/ SONDA · ENTERPRISE

Permissions without roles. One flag per action, per person.

An organization has an owner and divisions; a division is a team of its own — its members, permissions, projects, approval flows, mail and AI seat — inside the same store. A person's access is a signed file of flags: create projects, publish, edit scripts, send, run apps, use Themis. Presets fill the flags in; nothing hides behind a role name.

17 FLAGS NEAREST OVERRIDE WINS WORKING HOURS · NETWORKS · EXPIRY 20 SEATS FREE

The flags

WorkspaceCreate projects. Delete projects. Manage shared environments. Run apps.
ProjectPublish — the one flag the store itself enforces. Create and delete folders. Create, edit and delete items. Send and run. Edit project variables. Edit scripts. Edit checks.
TeamSee the team. Use Themis AI. Discover — the owner's alone to grant.
PoliciesPull on start. Read-only when the store cannot be reached. The apps list, when Run apps is on.
PresetsViewer, Runner, Editor, Publisher, App runner — fillers for the flags, not roles.
/ THE PEOPLE

Owner, divisions, administrators, members.

The owner is the first account, and nothing is closed to the owner. Administrators hold everything in the division they administer, except Discover.

Divisions

Created, renamed and closed by the owner, who names their administrators and may cap their seats. One person can be on several, with one identity and key across all of them. Each division has its own roster, projects, approval flows, mail and Themis seat, inheriting the organization's defaults and overriding them.

Onboarding

A one-time password and a ticket that carries the store sealed under it. Or an invitation, valid fourteen days: the newcomer picks a username and a password, passes company SSO if required, and an administrator approves the request. Usernames never change and are never reused. A team password is twelve characters at least.

The recovery key

One hundred and sixty bits, shown once as eight groups of four. It seals the owner's key a second time, can be renewed under Enterprise Setup, and is what resets the administrator on a Sonda Server. There is no way to recover a password without it — not by LockFlare, not by anyone.

Collaborative workspaces

A workspace belongs to its home division and can be shared with guest divisions; per guest division, approval makes its changes wait for the home administrators. A workspace has no people; it has divisions.

Pause and hide

An administrator pauses a project, a folder or an item for everyone, the administrator included; hides items from the team or from named people; pauses a member. "Tony has had this open for four minutes" — presence per person, heartbeat once a minute.

Nearest override wins

Item or folder, then project, then workspace, then the division set, then the global set. A permission save is written over the version it opened, and a refusal names who saved and when. A Sonda refuses a permissions file older than one it has seen.

/ THE ACCESS WINDOW

When, from where, until when.

Per member, beside the flags.

Days and hours

Working days. Hours from and to, crossing midnight if needed, in a named time zone. A sign-in outside the window is refused — and is a trigger an administrator can be mailed about.

Networks

Addresses and CIDRs the member may work from, read from the computer's own interfaces and sent nowhere. A sign-in from elsewhere is refused and logged.

Until

A last day. A pause, with who paused it — the team page, directory sync or SCIM — so each lifts only its own.

/ LOCKFLARE SONDA

Every flag, in the free edition.

RBAC and identity, listed →