Organizations, workspaces and roles
bb-sign organizes work in two layers so that each person sees and does exactly what they should. Envelopes live in workspaces inside an organization: the workspace role defines what someone can do with its envelopes, and the organization role defines what they can administer (users, labels, certificate).
The organization
Section titled “The organization”The organization holds everything that belongs to a customer: users, workspaces, envelopes, documents, label keys, API credentials, webhooks and certificate. Each organization is fully isolated from the others. A user belongs to one organization only, and an API credential always acts on behalf of the organization that created it.
Binary Bridges, as platform administrator, creates organizations.
Workspaces
Section titled “Workspaces”A workspace groups envelopes inside the organization. It lets you separate areas (Human Resources, Purchasing, Legal) and control who sees what: each person sees the envelopes of the workspaces they have access to.
Every organization has the General workspace, created along with it. The application shows it as General (everyone) because every member of the organization can work in it without being granted access. General is permanent: it cannot be renamed or deleted.
Administrators create the other workspaces and decide who takes part in each one. A workspace can be deleted once it no longer holds envelopes, archived ones included. The steps are in Workspaces and members.
Workspace roles
Section titled “Workspace roles”In each workspace, a person or an API credential holds one of four roles. The application calls
them Viewer, Auditor, Contributor and Manager; the API uses viewer, auditor,
contributor and manager. Each role includes everything the previous one allows:
| Role | What it adds |
|---|---|
viewer (Viewer) |
See the list and the detail of envelopes, archived ones included. |
auditor (Auditor) |
Download documents and consult each envelope’s audit trail. |
contributor (Contributor) |
Create envelopes, edit them before sending, upload documents, assign labels and send. |
manager (Manager) |
Cancel envelopes. |
| Permission | viewer | auditor | contributor | manager |
|---|---|---|---|---|
envelope:read | Yes | Yes | Yes | Yes |
archive:read | Yes | Yes | Yes | Yes |
audit:read | No | Yes | Yes | Yes |
document:download | No | Yes | Yes | Yes |
envelope:create | No | No | Yes | Yes |
envelope:update | No | No | Yes | Yes |
document:upload | No | No | Yes | Yes |
label:assign | No | No | Yes | Yes |
envelope:send | No | No | Yes | Yes |
envelope:cancel | No | No | No | Yes |
In General, everyone is a Contributor. Every member of the organization holds the Contributor role in the General workspace permanently, so that role is neither granted nor revoked there. In the other workspaces, an administrator grants each member the role they need.
Organization roles
Section titled “Organization roles”The organization role defines which sections of the application a person sees and what they can administer:
| Role | Name in the application | What it allows |
|---|---|---|
org_member |
Org Member | Work with envelopes according to their workspace roles, from the Dashboard, Envelopes and Archived. |
org_admin |
Org Admin | All of the above in every workspace, without needing to belong to them, plus invite users, create workspaces and grant roles, define label keys, manage API credentials and webhooks, configure the certificate and consult the organization’s audit trail. |
org_api |
API credential | An integration. It lists workspaces and label keys; what it can do with envelopes depends on its workspace roles. Administering the organization is reserved for people. |
platform_admin |
Platform Admin | Binary Bridges. Creates organizations and defines quotas and the seal’s appearance. |
Administrators see every workspace in the organization without being a member of any, so they are not added to workspaces. The full permission matrix is in Permission matrix.
Tasks reserved for Managers and administrators
Section titled “Tasks reserved for Managers and administrators”A Contributor creates, edits, sends and downloads envelopes. Two kinds of tasks require another role:
- Cancelling an envelope belongs to a Manager of the workspace or an administrator. If you need to cancel one, ask your administrator to do it or to grant you the Manager role in that workspace. See Cancel an envelope.
- Administering the organization (users, label keys, workspaces, credentials, webhooks and certificate) belongs to administrators.
Access to envelopes and workspaces
Section titled “Access to envelopes and workspaces”Each person sees only the envelopes of their workspaces: the others do not appear in lists or
counters. If you open an envelope or a workspace you do not have access to, the application answers
as if it did not exist (“Envelope not found, or you don’t have access to it.”), and the API answers
404. This protects each workspace’s information. An organization action your role does not allow
gets the message “You don’t have permission to do this.” instead (403 in the API).
Membership cap
Section titled “Membership cap”A person or an API credential can belong to at most 50 workspaces. Administrators do not count toward this limit, because they see every workspace without belonging to any.