Stratforge One

Core concepts

Stratforge One is the control plane for your Stratforge account. It is where you administer the people in your organization, decide who can do what, connect Stratforge products, and keep sign-in and spend under control.

This page walks through the mental model behind the console - the handful of concepts that everything else builds on. Skim it once and the rest of the docs will click into place.

New here? Read this page top to bottom, then follow the Quickstart to set everything up in order.

Organization

Your organization is the top-level container for everything in Stratforge One. It has an identity you control: a name, a label, a logo, and a URL (slug) that all your sign-in and product links are built from. Every member, group, app, policy, and bill lives inside this one organization.

Changing the organization URL re-points all of your links and signs everyone out, so treat it as a deliberate move rather than a casual edit.

Learn more in Organization.

Members (directory users)

Members are the people in your organization. The Directory is the roster where you invite them, see who is active, pending, or suspended, and open any person to manage their profile and access.

Each member has an organization-level role of either Admin or Member. Admins can manage the organization; members get only the access you grant them. From a member's profile you can resend invitations, grant or remove the admin role, suspend or remove people, and review the products they can reach.

Learn more in Directory users.

Groups

Groups let you manage people in bulk instead of one at a time. Put members into a group, then grant that group product access, roles, and data policies once - everyone in the group inherits them.

Group membership can be added manually in the console, and members synced from an external directory are tagged by their source. Groups are the unit you will reach for whenever you want consistent access across a team.

Learn more in Groups.

Roles and permissions (access control)

Access control is how you decide what people can actually do inside a connected app. Each app exposes a set of modules, and a role is a named bundle of permissions across those modules. Some roles are System roles that ship with the app; you can also create Custom roles, optionally cloning an existing role as a starting point.

Within a role you grant or revoke individual permissions per module, and you can gate a module entirely so members with that role never see it. Assign roles to members or to groups to put them to work.

Learn more in Access control overview.

Data policies

Data policies control which records a person can see inside an app, rather than which actions they can take. A policy is a set of attribute-based rules; you assign it to users or groups, and members of a group see the union of the policies that apply to them.

A default access mode decides what happens for someone with no applicable policy: Permissive grants full access, while Restrictive denies everything until a policy is assigned. This default applies organization-wide, so set it to match how cautious you need to be.

Learn more in Data policies.

Apps (connected Stratforge products)

Apps are the Stratforge products connected to your organization - the things your members actually use day to day. The catalog shows what is available to subscribe to, and once an app is connected you manage it from one place.

Managing an app brings together its Data Policies (which records users and groups can see), its Access Controls (the roles and permissions for the app), and its Settings (data policy defaults and other options). Granting product access - to individual members or to whole groups - is what puts an app in someone's hands.

Learn more in the Apps catalog and Manage apps.

Security and sign-in

Security is where you set the rules for how members sign in. You manage the multi-factor authentication (MFA) methods your organization allows - an authenticator app (TOTP) and email one-time codes - and you can force MFA so every member must complete a second step on their next sign-in.

This is also where you configure identity providers for single sign-on (SSO), including SAML and LDAP, so people can sign in with your existing identity system.

Learn more in Security overview and Authentication.

Billing

Billing is where you keep spend visible and under control. The dashboard summarizes credits used, amount billed, and your plan (for example pay-as-you-go or enterprise). Budgets let you set a limit and restrict usage once it is reached, and Bills break spend down by service so you can see where it goes.

Learn more in Billing overview, Budgets, and Bills.

Your own account

Separate from administering the organization, every person - including you - has an account for their personal profile, preferred language, and personal MFA setup.

Learn more in Account and Settings.

Ready to put these pieces together? Head to the Quickstart.