> For the complete documentation index, see [llms.txt](https://docs.silkline.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.silkline.ai/configuration/secure-configuration-guide.md).

# Secure Configuration Guide

Secure administrator access, permissions, sharing, integrations, and data handling for your Silkline organization

Use this guide to secure your Silkline organization before adding users or processing sensitive data. Apply your organization's security requirements when choosing identity providers, recipients, integrations, and export destinations.

**Audience:** Customer organization administrators and their identity-provider administrators. **Version:** 1.7. **Last reviewed:** September 16, 2026.

## Obtain and use this guide

This guide is available without signing in. Bookmark this page or obtain its [Markdown version](https://docs.silkline.ai/configuration/secure-configuration-guide.md). Use the checklist during onboarding, when administrative access changes, and during your organization's periodic access and configuration reviews. Compare your organization's settings with the recommendations below and record any exceptions, their approver, and their review date.

For setup, recovery, or settings that require Silkline assistance, contact <support@silkline.ai>. Report suspected unauthorized access to <security@silkline.ai>. Include your organization name and affected account or resource; do not include passwords, setup links, integration secrets, or sensitive attachments in email.

## Secure the first administrator account

1. Coordinate provisioning with your Silkline contact. Confirm the organization name, approved email domains, designated administrator, and application URL for your deployment. Use the deployment assigned to your organization.
2. Use an individually assigned work account. Protect its mailbox with your organization's approved multifactor authentication (MFA), and restrict mailbox delegation and forwarding. Email sign-in and invitation links grant access to their recipient; keep them confidential.
3. Open the invitation or sign-in page from the confirmed application URL in a supported web browser. Verify the hostname before authenticating. If a local password is used, choose a unique password and store it in an approved password manager.
4. Open **Organization Settings → Users and Access**. Confirm that you are in the correct organization and hold the **Admin** role. Check the default role for new users before inviting anyone or enabling SSO.
5. Establish a second, explicitly authorized administrator for recovery and continuity. Have that person verify their own sign-in and administrative access. Keep recovery credentials under your organization's control and agree on a recovery procedure with Silkline support.

Use Admin only for people who need organization-wide authority. Use a lower privilege account for routine procurement work where practical. Do not share administrator accounts or reuse another administrator's sign-in links.

## Configure SSO and enroll passkeys

An identity provider (IdP) authenticates your organization's users. Silkline controls their application roles and permissions. Configure both layers.

1. Have Silkline verify your organization's SSO email domains. Limit assignment to the Silkline application in your IdP to approved users or groups.
2. As an Admin with permission to create SSO connections, open **Settings → Single sign-on**. Follow [Self-service SSO setup](/configuration/sso-configuration/self-service-sso.md) and copy the exact redirect URI displayed for your organization.
3. Give the setup link only to the intended IdP administrator. The recipient does not need a Silkline account. Each link works once and expires after seven days; revoke unused links from **Outstanding setup links**.
4. In your IdP, require your organization's approved MFA for Silkline access. Enroll an approved passkey or security key using that provider's security settings: register the authenticator, complete the device verification, and register an approved recovery method. Follow your IdP's enrollment and recovery instructions.
5. Test sign-in in a private browser window with both an administrator and an ordinary user. Confirm the IdP's authentication policy applies and Silkline assigns the intended role. Verify that an account without IdP application access cannot enter through SSO. Repeat the test from the Silkline desktop app if your users have it installed.

SSO requires organization-specific setup. Passkey enrollment and MFA enforcement in this procedure are IdP controls; they are not automatically provisioned by Silkline. Silkline's customer Keycloak sign-in flow also supports local password or email-link authentication. Do not assume configuring SSO disables every other sign-in method. Ask support to review the available authentication and recovery paths for your organization before relying on an SSO-only policy.

The Silkline desktop app runs the IdP's sign-in page in the user's default web browser and returns to the app through its registered `silkline://` link, so an IdP policy requiring a passkey or security key applies there on the same terms as the web app. The app accepts one such return per sign-in attempt, matched to a single-use value it generates, and the attempt expires after five minutes.

See [SSO Configuration](/configuration/sso-configuration.md) for supported providers and environment-specific guidance. Enroll passkeys in a web browser, through your IdP's own security settings.

## Understand roles and security-sensitive settings

**Admin** is Silkline's top-level customer administrative role. It includes organization settings, user-role assignment, SSO connection setup, integration editing, and Public Files management. A user with permission to assign roles can assign Admin. Treat that permission as administrative authority.

Silkline support has separate provider administrative capabilities. Customer Admin access does not grant control of Silkline's infrastructure or other customer organizations. Contact support for provider-managed provisioning, domain changes, and recovery assistance.

| Role             | Security implications                                                                                                                        |
| ---------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| Admin            | Controls organization-wide access and security-sensitive settings. Limit membership and review each assignment.                              |
| Buyer            | Can conduct procurement and send supplier communications; can edit email templates. General organization settings require Admin permissions. |
| Supplier Quality | Can manage supplier and quality information and send evaluations. Review access to externally shared assessment content.                     |
| Material Planner | Can manage parts and send supplier check-ins. Review the recipients and information exposed by those messages.                               |
| Punchout Buyer   | Has purchasing capabilities for punchout-supporting suppliers. Review purchasing and approval authority separately.                          |
| Collaborator     | Can contribute sourcing information, including requests and quotes. Grant only when editing is needed.                                       |
| Viewer           | Use for people who need visibility without editing authority. Viewing data still creates a confidentiality responsibility.                   |

Keep role-based access control (RBAC) enabled. Disabling it gives members a broad default permission set; the role restrictions described here depend on RBAC. Ask support to confirm RBAC if the role controls are unavailable. Prefer **Viewer** as the new-user default, then assign additional roles after approval. Changing the default role does not change existing members' assignments.

See [Users and Access](https://github.com/Silkline/client-app/tree/development/docs/configuration/profile-and-settings/organization-settings/organization-users.md) for role assignment. Review all assignments, including SSO users created on first sign-in. Organization-wide settings are not all Admin-only: for example, Buyers can edit supplier email templates. Apply the permission model to the specific setting being changed.

## Control supplier and share-link exposure

Before sending an RFQ, PO, check-in, evaluation, or issue, verify the recipient addresses, supplier, message body, resource details, and attachments. Include only information approved for those recipients. Treat shared mailboxes as access granted to everyone who can read that mailbox.

Supplier links can expose resource information without a Silkline sign-in. Protected attachments can require verification of the recipient email address. A tokenized link does not by itself verify the reader's identity. Do not forward links beyond the approved audience or place them in public tickets or websites.

Expiration depends on the sharing action. RFQ email shares and links created with **Copy share link** have a 30-day expiration. Review the access expiration shown for the resource rather than assuming every share uses the same duration. See [Supplier access](https://github.com/Silkline/client-app/tree/development/docs/for-suppliers/accessing-rfqs-and-pos.md).

To remove a recipient's protected access, open the resource's **Share** menu, select **Unshare** for the recipient, and confirm removal. This removes that recipient's access to protected content, including attachments. Guest links can remain usable until they expire. If a link is disclosed or immediate revocation is needed, contact support to revoke the affected link access as well. Revocation cannot recall data that a recipient has already downloaded.

### Public Files

**Organization Settings → Public Files** is for documents approved for public distribution. Uploading publishes a file immediately. Its URL requires no authentication and does not expire. Do not upload confidential or controlled documents here. The absence of a public listing does not make a URL private.

Admin users with the **Edit organization hosted file** permission can manage these files. With RBAC disabled, all members can manage them. Use **Unpublish** to disable a public URL and verify it in a signed-out browser. Existing copies outside Silkline remain outside your control. See [Public Files](/configuration/public-hosted-files.md).

## Protect integration credentials and data flows

Have Silkline support configure only the integrations your organization has approved. For each connection, use a dedicated external service identity with the minimum necessary resource access. Confirm the destination, account, and ingest/writeback directions before enabling a flow.

An Admin can open **Organization Settings → Integrations**, select the integration, and use **Secrets → Add Secret** or **Edit Secret**. Submit secrets through that form, not in documentation, chat, or ordinary email. Saved secrets are encrypted and cannot be viewed through the form after submission.

For rotation, issue a replacement credential in the external system, save it in Silkline, verify the intended synchronization, and revoke the superseded credential in the external system. Updating Silkline's stored secret does not revoke the credential at its issuer. For a compromised credential, revoke it promptly and coordinate recovery with support.

Review **Connected Resources** for actual data-flow directions. Disable unneeded flows through the integration's configuration and coordinate decommissioning with support. Revoke external credentials when retiring a connection. An integration's availability does not establish that its destination is approved for your organization's sensitive data.

See [Managing Integrations](/configuration/integrations/managing-integrations.md) and the guide for your external system.

## Verify desktop app browser permissions

The Silkline desktop app permits clipboard reads and writes only from the configured Silkline application origin. It denies other browser permission requests from Silkline pages and all requests from sign-in and supplier punchout pages. Denied capabilities include camera, microphone, geolocation, and notifications.

During desktop-app acceptance testing, copy and paste approved non-sensitive text in Silkline and confirm both operations work. Open an approved supplier test page that requests a denied capability, and confirm that the page does not receive it or display a Silkline operating-system permission prompt. Use an approved web browser outside the desktop app for an authorized workflow that requires another browser-managed permission.

## Confirm operational logging destinations

Silkline operators manage operational logging destinations and credentials. Ask Silkline support to confirm the approved destinations for your deployment before processing data with residency or handling restrictions. Keep telemetry credentials in the managed secret store; do not include them in support messages.

During infrastructure ownership changes, Silkline operators retain log storage, secret references, and subscription targets and verify delivery to each approved destination. Request confirmation from support when reviewing these controls.

When more than one monitoring destination is approved, request separate delivery evidence for each destination, including infrastructure route-health metrics and cloud audit events from each AWS account. A configured monitor or a successful infrastructure deployment does not establish that its telemetry is arriving.

Include the deployment cluster in verification: request recent node counts, available deployment replicas, CPU and memory metrics, and indexed container logs from each approved destination. Confirm collector readiness after rollout.

Prepared Government notification destinations do not establish cutover. US5 remains the notification and signal-review authority until an attended activation. Verify Government detections without paging or creating triage tickets.

Request confirmation of the active monitoring notification destination and a recent alert-and-recovery delivery test. During a destination change, operators verify synthetic execution, monitor evaluation and notification delivery, and confirm that the standby destination does not send duplicate monitoring alerts. Include Cloud SIEM high/critical and medium notifications, signal-review queue checks and checker heartbeats in the verification. Confirm that open signals in the standby organization have a recorded disposition.

## Review notifications and data exports

Review **Organization Settings → Email Settings** before sending supplier communications. Approve the From address, domain configuration, email templates, recipients, and any copied mailboxes. Templates affect the whole organization; Buyers as well as Admins can edit them. Avoid putting sensitive details directly in subjects or message bodies when a restricted resource link is appropriate.

Under **Account**, review approval email preferences, approval delegates, auto-follow tags, and evaluation reminders. Choose recipients and delegates who are authorized to receive the related information. These are personal settings; approval confirmation and delegate approval emails default to off, and evaluation reminders default to off for a newly created user. Other workflow emails can still be sent. See [User Profile](https://github.com/Silkline/client-app/tree/development/docs/configuration/profile-and-settings/user-profile.md) and [Email Settings](https://github.com/Silkline/client-app/tree/development/docs/configuration/profile-and-settings/organization-settings/email-settings.md).

For [line-item CSV exports](https://github.com/Silkline/client-app/tree/development/docs/configuration/line-items.md#export-to-csv), the current view's filters and columns determine the exported content. Review both before exporting and export only what the recipient needs. Store downloads on approved devices and in approved repositories, apply your organization's retention rules, and remove temporary copies when appropriate. CSV files, PDFs, and downloaded attachments are copies outside Silkline's access controls; changing a role or revoking a share does not recall them. Apply your organization's access and device policies to exports, and ask support to confirm available controls for your deployment.

## Recommended settings and provisioning defaults

These provisioning states describe a newly created organization in Silkline's standard provisioning workflow. Existing organizations and explicitly configured deployments can differ. Verify your organization's actual state before use.

| Setting                           | Controlling role                                                 | Provisioning state                                                                                            | Recommendation                                                     | Security implication                                                                       | Verification step                                                                    |
| --------------------------------- | ---------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ |
| RBAC                              | Silkline support manages enablement; Admin manages user roles    | Enabled                                                                                                       | Keep enabled                                                       | Disabling RBAC grants broad member permissions                                             | Review role controls in Users and Access; confirm enablement with support            |
| Default role for new users        | Admin                                                            | Selected explicitly during provisioning; no fixed Viewer default                                              | Select Viewer unless a reviewed workflow requires more access      | New joiners, including SSO users, receive this role                                        | Check the default role and a newly joined user's assignment                          |
| Administrator assignments         | Silkline support provisions access; Admin assigns customer roles | Named administrator requires an explicit assignment                                                           | Limit Admin; verify a recovery administrator                       | Role-assignment authority can grant full customer administrative access                    | Review every Admin and role-assignment grant                                         |
| SSO connection                    | Admin with SSO permission and the customer's IdP administrator   | Requires connection setup                                                                                     | Configure approved domains and restrict IdP application assignment | SSO can create users on first sign-in                                                      | Test an approved user and an unassigned IdP user                                     |
| MFA and passkeys                  | Customer IdP administrator and each user                         | IdP-managed; not automatically enrolled by Silkline                                                           | Require approved MFA and enroll approved passkeys/security keys    | Authentication strength depends on IdP policy and alternate sign-in paths                  | Test enforcement and review alternate paths with support                             |
| Send on behalf                    | Admin; IT administrator configures sending-domain DNS            | Disabled                                                                                                      | Leave disabled until the sender domain and use are approved        | Outbound email can represent your organization                                             | Review Email Settings and a test message's sender                                    |
| Supplier/resource sharing         | Users with the relevant resource-sharing permission              | No resource recipients at organization provisioning; grants arise from sharing actions                        | Share only with approved recipients and review expiration          | Guest links and authenticated attachment access have different scopes                      | Inspect Share access and test the intended recipient's view                          |
| Public Files                      | Admin with hosted-file permission                                | No files at provisioning; uploads publish immediately                                                         | Publish only approved public documents                             | URLs require no authentication and never expire                                            | Review the Public Files list and open a URL while signed out                         |
| Integration credentials and flows | Silkline support creates integrations; Admin edits them          | Require integration setup and credentials                                                                     | Use scoped service identities and only approved flow directions    | Connections can import or export organization data                                         | Review Secrets status and Connected Resources; verify a sample sync                  |
| Desktop browser permissions       | Silkline desktop app                                             | Clipboard access is limited to the Silkline application origin; other browser permissions are denied          | Keep the origin-scoped clipboard policy                            | Sign-in and supplier content cannot access clipboard or other browser-managed capabilities | Test Silkline copy/paste and a denied permission from an approved supplier test page |
| Personal notifications            | Each user                                                        | Approval confirmation emails, delegate approval emails, and evaluation reminders default to off for new users | Enable only the notices needed by authorized recipients            | Notifications can contain procurement details outside the application                      | Review Account preferences and a test notification with non-sensitive data           |
| Operational logging               | Silkline operators                                               | Centrally managed destinations and secret-store credentials                                                   | Confirm approved destinations and coverage with support            | Telemetry delivery follows the configured destinations                                     | Obtain per-destination metric and audit-event evidence after routing changes         |
| Data exports                      | Users with access to the relevant export workflow                | Created on request using the selected view; not generated during organization provisioning                    | Minimize columns and rows; use approved storage and retention      | Downloaded copies are outside Silkline access controls                                     | Review the selected view and a sample export before distribution                     |

Recommendations requiring customer action are not automatically applied secure defaults. Record and resolve any differences between your approved configuration and the actual settings with your security team and Silkline support.

## Review and decommission administrative access

Review administrator assignments, default roles, SSO application assignments, outstanding setup links, supplier shares, public files, integration credentials, and notification recipients at your organization's required interval. Use [Resource History](https://github.com/Silkline/client-app/tree/development/docs/configuration/resource-history.md) to review available resource changes; contact support for authentication or administrative investigation assistance.

When an administrator leaves or changes responsibilities:

1. Assign a successor and verify their sign-in and administrative permissions before removing the departing administrator, unless immediate containment is required.
2. Remove the departing person's Admin and other unnecessary role assignments in **Users and Access**. Remove their Silkline application assignment in the IdP and revoke applicable IdP sessions and authenticators.
3. Coordinate with Silkline support to revoke remaining Silkline sessions and disable applicable local authentication or recovery access. **Inactive** status for SSO users affects visibility; it does not block their sign-in.
4. Reassign approval delegates and operational responsibilities. Revoke unused SSO setup links and rotate any integration credentials the departing person controlled or could have retained.
5. Review their resource shares, Public Files, and exported copies under your retention policy. Verify that the departing account cannot sign in or use the removed privileges.

For organization decommissioning, agree on approved exports, retention, access revocation, and data disposition with Silkline support before ending service.

## Browser connection policy

Silkline manages the application's Content Security Policy (CSP). Frame, embedding, object, and base-URL restrictions are enforced. The `connect-src` policy is report-only: violations are reported without blocking requests.

The connection allowlist includes `media.licdn.com`, `media-exp1.licdn.com`, and `static-exp1.licdn.com` for avatar checks, and `fonts.gstatic.com` for PDF fonts. It also permits `data:` and `blob:` fetches for embedded and browser-generated resources. These entries apply only to the report-only connection policy.

Keep browser security protections enabled. Review your organization's network restrictions with Silkline support when avatar images or PDF exports fail. To verify a deployment, inspect the document's response headers in browser developer tools: these sources belong in `Content-Security-Policy-Report-Only` under `connect-src`. Test avatar display and order PDF export, and review CSP reports for unexpected destinations before enforcing the connection policy.

## Administrator checklist

* [ ] Verify the organization, deployment URL, named Admins, and recovery access.
* [ ] Keep RBAC enabled and review the default role and existing assignments.
* [ ] Configure and test SSO, IdP MFA/passkeys, and alternate sign-in paths.
* [ ] Revoke unused SSO setup links.
* [ ] Review supplier recipients, guest links, and protected attachment access.
* [ ] Confirm every Public File is approved for unauthenticated distribution.
* [ ] Review integration identities, credentials, destinations, and flow directions.
* [ ] Verify desktop copy/paste and denial of other browser permissions.
* [ ] Confirm operational logging destinations and delivery evidence with support.
* [ ] Review notification recipients, delegates, email templates, and exports.
* [ ] Record exceptions and verify departing administrators' access is revoked.

## Maintenance and revision history

Update this guide whenever security-relevant settings are added or existing settings, provisioning defaults, permissions, or administrative workflows change. Update the recommendations, verification steps, review date, and revision history in the same change.

| Version | Date       | Coverage                                                                                                                                         |
| ------- | ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| 1.0     | 2026-09-09 | Administrator lifecycle, SSO and IdP passkeys, permissions, sharing, integration credentials, notifications, exports, and provisioning defaults. |
| 1.1     | 2026-09-10 | Desktop app sign-in through the system browser, and the passkey and security-key policy that applies to it.                                      |
| 1.2     | 2026-09-16 | Operational logging destinations, credential handling, and verification during infrastructure ownership changes.                                 |
| 1.3     | 2026-09-16 | Per-destination verification of infrastructure metrics and AWS account audit events.                                                             |
| 1.4     | 2026-09-16 | Deployment-cluster metric, log, and collector-readiness verification.                                                                            |
| 1.5     | 2026-09-16 | Browser CSP enforcement, report-only avatar and PDF connection sources, and verification guidance.                                               |
| 1.6     | 2026-09-16 | Monitoring and SIEM preparation, notification authority, checker and standby verification.                                                       |
| 1.7     | 2026-09-16 | Desktop app origin-scoped clipboard policy, browser-permission denial, and customer verification.                                                |
