Organisation administration · Public
Run your organisation in IAM
Manage members, invites, roles, and bulk imports from the IAM area once your tenant is active.
IAM is where tenant administrators run the organisation day to day. It appears for active commercial and enterprise tenants when the signed-in member has the right permissions. Open iam after you sign in and switch to the tenant you want to manage.
Tenant status
If your account belongs to several tenants, use tenant switching before changing members, branding, or connections. Actions apply to the selected tenant.
| Status | What it means |
|---|---|
| Active | Members can use the tenant and administrators can manage it. |
| Not verified | Skyfallen's tenant review is still pending. Submit documents at verify before normal operation. |
| Disabled | Access is blocked until the tenant is restored. |
Organisation information
Open Organisation in IAM to review the legal and operational details registered for the tenant. Most fields are locked because they come from verification and contract records.
To change locked fields such as legal name, registration number, Workforce Identity, vanity domain, or SSO management toggles, use To change these, please contact us on that page to open a Skyfallen support request.
Enterprise tenant namespaces and member email domains are managed separately on IAM → Organisation → Domains. Members need domains:manage to add domains, choose verification methods, change the primary domain, or retire a domain.
Enterprise tenants with Workforce Identity can also publish sign-in and the workforce portal on a custom hostname under Organisation → Profile → Custom domain. See Custom domains for enterprise sign-in.
| Who | What they can change |
|---|---|
| Any active member | View all organisation fields |
| Primary owner | Transfer primary ownership to another member |
Member with tenant:manage |
Update billing and technical contacts, lookup by email, and password reset settings |
Agreements
Open Agreements in IAM to review executed legal agreements and complete any pending signatures.
Other members cannot open the agreements page or view executed copies on the legal portal. See Tenant permissions reference for the full rule set.
The primary owner always holds the * permission. ONE prevents removing that grant from the primary owner and assigns it automatically when ownership transfers.
| Who | What they can do |
|---|---|
| Primary owner | Sign pending agreements and view executed agreements they signed |
Member with tenant:manage |
View every executed agreement for the tenant |
| Member who signed an agreement | View that executed agreement, even without tenant:manage |
Platform settings
Open Organisation and scroll to Platform settings to review what is enabled for the tenant.
The primary owner or a member with the wildcard (*) permission can configure Legacy SSO password migration on the Legacy SSO migration tab in IAM → Organisation when Workforce Identity is enabled. Members with tenant:manage alone can review the tab but cannot save migration settings.
| Setting | Who can change it | What it does |
|---|---|---|
| Lookup by email | tenant:manage |
Routes members who sign in at auth.skyfallen.one with an address on any verified tenant domain to your organisation sign-in automatically. |
| Allow password reset | tenant:manage |
Lets members recover access through the self-service reset flow described in Reset a forgotten password. |
| Workforce Identity | Skyfallen | Enables the workforce portal and branded sign-in experience. |
| SAML application management | Skyfallen | Lets IAM administrators create and manage SAML service provider applications. |
| CAS application management | Skyfallen | Lets IAM administrators create and manage CAS applications. |
| Lookup by domain | Skyfallen | Enables a vanity domain for enterprise sign-in and the workforce portal. When active, the configured domain appears next to this setting. |
Members and roles
Open Members in IAM to see who belongs to the tenant. Each member may have an assigned role and always has an effective permission list.
Open IAM → Roles to create custom roles and define the permissions they grant. Members with iam:roles:edit can manage role templates. Assign roles from a member's permissions page with iam:permissions:manage.
The built-in Owner role carries * and is assigned to owners at setup. Create narrower custom roles when you want separation of duties. Role permissions are locked on the member; additional permissions can still be added on top.
From a member row you can open their permissions page. Administrators with iam:members:manage can edit profiles or remove memberships.
Bulk selection
On the members list, select one or more rows to run bulk actions from the toolbar. Bulk operations use the same delegation rules as single-member edits.
Bulk actions cannot include your own membership, cannot remove the primary owner, and cannot move the primary owner off the Owner role. You can only act on members whose effective permissions are within your own grants, and you can only assign roles or add permissions you already hold.
A member who cannot perform an action on one member individually cannot use bulk selection to perform that action either.
| Bulk action | Permission | What it does |
|---|---|---|
| Remove | iam:members:manage |
Removes the selected memberships. Enterprise tenants also delete the underlying user accounts. |
| Assign role | iam:permissions:manage |
Applies one role to every selected member. Role permissions are locked on each membership. |
| Add permission | iam:permissions:manage |
Grants one additional permission to every selected member. Members who already hold it are skipped. |
Invites
Open Invites to issue a controlled path into the tenant. For enterprise tenants, the invited account email must match the tenant email domain. Invites expire after 96 hours and can be revoked from the invites page.
Workforce Identity tenants can send the invite link to a separate delivery email. The account email still remains the address that will join the tenant.
CSV imports
Enterprise tenants with iam:import can open Members → Import and upload a CSV.
Required columns:
Optional columns include secondary_emails, birth_date, phone, password, role, and permissions.
Role column
The role column accepts either a role UUID or a role name from your tenant. Skyfallen ONE resolves the value in this order:
- Match the value against a role UUID in the current tenant.
- If there is no UUID match, treat
owneras the built-in Owner role. - Otherwise match a role name case-insensitively.
Other legacy labels such as admin and member work only when your tenant already has roles with those names. UUIDs are the safest choice when names are duplicated or renamed.
On Members → Import, expand Role references for CSV import under the upload section to copy each role UUID without leaving the page. You can still open IAM → Roles to review or edit role templates.
Use permissions for extra unlocked grants on top of the role. Import rows are subject to the same delegation rules as manual permission edits.
| Column | Notes |
|---|---|
first_name |
Member first name. |
last_name |
Member last name. |
email |
Must use the tenant domain. |