need to log in again. While a user is active, their session is automatically refreshed in the background, ensuring uninterrupted access to the platform.
Users can manually log out from the account menu in the top-right corner. When logging out, all session data is cleared and the user is redirected to the login screen. If a user logs in from a new device or browser, they may be prompted to verify their identity for security purposes.
Multi-User Organization Structure
Your Docupath tenant can accommodate up to 500 users across parent and sub-organization structures. Each user must have a unique email address. Administrators can invite new users by email, and invitations expire after 7 days if not accepted.
Users can be assigned one of four roles: Admin (full platform access), Manager (document management and export), Reviewer (view and comment on documents), or Validator (review and approve documents). Role-based access controls ensure users only see documents and features appropriate to their permissions.
Supported Configurations and Options
Feature | Details |
Session Duration | Up to 7 days; automatically refreshed while active |
Password Reset | Email-based verification, 24-hour link expiration |
SSO Providers | Google Workspace, Microsoft 365, Microsoft Entra ID |
Invite Expiration | 7 days |
Other Technical Specifications
Specification | Value |
Inactivity Timeout | 24 hours |
Password Reset Link Validity | 24 hours |
Maximum User Accounts Per Tenant | 500 |
Login Rate Limiting | 5 failed attempts per 15 minutes (IP-based) |
Notes
Microsoft 365 and Entra ID Integration: Organizations using Microsoft 365 or Entra ID can configure SSO for seamless employee authentication using their existing Microsoft credentials.
User Invitation System: Administrators invite new users by email; invitations trigger automated emails containing a unique signup link.
Role-Based Access Control (RBAC): User roles determine which features, documents, and actions are available upon login. Sub-organizations can restrict visibility of parent organization data based on user assignment.
SSO Email Mismatch: If a user's SSO email address does not match their registered Docupath email, they will be treated as a new user. Administrators should ensure email consistency before enabling SSO.
Session Timeout on Mobile: Mobile app sessions may timeout sooner if the app is backgrounded for extended periods. Users will be prompted to re-authenticate.
Password Reset Delays: Password reset emails may take up to 5 minutes to arrive. Users should check spam folders if a reset email is not received.
Sub-Organization Isolation: Users assigned to a sub-organization cannot access documents or data from other sub-organizations unless explicitly granted cross-organizational permissions by the parent Admin.
No Guest Account Access: Docupath does not support temporary guest accounts. All users must have active accounts with assigned roles.
