Run your organization
The admin console tab by tab: members, roles, seats, billing, policies, audit, SIEM, recovery and single sign-on.
On this page
Documentation sections
The Organization page is your organization's admin console. From there you manage members and their roles, the subscription, the rules that apply to everyone, the audit log and the recovery of team vaults.
Open the console
In the enterprise space, click Organization in the sidebar. The page shows your organization's name, its plan and your role. The tabs sit below: twelve for the owner, eleven for an admin.
| Tab | What you do there | Who sees it |
|---|---|---|
| Overview | Key figures and charts | Owner, admin |
| Guide | The setup checklist, and what members can expect | Owner, admin |
| Members | Change roles, remove people | Owner, admin |
| Invitations | Invite by email, revoke pending invitations | Owner, admin |
| Billing | Subscribe, buy seats, manage payment | Owner, admin |
| Workspace | Marketplace, extensions, imposed theme and font | Owner, admin |
| Governance | Sessions, sharing rules, retention | Owner, admin |
| Audit | Read and verify the activity log | Owner, admin |
| SIEM | Stream the audit log to your security tools | Owner |
| Recovery | Organization key and team vault recovery | Owner, admin |
| Settings | Rename, or delete the organization | Owner, admin (deletion: owner) |
| SSO | Single sign-on with your identity provider | Owner, admin |
Overview
Figure cards give the state of the organization at a glance: members (and pending invitations), audit events over the last 30 days, seats used, pooled storage and the integrity of the audit log. The owner also sees the SIEM destinations. Below, charts show audit activity per day, the most frequent event types and how members are spread across roles.
Guide
The Guide has two views:
- Administrator: the setup steps in order, which tick themselves from the real state of your organization. Name your organization, subscribe, create your organization key, invite your team, understand the roles, set your policies, set up the workspace, know what the log holds. Open takes you to the right tab.
- Member: what joining changes for a member, what the organization can and cannot see, and what happens when someone leaves.
Members
The table lists every member with their role, status and join date. Each member appears as an account identifier, which you can copy.
- To change a role, pick a new one in the Role list: Admin, Security admin, Editor or Viewer.
- To take someone out, click Remove, then confirm.
An admin cannot change or remove an owner. The owner role cannot be given from this tab.
Invitations
- Type the person's Email.
- Choose a Role: Admin, Editor or Viewer.
- Click Invite.
The person receives an email in your interface language. Pending invitations are listed with their expiry date: they expire after 7 days. Click Revoke to cancel one. You can change the role later from Members.
Without a subscription, a band says Invitations are waiting for a subscription: every invitation would be refused, because the organization has no seats yet.
Billing
To subscribe:
- Choose Monthly (€11 per seat per month) or Annual (€110 per seat per year).
- Click Subscribe. The payment page opens in your browser.
Once the subscription is active, Manage billing opens the payment portal, where you change the card or cancel. The tab also shows four figures: Plan, Paid seats, Billable members and Pooled storage.
The band at the top tells you the state of the subscription:
| State | What it means |
|---|---|
| No subscription | The organization is dormant: no seats, no team vaults, no pooled storage, invitations refused. You can prepare everything meanwhile. |
| Subscription active | Everything works. You can cancel at any time from the portal. |
| Payment overdue | A charge failed. Your team keeps full access while the payment is retried: update the payment method before suspension. |
| Subscription stopped | Read only: no new vault, invitation or file. Everything that exists stays readable, and subscribing again restores writing at once. |
Seats and free viewers
- The plan has a minimum of three seats.
- Every member who is not a viewer takes a seat. Adding an editor beyond the minimum adds a seat, charged pro rata. Removing one gives it back.
- Viewers are free and never count.
- The − and + buttons next to Paid seats give a seat back or buy one. Filarr never goes below your current members or the plan minimum.
- Each paid seat adds 100 GB to the organization's pooled storage.
Workspace
This tab decides what the app offers your members. Each setting says whether it is enforced by the server or applied best-effort by the app.
| Setting | Effect |
|---|---|
| Turn off the marketplace | No extensions and no layout templates. The sidebar entry disappears. |
| Turn off the layout market | Layout templates only. Extensions stay available. |
| Forbid publishing | Members can install, but not publish under their account. |
| Extensions | All extensions, Allowed extensions only (you list their identifiers), or No extensions. |
| Organization theme and Enforce this theme | Sets a theme on members' devices. With the lock, the theme choice in Settings is closed to them. Without it, each member can change the theme afterwards. |
| Organization font and Enforce this font | Sets a font on members' devices. With the lock, Filarr applies it again at each start, but members can still pick another font in Settings until then. |
Members receive the new policy at their next sync, within a few minutes. An app that is offline applies the last policy it received.
Governance
Governance policy groups the rules that apply to every member.
| Group | Settings |
|---|---|
| Sessions & authentication | Require two-factor authentication, Re-authenticate for sensitive actions, Idle timeout (minutes), Absolute session limit (minutes), Offline grace (days) (empty means 30 days) |
| Sharing | Block external share links (this also blocks Filarr Send), Require a password on shares, Require an expiry on shares, View-only (block download of shared content), Maximum share expiry (days) |
| Retention | Purge trash older than (days), Prune note versions older than (days). Retention runs on each member's device. |
Click Save to apply. Below the form, Governance & offline enforcement explains what the server enforces and what the app only applies best-effort. For example, a device that stays offline past the grace period locks until it reconnects.
Audit
The Audit log records sign-ins, role changes, shares created or revoked, and admin actions. It holds metadata only: never a file's content or a note's title. The audit log is included in the Teams and Enterprise plans.
- The columns are Time, Event, Actor, Target, IP /16 and Country.
- Filter by event type, and click Load more to go further back.
- Verify integrity checks the chained log: Intact, or Tampering detected if a line was changed or removed.
SIEM
Audit log streaming sends every audit event to your security tools as it happens. Click Add a sink, then choose:
- Webhook: events are sent as JSON over HTTPS and signed with HMAC-SHA256. Give a signing secret of at least 16 characters.
- Splunk HEC: events go to your Splunk HTTP Event Collector, with its token.
Secrets and tokens are stored encrypted and never shown again. A switch turns each destination on or off, and Remove deletes it. Streaming is included in the Teams and Enterprise plans.
Recovery
The Recovery tab (Escrow & recovery) lets the organization give a member back access to their team vaults if they lose their password. It never covers anyone's personal space.
- Click Enable (org key) to create the organization recovery key. Do it before inviting your members: vaults sealed before the key exists cannot be recovered.
- Check the key's fingerprint with another admin, by phone or in person.
- When a member asks for help, their request appears under Recovery reset requests. Confirm their identity outside Filarr, then click Complete recovery.
With the Org key policy, any single admin can recover. Convert to Shamir k-of-n requires several admins together; it needs at least two admins with their own keys, and it cannot be undone. Rotate org key replaces the key and re-seals every recovery copy.
Recovery only works for members who gave their consent (Allow recovery). At the moment, this consent appears only in this tab, so members who cannot open the console cannot give it yet. A member who lost access asks from Settings → Account & Sync → Lost access? Request team-vault recovery, in the enterprise space.
Settings
- Organization name: type the new name, then Save.
- Handle: the organization's identifier, shown for reference.
- Danger zone → Delete organization (owner only): the organization goes read-only for 30 days, then disappears. See When an organization closes.
SSO
Single sign-on (OIDC) lets your members sign in through your identity provider. The provider confirms who they are; it never sees a vault key.
- Enter the Issuer URL, the Client ID and the Client secret, then click Save connection.
- Under Email domains, add your domain, publish the DNS TXT record shown, then click Verify.
- Click Enable SSO. It stays unavailable until at least one domain is verified.
Auto-provision new members on first SSO login (JIT) creates a member on their first sign-in, as Viewer or Editor.
After an SSO sign-in, a member can make the device trusted in Settings → Hardware security key → Trusted device (SSO), so the vault unlocks there without the password.
Roles
| Role | Takes a seat | Opens the console | What they can do |
|---|---|---|---|
| Owner | Yes | Yes | Everything, including SIEM and deleting the organization |
| Admin | Yes | Yes | Members, invitations, billing, settings, governance, workspace, audit, recovery, SSO. Not SIEM. Cannot change or remove an owner. |
| Security admin | Yes | Not yet | Meant for the audit log, SIEM and governance, with no power over members or billing. The app does not open the console to this role yet. |
| Editor | Yes | No | Works in the vaults shared with them |
| Viewer | No, free | No | Works in the vaults shared with them |
What an administrator cannot do
Administration governs access, never decryption. No role, not even the owner's, can:
- read a member's encrypted files or notes, including in shared vaults;
- see anything in a member's personal space;
- find content in the audit log, which holds metadata only.
Filarr holds no master key either. The one exception is the recovery described above: with the organization key and the member's consent, an admin can give back access to the organization's vaults, and nothing else.
Limits to know
- SSO is OIDC only, and SSO sign-in works in the desktop app only.
- There is no CSV export button for the audit log in the app.
- The app has no screen to customize your organization's branding (logo, colors), even though the Guide mentions branded pages.
- Security admins cannot open the console yet.
- An enforced theme can still be switched between light and dark from the command palette until the app restarts, and an enforced font can be changed in Settings until the next start.
- Rules applied on devices (idle lock, retention, view-only) are best-effort: a determined user on a modified device can work around them.