Run your organization

The admin console tab by tab: members, roles, seats, billing, policies, audit, SIEM, recovery and single sign-on.

On this page
Documentation sections

The Organization page is your organization's admin console. From there you manage members and their roles, the subscription, the rules that apply to everyone, the audit log and the recovery of team vaults.

Open the console

In the enterprise space, click Organization in the sidebar. The page shows your organization's name, its plan and your role. The tabs sit below: twelve for the owner, eleven for an admin.

TabWhat you do thereWho sees it
OverviewKey figures and chartsOwner, admin
GuideThe setup checklist, and what members can expectOwner, admin
MembersChange roles, remove peopleOwner, admin
InvitationsInvite by email, revoke pending invitationsOwner, admin
BillingSubscribe, buy seats, manage paymentOwner, admin
WorkspaceMarketplace, extensions, imposed theme and fontOwner, admin
GovernanceSessions, sharing rules, retentionOwner, admin
AuditRead and verify the activity logOwner, admin
SIEMStream the audit log to your security toolsOwner
RecoveryOrganization key and team vault recoveryOwner, admin
SettingsRename, or delete the organizationOwner, admin (deletion: owner)
SSOSingle sign-on with your identity providerOwner, admin

Overview

Figure cards give the state of the organization at a glance: members (and pending invitations), audit events over the last 30 days, seats used, pooled storage and the integrity of the audit log. The owner also sees the SIEM destinations. Below, charts show audit activity per day, the most frequent event types and how members are spread across roles.

Guide

The Guide has two views:

  • Administrator: the setup steps in order, which tick themselves from the real state of your organization. Name your organization, subscribe, create your organization key, invite your team, understand the roles, set your policies, set up the workspace, know what the log holds. Open takes you to the right tab.
  • Member: what joining changes for a member, what the organization can and cannot see, and what happens when someone leaves.

Members

The table lists every member with their role, status and join date. Each member appears as an account identifier, which you can copy.

  • To change a role, pick a new one in the Role list: Admin, Security admin, Editor or Viewer.
  • To take someone out, click Remove, then confirm.

An admin cannot change or remove an owner. The owner role cannot be given from this tab.

Invitations

  1. Type the person's Email.
  2. Choose a Role: Admin, Editor or Viewer.
  3. Click Invite.

The person receives an email in your interface language. Pending invitations are listed with their expiry date: they expire after 7 days. Click Revoke to cancel one. You can change the role later from Members.

Without a subscription, a band says Invitations are waiting for a subscription: every invitation would be refused, because the organization has no seats yet.

Billing

To subscribe:

  1. Choose Monthly (€11 per seat per month) or Annual (€110 per seat per year).
  2. Click Subscribe. The payment page opens in your browser.

Once the subscription is active, Manage billing opens the payment portal, where you change the card or cancel. The tab also shows four figures: Plan, Paid seats, Billable members and Pooled storage.

The band at the top tells you the state of the subscription:

StateWhat it means
No subscriptionThe organization is dormant: no seats, no team vaults, no pooled storage, invitations refused. You can prepare everything meanwhile.
Subscription activeEverything works. You can cancel at any time from the portal.
Payment overdueA charge failed. Your team keeps full access while the payment is retried: update the payment method before suspension.
Subscription stoppedRead only: no new vault, invitation or file. Everything that exists stays readable, and subscribing again restores writing at once.

Seats and free viewers

  • The plan has a minimum of three seats.
  • Every member who is not a viewer takes a seat. Adding an editor beyond the minimum adds a seat, charged pro rata. Removing one gives it back.
  • Viewers are free and never count.
  • The and + buttons next to Paid seats give a seat back or buy one. Filarr never goes below your current members or the plan minimum.
  • Each paid seat adds 100 GB to the organization's pooled storage.

Workspace

This tab decides what the app offers your members. Each setting says whether it is enforced by the server or applied best-effort by the app.

SettingEffect
Turn off the marketplaceNo extensions and no layout templates. The sidebar entry disappears.
Turn off the layout marketLayout templates only. Extensions stay available.
Forbid publishingMembers can install, but not publish under their account.
ExtensionsAll extensions, Allowed extensions only (you list their identifiers), or No extensions.
Organization theme and Enforce this themeSets a theme on members' devices. With the lock, the theme choice in Settings is closed to them. Without it, each member can change the theme afterwards.
Organization font and Enforce this fontSets a font on members' devices. With the lock, Filarr applies it again at each start, but members can still pick another font in Settings until then.

Members receive the new policy at their next sync, within a few minutes. An app that is offline applies the last policy it received.

Governance

Governance policy groups the rules that apply to every member.

GroupSettings
Sessions & authenticationRequire two-factor authentication, Re-authenticate for sensitive actions, Idle timeout (minutes), Absolute session limit (minutes), Offline grace (days) (empty means 30 days)
SharingBlock external share links (this also blocks Filarr Send), Require a password on shares, Require an expiry on shares, View-only (block download of shared content), Maximum share expiry (days)
RetentionPurge trash older than (days), Prune note versions older than (days). Retention runs on each member's device.

Click Save to apply. Below the form, Governance & offline enforcement explains what the server enforces and what the app only applies best-effort. For example, a device that stays offline past the grace period locks until it reconnects.

Audit

The Audit log records sign-ins, role changes, shares created or revoked, and admin actions. It holds metadata only: never a file's content or a note's title. The audit log is included in the Teams and Enterprise plans.

  • The columns are Time, Event, Actor, Target, IP /16 and Country.
  • Filter by event type, and click Load more to go further back.
  • Verify integrity checks the chained log: Intact, or Tampering detected if a line was changed or removed.

SIEM

Audit log streaming sends every audit event to your security tools as it happens. Click Add a sink, then choose:

  • Webhook: events are sent as JSON over HTTPS and signed with HMAC-SHA256. Give a signing secret of at least 16 characters.
  • Splunk HEC: events go to your Splunk HTTP Event Collector, with its token.

Secrets and tokens are stored encrypted and never shown again. A switch turns each destination on or off, and Remove deletes it. Streaming is included in the Teams and Enterprise plans.

Recovery

The Recovery tab (Escrow & recovery) lets the organization give a member back access to their team vaults if they lose their password. It never covers anyone's personal space.

  1. Click Enable (org key) to create the organization recovery key. Do it before inviting your members: vaults sealed before the key exists cannot be recovered.
  2. Check the key's fingerprint with another admin, by phone or in person.
  3. When a member asks for help, their request appears under Recovery reset requests. Confirm their identity outside Filarr, then click Complete recovery.

With the Org key policy, any single admin can recover. Convert to Shamir k-of-n requires several admins together; it needs at least two admins with their own keys, and it cannot be undone. Rotate org key replaces the key and re-seals every recovery copy.

Recovery only works for members who gave their consent (Allow recovery). At the moment, this consent appears only in this tab, so members who cannot open the console cannot give it yet. A member who lost access asks from Settings → Account & Sync → Lost access? Request team-vault recovery, in the enterprise space.

Settings

  • Organization name: type the new name, then Save.
  • Handle: the organization's identifier, shown for reference.
  • Danger zone → Delete organization (owner only): the organization goes read-only for 30 days, then disappears. See When an organization closes.

SSO

Single sign-on (OIDC) lets your members sign in through your identity provider. The provider confirms who they are; it never sees a vault key.

  1. Enter the Issuer URL, the Client ID and the Client secret, then click Save connection.
  2. Under Email domains, add your domain, publish the DNS TXT record shown, then click Verify.
  3. Click Enable SSO. It stays unavailable until at least one domain is verified.

Auto-provision new members on first SSO login (JIT) creates a member on their first sign-in, as Viewer or Editor.

After an SSO sign-in, a member can make the device trusted in Settings → Hardware security key → Trusted device (SSO), so the vault unlocks there without the password.

Roles

RoleTakes a seatOpens the consoleWhat they can do
OwnerYesYesEverything, including SIEM and deleting the organization
AdminYesYesMembers, invitations, billing, settings, governance, workspace, audit, recovery, SSO. Not SIEM. Cannot change or remove an owner.
Security adminYesNot yetMeant for the audit log, SIEM and governance, with no power over members or billing. The app does not open the console to this role yet.
EditorYesNoWorks in the vaults shared with them
ViewerNo, freeNoWorks in the vaults shared with them

What an administrator cannot do

Administration governs access, never decryption. No role, not even the owner's, can:

  • read a member's encrypted files or notes, including in shared vaults;
  • see anything in a member's personal space;
  • find content in the audit log, which holds metadata only.

Filarr holds no master key either. The one exception is the recovery described above: with the organization key and the member's consent, an admin can give back access to the organization's vaults, and nothing else.

Limits to know

  • SSO is OIDC only, and SSO sign-in works in the desktop app only.
  • There is no CSV export button for the audit log in the app.
  • The app has no screen to customize your organization's branding (logo, colors), even though the Guide mentions branded pages.
  • Security admins cannot open the console yet.
  • An enforced theme can still be switched between light and dark from the command palette until the app restarts, and an enforced font can be changed in Settings until the next start.
  • Rules applied on devices (idle lock, retention, view-only) are best-effort: a determined user on a modified device can work around them.