Articles on: Safedrop 26

safedrop tenant administrators guide

safedrop Tenant Administrator Guide


This guide covers administrative tasks for managing your organisation's safedrop instance.



Overview


As a Tenant Administrator, you have access to manage:

  • Teams and team memberships
  • Users and access permissions
  • Organisation settings
  • Security configurations
  • Audit logs



Accessing the Admin Panel


  1. Log in with your administrator account
  2. Click Admin in the main menu
  3. You'll see the administration dashboard


Admin Dashboard

Screenshot: The main administration dashboard



Team Management


Creating Teams


  1. Navigate to Teams from the menu
  2. Click New Team
  3. Enter a team name and description
  4. Click Create Encrypted Team

A Team Encryption Key (TEK) is automatically generated. You'll be the first member with access and your first team created will be marked as the default team automatically


Create Team

Screenshot: The create team dialog


Setting the Default Team


One team should be marked as default for new user signups:


  1. Go to Teams
  2. Click the menu on the team
  3. Select Set as Default


New self-signup users are automatically added to the default team.


Deleting Teams


  1. Click the menu on the team
  2. Select Delete Team
  3. Type the team name to confirm
  4. Click Delete


Note: You cannot delete the default team. Set another team as default first.



Users can only be manually added to teams if an invite has already been sent to them and their email address has been verified

Member Management


Inviting Members


  1. Click on Admin
  2. Click Invite user in top right hand corner
  3. Enter the user's email address
  4. Select their role (Member or Admin)
  5. Click Add




Add Member

Screenshot: The add member dialog


Roles Explained


Role

Capabilities

Member

View and upload files, access messages

Admin

Everything members can do, plus: invite users, grant TEK access, manage team settings


Granting TEK Access


When new members join, they need TEK access to view encrypted content:


  1. You'll see a notification banner when users are waiting
  2. Go to Teams and select the team
  3. Find the member with "Pending Access" badge
  4. Click Grant Access


The member's public key is used to wrap the TEK, giving them access.


Grant TEK Access

Screenshot: The pending access banner and grant access button


Removing Members


  1. Select the team
  2. Find the member
  3. Click the menu on their row
  4. Select the trash can to Remove from Team
  5. Confirm the removal


Note: Removed members lose access immediately. They cannot decrypt any team content.



User Management


Viewing All Users


  1. Go to AdminUsers tab
  2. View all users in your organisation
  3. See their status, role, and verification state


User List

Screenshot: The user management table


User Status Indicators


Status

Meaning

Verified

User can access the platform

Pending

Waiting for email verification

Locked

Account temporarily locked

Deleted

Account marked for deletion


Resetting User 2FA


If a user loses access to their authenticator:


  1. Find the user in the list
  2. Click the menu
  3. Select Reset 2FA
  4. Confirm the action


The user will need to set up 2FA again at next login.


Deleting Users


  1. Find the user
  2. In line with the username you will see a trashcan
  3. Select the trashcan icon
  4. Confirm deletion


Warning: This removes the user from all teams and revokes all access.



Organisation Settings


Accessing Settings


  1. Go to AdminOverview tab
  2. Configure organisation-wide options


Branding


Setting

Description

Logo

Upload your organization's logo

Primary Colour

Set your brand colour


Branding Settings

Screenshot: The branding configuration section


Security Settings


Setting

Description

Allowed Domain

Restrict signups to specific email domain

Session Timeout

How long until inactive users are logged out

2FA Required

Force all users to enable two-factor authentication


Embedding Settings


Control how SafeDrop forms can be embedded:


Setting

Description

Enable Embedding

Allow forms to be embedded on external sites

Allowed Domains

Whitelist specific domains for embedding

Custom CSP

Advanced content security policy settings


Message Settings


Setting

Description

Default Expiry

How many days before messages expire

Max Expiry

Maximum expiry allowed for messages

Delete on Expiry

Automatically delete or archive expired messages



Storage Management


Viewing Storage Usage


  1. Go to Admin → **Overview ** tab
  2. See total storage used
  3. View breakdown by team


Storage Usage

Screenshot: The storage usage dashboard


Storage Limits


Your plan includes a storage allocation. When approaching limits:

  • Users receive warnings when uploading
  • Uploads are blocked when limit is reached
  • Contact your SafeDrop account manager to increase limits



Audit Logs


Viewing Audit Logs


  1. Go to AdminAudit Logs tab
  2. Browse security-relevant events
  3. Filter by user, action, or date range


Audit Logs

Screenshot: The audit log viewer


Events Logged


Event Type

Description

Login

User sign-ins (success and failure)

Logout

User sign-outs

User Created

New user registrations

Team Created

New team creation

Member Added

User added to team

Member Removed

User removed from team

TEK Granted

Encryption access granted

File Uploaded

File added to Secure Store

File Downloaded

File downloaded from Secure Store

Message Sent

safedrop message created

Message Viewed

Message opened by recipient


Exporting Logs


  1. Filter to your desired date range
  2. Click Export
  3. Download CSV file



Security Administration


Key Rotation


Rotate team encryption keys for security:


  1. Go to Teams
  2. Select the team
  3. Click Secure store tab
  4. Click Key rotation


All team members receive new wrapped keys. Files are re-encrypted with the new key.


Note: Key rotation may take time for teams with many files.





Account Recovery


When users cannot access their accounts:


Tier 1 Recovery (Self-Service):

  • User uses their 12-word recovery phrase
  • No admin intervention needed


Tier 2 Recovery (Admin Assisted):

  • User requests admin recovery
  • Admin verifies identity out-of-band
  • Admin initiates account reset
  • User creates new credentials


Account Recovery

Screenshot: The admin account recovery interface


Monitoring Failed Logins


  1. Check audit logs for failed login attempts
  2. Look for patterns indicating attacks
  3. Consider temporarily locking affected accounts



Best Practices


Team Structure


  1. Create logical teams - Based on departments or projects
  2. Limit admin roles - Only grant admin where needed
  3. Review memberships regularly - Remove inactive members
  4. Use meaningful names - Make team purposes clear


Security


  1. Require 2FA - Enable organisation-wide 2FA requirement
  2. Monitor audit logs - Check regularly for unusual activity
  3. Prompt TEK approvals - Don't leave users waiting
  4. Rotate keys annually - Maintain encryption hygiene


User Management


  1. Verify identities - Before granting access or recovery
  2. Offboard promptly - Remove departed employees immediately
  3. Document roles - Keep records of who has admin access
  4. Train users - Ensure users understand security features



Troubleshooting


User Cannot Access Team


  1. Check they're added as a team member
  2. Verify their TEK access has been granted
  3. Have them try logging out and back in
  4. Check they've verified their email


Storage Limit Issues


  1. Review storage usage by team
  2. Identify large files that can be removed
  3. Contact SafeDrop for limit increases


Audit Log Missing Events


  1. Ensure you're looking at correct date range
  2. Check event type filters
  3. Some events may be delayed slightly



Getting Help


For issues beyond this guide:

  • Technical Support - Contact SafeDrop support
  • Account Changes - Contact your account manager
  • Security Incidents - Report immediately to SafeDrop security team



This guide covers tenant administration. For super-admin (platform-wide) functions, contact SafeDrop.


Updated on: 20/01/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!