- API key
- A secret a program uses to act for you in one app, with only the permissions you chose and an expiry date.
- Entitlement
- The right to use an app: for a tenant, which apps it has; for a person, their own apps such as Avand storage or Peyk mail.
- Grace period
- The 30 days between approving a tenant's deletion and removing its data, during which the tenant can be restored.
- Guest
- A person from outside the tenant invited for limited collaboration.
- A guest cannot hold an administrative role, and their access may have an end date.
- Member
- A person who belongs to a tenant, directly or through a unit or subgroup.
- Members use the tenant's apps according to their roles. Removing someone from a tenant ends their access to its data at once.
- Organisation sign-in
- A tenant's own sign-in system (such as its company directory) linked to Shokoofa, so members sign in with their work account.
- Names and email addresses may then be managed there and cannot be changed in Shokoofa.
- Permission
- The ability to perform one specific action, such as reading the member list.
- Each app works out your permissions from your roles; a permission is never taken from the sign-in token itself.
- Platform role
- A role of Shokoofa's own staff, such as platform owner or operator, held for a limited time and recertified.
- Recertification
- Confirming, before a role expires, that its holder still needs it. A platform role that is not recertified is removed automatically.
- Role
- A set of permissions given to a person, such as tenant administrator or member.
- Tenant roles are given per tenant; platform roles belong to Shokoofa staff. Some roles cannot be held together (separation of duties).
- Role group
- The group in the identity service whose members hold a tenant role; being in it is holding the role.
- Seat
- One member's use of an app. A tenant's seat limit caps how many members can use that app.
- Separation of duties
- Rules that stop one person from holding roles that should be split, such as a guest with an administrative role.
- Service account
- A non-human account a tenant uses to connect another system, such as a directory sync.
- A service account never holds an administrative role; administrative work is done by accountable people.
- Step-up confirmation
- Confirming your identity again before a sensitive action, with a factor other than your password.
- For example a one-time code from an authenticator app. Your organisation may require it for platform actions and other sensitive changes; where it is optional, the account center says so.
- Subgroup
- A group of members for a specific purpose, such as a project; its member list can be private.
- Support session
- Time-limited access for Shokoofa support to a tenant's apps or a person's own data, only after they approve it.
- Tenant
- A Shokoofa customer, such as a company or an institution. Each tenant's data and members are kept apart from every other tenant.
- A person can belong to several tenants. Each tenant has a permanent key, one or more owners, and the apps it is entitled to.
- Two-person rule
- A sensitive change that two different people must approve, neither of them the person who asked for it, such as deleting a tenant.
- Unit
- Part of a tenant's formal structure, such as a department or a team.
- Units form a tree that the tenant's administrators define.
- Verified domain
- An email domain a tenant has proved it owns with a DNS record; one domain belongs to at most one tenant.