SafeShare Administrator's Guide
|
All features of Cocoon Data technologies are accessed through a Cocoon Data user account. The core of these features include the ability to:
A Cocoon Data user who has the SafeShare administrator role (also simply known as a 'SafeShare administrator'):
(1) A file object / Secure Object is defined as Cocoon Data-encrypted data that has been registered on the Cocoon Data Platform, along with the properties associated with this encrypted data. For more information about file objects, see Administering files within the Organisation Administration section of this guide.
Each Cocoon Data user's account is defined by a set of fields described in the table below, of which only the Email field can be specified when a SafeShare administrator's account is added account through SafeShare Administration.
A SafeShare administrator user can configure their own user account's fields when they edit their own account.
Unless stated in the following table, these fields and their values are visible on the Administrators page of SafeShare Administration.
Field | Description | Required? |
---|---|---|
The email address that forms part of a user's credentials, which the user requires to authenticate to the Cocoon Data Platform. This email address:
| Yes | |
First Name (2) | A user's first name (e.g. a given name or nickname). This field is only editable through the user's own My Account feature. | No |
Last Name (2) | A user's last name (e.g. a surname or family name). This field is only editable through the user's own My Account feature. | No |
Other Name (2) | A user's middle name (e.g. one or more other given names). This field is only visible and editable through the user's own My Account feature. | No |
Mobile Number (2) | The mobile number of a user. This field is only visible and editable through the user's own My Account feature. Note: This number must include the country calling code and plus (+) sign prefix. | No |
Default Language (2) | The language preference/settings for a user. Any changes to this field apply immediately to the user interfaces of SafeShare Administration, SafeShare for Web and Organisation Administration (if the user has access to these features). Note: This setting overrides the System Default language (defined through the Internationalisation page). | No |
Locked | This field indicates 'Yes' if a Cocoon Data user account has been locked as a result of the user mistyping their password more than the maximum number of times configured by a SafeShare administrator. The user themselves will need to unlock this account by following the instructions in their 'account lockout' notification (or by resetting their password via any of the options on the Cocoon Data Sign-in page). If a user account is not locked, this field indicates nothing. The values of this non-editable field are only visible on the Administrators and/or Users page. | Not applicable |
MFA Enabled (2) and Re-seed MFA | The MFA Enabled field's check box for a SafeShare administrator's account is selected if that user has multi-factor authentication (MFA) enabled on their account. (This field is also editable through the user's own My Account feature.) If this check box is selected for a SafeShare administrator's account, then the Re-seed button becomes available for that account in the Re-seed MFA column/field. If a SafeShare administrator account does not have MFA enabled, this field's check box is cleared for their account. The state of MFA being enabled or disabled for SafeShare administrator accounts other than your own is only visible on the Administrators page. | No |
(2) While a SafeShare administrator can modify these fields' values for their Cocoon Data user account via the My Account feature through SafeShare Administration, the user can also modify these values via equivalent features in SafeShare for Web and other SafeShare products, as well as Organisation Administration (assuming they are a member of at least one organisation and have the required roles to access these features). A SafeShare administrator becomes a member of an organisation when:
Note: Other fields are associated with a SafeShare administrator's user account. However, these fields are either:
- only visible through the 'Users' page of Organisation Administration, or
- used internally by the Cocoon Data Platform and are therefore only exposed to a limited extent through user interfaces (or not exposed at all).
Each Cocoon Data user must be assigned a role, which grants the user access to different sets of features available through the Cocoon Data Platform and Cocoon Data technologies. A Cocoon Data user is automatically granted the SafeShare administrator role when their user account is added through SafeShare Administration.
Note: Users can have more than one role (as explained in more detail in the following table):
- A user with the SafeShare administrator role can also be granted the Organisation administrator role for any organisation.
- A user with either of these administrator roles can also be granted either the Originator or Collaborator role for any organisation.
- Likewise, a user with either the Originator or Collaborator role in any organisation can have the SafeShare administrator and/or Organisation administrator roles.
Role | Description |
---|---|
SafeShare administrator | A Cocoon Data user with the SafeShare administrator role can access all administration features of their Cocoon Data Platform instance made available through the SafeShare Administration interface. A Cocoon Data user's account is granted this role when the user is either:
|
Other Cocoon Data user roles | Cocoon Data users with roles other than the SafeShare administrator role can access other features of their organisations' access to the Cocoon Data Platform relating to the manipulation and handling of files. For more information about these other Cocoon Data user roles, see An organisation user's roles in the Organisation Administration section of this guide.
|
This procedure describes how to add a SafeShare administrator user account to the Cocoon Data Platform. This process grants the Cocoon Data user the SafeShare administrator role.
To add a SafeShare administrator user to the Cocoon Data Platform:
Removing a Cocoon Data user account from SafeShare Administration:
Note: Removing a Cocoon Data user account from SafeShare Administration does not delete this account from the Cocoon Data Platform. If a Cocoon Data user (previously removed from SafeShare Administration) is added back again or granted other user roles (which would provide the user with access to features such as file handling and manipulation within their organisation/s on the Cocoon Data Platform), then the same user account is re-utilised. Any fields that the user had previously edited/customised are retained.
To remove a Cocoon Data user account from SafeShare Administration:
This procedure describes how to edit the fields of your (SafeShare administrator) user account on the Cocoon Data Platform.
To edit your SafeShare administrator user account:
Only a Cocoon Data user with the Local Account Type who has signed in to either SafeShare for Web or SafeShare Administration can change their own password.
Note: The authentication of an LDAP user on the Cocoon Data Platform is delegated to its respective LDAP server. If you have an LDAP user account and wish to change its password, you will need to contact your LDAP administrator for details on how to do this (e.g. through the user account on your LDAP server/user directory). See Configuring LDAP for more information.
To change your password:
Terminating your SafeShare administrator account's sessions immediately invalidates all of your currently valid refresh tokens. This action immediately signs you out of your current SafeShare Administration session and then every other SafeShare application with which you have an active session (i.e. once these sessions' access tokens expire). This also includes any other client applications using the Cocoon Data Platform's resources with access tokens obtained through your account.
This feature is useful if your SafeShare administrator account is at risk of being compromised - for example, you suspect that you forgot to sign out from a shared computer or you were signed in from a laptop that was either lost or stolen before you signed out.
To terminate your SafeShare administrator account's sessions:
If required, any SafeShare administrator user account (including your own) can be configured with multi-factor authentication (MFA) by enabling this feature on such an account.
If MFA has been enabled on a Cocoon Data user account, then in order to successfully sign in through this account (on the Cocoon Data Sign-in page), the user is required to enter both their password (i.e. the 1st authentication factor) as well as an authentication code obtained from an authenticator application (aka authenticator app) running on the user's mobile device (i.e. the 2nd authentication factor).
The MFA feature supports the following mobile devices and authenticator apps:
Notes:
- Before enabling MFA on a SafeShare administrator account, you may wish to confirm if the user of this account is in possession of any one of these supported mobile devices (above), or notify the user that they will require access to one of these devices to continue signing in through the Cocoon Data Sign-in page.
- The URLs to download the appropriate authenticator app for a supported device are available to users when they configure MFA on their accounts (and are themselves configurable through the Configuration page).
To enable or disable MFA on your and/or other SafeShare administrator account/s:
Tip: You can also enable or disable MFA on your own SafeShare administrator account by:
- Ensuring you are signed in to SafeShare Administration.
- Clicking your email address at the top-right of the page and choosing My Account from the drop-down menu.
- In the Security section of the subsequent page, clicking the Enable/Disable button to the right of Multi-factor authentication.
While multi-factor authentication (MFA) is enabled on a SafeShare administrator's account, the user might lose the ability to generate authentication codes for their 2nd authentication factor (explained in more detail above) due to any of the following reasons:
If one of these scenarios occurs, the SafeShare administrator will no longer be able to sign in through the Cocoon Data Sign-in page and they may likely send you or any other SafeShare administrator an email message about one of these scenarios having occurred (via 'contact your administrator' feature on the Authentication code request page as they attempt to sign in through the Cocoon Data Sign-in page).
Therefore, to resolve this situation, the SafeShare administrator requires MFA to be re-configured (aka re-seeded) for their account.
To re-configure MFA on one or more SafeShare administrator account/s: