Skip to main content

Namespaces

Trivore ID is a multi-tenant system; a namespace roughly represents one tenant (customer organisation). Namespaces on the Main Menu is where tenants are managed. One organisation may have multiple namespaces, managed by one or more user accounts as needed — if so, it's recommended to give them a common namespace code prefix, to keep them easy to tell apart.

This Main Menu item is only available to accounts with the Portal Admin or Portal Auditor role.

Management view

Selecting Namespaces opens the list of namespaces, with the current namespace shown in bold. Selecting a namespace shows its account, group, role, and user directory counts. As in other management views, columns can be shown or hidden from the icon in the top-right corner of the list.

  • Add / Delete namespace — create or remove a namespace.
  • Configuration — opens a dropdown with Edit namespace (see Editor below), Default policies (see Default policy), and Outside user access (add or remove users who don't belong to the namespace but are allowed access to it).
  • Info — shows Changes to namespace, an audit log of edits made to it.
  • Actions — print the namespace list or a namespace report, import or export namespaces, manage multi-namespace administrators, or invite new user accounts by email and manage open invitations.

Editor

Opened via Configuration → Edit namespace. Settings are organised across the following tabs.

Core

  • Namespace name — full name, short name, code (fixed once created), description, and an optional validity period (Valid from / Valid to).

  • Default settings for new user accounts — the sign-in account naming policy for accounts created from now on (existing accounts keep their current sign-in name); options include several lengths of random numbers, the user's email address, a name-plus-numbers pattern, fully manual entry, and more. Related settings here control auto-incrementing numbering and whether pattern validation can be disabled.

    tip

    When creating a specially named service account, temporarily switch this to Manually defined, create the account, then switch it back.

  • Duplicate account prevention — whether duplicate email addresses, or multiple accounts verified with the same email address, are allowed.

User Interface

What users in the namespace see and can do in their own account: whether nicknames (and duplicate nicknames) are allowed, whether self-service password recovery and full access to the user preferences view are allowed, whether users can invite new accounts (and for how many days such an invite stays valid), the maximum number of email addresses and phone numbers per account, and which redirect views theme is used.

Features

  • LDAP server — enable LDAP authentication for the namespace (optionally scoped to a single Group rather than everyone), and the resulting LDAP authentication DN and password. An LDAP extensions section additionally enables Cisco-specific extensions where needed.
  • SMS settings — enable SMS messages (and custom SMS messages), the default region and originator, and the SMS billing plan.

Branding

Upload the namespace's logos: a top-bar logo, a Management UI sign-in logo, a separate OpenID Connect sign-in logo, and a general logo (used in places like reports — use a high-resolution image here, since reports are often printed). An alternative sign-in address for private sign-in can also be set here.

User identification

Settings related to personal identity codes and strong identification:

  • Conflict detection and sharing rules for personal identity codes and electronic identifiers (whether multiple accounts may share the same one).
  • Whether Legal Info fields are updated automatically after strong identification.
  • Age-related settings: the minor age limit, and whether minor-related fields update automatically.
  • Which documents are accepted for strong identification (passport, ID card, and similar — including whether expired documents are accepted).

Personal data

Configures the email notification sent when a personal data request affecting this namespace is submitted: whether to send it, the recipient address and name, and the subject/content templates (which support placeholders like {user_username}, {request_type}, and {request_remarks}). This is separate from the notification sent to the user when their request is confirmed, which is configured per-request in the PDR admin view.

Message templates

Toggles for using the built-in system email/SMS templates as-is, or replacing them (with localisation support) for this namespace. This is distinct from Email Templates, the main menu item for authoring full custom templates with Template Languages — settings here don't affect those.

User registration

Controls self-service registration only — for example, a visitor registering during an OAuth 2.0 authentication flow. It has no effect on accounts created by administrators or via the API. Besides the on/off toggle, the registration form's heading and info text (above and below the form) can be customised per language here.

Password Reset

Namespace-wide behavior for the self-service password reset form: whether it's allowed at all; whether users can be found by phone number, email address, or username; whether an email address or phone number must already be verified to be usable for reset; and, for name verification, whether to ask for a name during SMS- or email-based reset and which name source to prefer (Legal Info vs. User Info).

Miscellaneous

  • Legal — the namespace's binding legal data location (for GDPR and similar legislation).
  • Authorisations — default validity time and purge delay time for authorisations.
  • Domicile codes — a reference table of municipality codes (importable/exportable), used where addresses need to reference a specific municipality.
  • Miscellaneous — suggested tags for the namespace.