Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

To create a group:

  • Click the Admin Console icon option in the upper right-hand corner the menu bar at the top of the PreVeil browser application, and then select Approval Group Groups from the left-hand menu.

    image-20240604-121553.pngImage Removedimage-20241224-185809.pngImage Added

  • Click on the plus sign icon under the Manage tab.

    image-20240604-121740.pngImage Removedimage-20241224-190001.pngImage Added

  • Give the group a name, and then type in the email address of the first user you want to add. When the user’s email address shows up in the pre-filled drop-down menu, select it to add the user to the group. Repeat to add at least two more additional users to the group. (Remember that you will need to add at least three users before you can create the group; the Create Approval Group button will remain grayed out until at least three users have been added to the group.)

    image-20240604-122310.pngImage Removedimage-20241224-190055.pngImage Added

  • Once at least three users have been added to the group, click on the Create button.

    image-20240604-122447.pngImage Removedimage-20241224-190125.pngImage Added

  • If you create a group with more than three users, then you will have additional options to select from in the How many approvals are required for recovery drop down menu for the required number of approvers

    image-20240604-122742.png

...

  • Admin Management

    • The purpose of this activity is to restrict administrators in the organization. Assigning a group to this activity will make it so certain activities an administrator performs in the Admin console require group approval

    • The Approval Group assigned to this activity must consist of entirely admin users, as a standard level user will not have access to the Admin console functionality

    • Actions like deleting a user, changing a user’s role, and swapping an approval group will invoke the Admin Management group’s approval

  • Data Export

    • Data Export allows an administrator within your organization to download a decrypted copy of the organization’s data

    • An organization must pass the organization health check to complete a full export

    • The types of exportable data are email, drive, activity log, and ACL report

      • Email data is exported in a folder hierarchy consisting of an inbox, drafts, sent, trash, and custom user folders

        • The mail messages are in EML format

      • Drive data is exported in the same folder set as the user’s actual drive and contains the files

      • Activity Log data is exported as a CSV file

      • ACL Report is exported as a CSV file

      • All or a selection of users may be chosen

      • A timeframe is chosen and may span the origin of the organization

    • The Approval Group assigned to this activity may compose of admin users, standard users, or a combination

  • Account Recovery

    • The account recovery Approval Group (also known as the Recovery Group) is a group of users within your organization that approve a user’s account recovery

    • PreVeil doesn’t utilize usernames and passwords for account recovery. Instead, what allows a user to access their PreVeil account is an encryption key that gets generated on a user’s device when they create their PreVeil account.

    • Assigning a Recovery Group to a user in your organization will provide each member of the group with a shard of the user’s encryption key. When invoked, the Recovery Group has the ability to rebuild a user’s key on their device, thereby allowing the user to re-access their account.

    • This is the primary method to protect a user’s account access, as PreVeil does not have access to any of our user’s encryption keys, so we cannot restore these keys for you. As such, the responsibility of making sure this recovery method is available to your users will fall upon the administrators of a PreVeil organization creating and assigning a Recovery Group for their users. We strongly recommend that a Recovery Group is assigned to every user in your organization.

    • The Recovery Group can consist of admin level users, standard level users, or a combination of the two.

...

  • Click on the Assign tab in the Approval Group section of the Admin Console.

    image-20240604-124347.pngImage Removedimage-20241224-190215.pngImage Added

  • Click on the Assign button next to either Admin Management or Data Export. For this example we’ll use Data Export.

    image-20240604-124853.pngImage Removedimage-20241224-190250.pngImage Added

  • Select the group that you want to assign to that activity from the drop-down list.

    image-20240604-125106.pngImage Removedimage-20241224-190331.pngImage Added

  • You will see the details about the group you selected. Click Assign to assign the group to the activity.

    image-20240604-125232.pngImage Removedimage-20241224-190408.pngImage Added

  • You will receive a confirmation message that the selected group is now assigned to the activity.

    image-20240604-125353.pngImage Removedimage-20241224-190438.pngImage Added

To assign an Approval Group as the Recovery Group for your organization’s users

  • Select Approval Group from the left hand menu, then click on the Assign tab.

    image-20240604-131405.pngImage Removedimage-20241224-190507.pngImage Added

  • Click on the Manage Users button.

    image-20240604-131525.pngImage Removedimage-20241224-190531.pngImage Added

  • Click on the checkbox next to the user (or users) you want to assign the Recovery Group to. (You can assign it to more than one user at a time.)

    image-20240604-131856.pngImage Removedimage-20241224-190600.pngImage Added

  • Click on the Set Recovery Group button.

    image-20240604-132054.pngImage Removedimage-20241224-190631.pngImage Added

  • Select the group that you want to assign as the Recovery Group from the drop-down list.

    image-20240604-132209.pngImage Removedimage-20241224-190705.pngImage Added

  • You will see the details about the group you selected. Click Set Recovery Group to assign the group to the users.

    image-20240604-132341.png

  • You will receive a confirmation that the group will now be assigned as the Recovery Group for the selected user (or users).

    image-20240604-134458.pngImage Removedimage-20241224-190816.pngImage Added

Info

Note: The user’s computer needs to be online for the Recovery Group to be successfully assigned. If the user’s device is not online, the Recovery Group will not be assigned to the user’s account. The recovery group will show up in the admin console, but the assignment will be incomplete. If the user’s device doesn’t come online within two weeks of the group being assigned, the assignment will fail, and the group will be removed from the user’s entry in the admin console.

...

  • Select the checkbox of the group you want to copy, and then click on the copy icon.

    image-20240604-135029.pngImage Removedimage-20241224-190843.pngImage Added

  • You can then make any changes you want to that group, like changing the name (which is required as you cannot have two Approval Groups with the same name), adding additional users, deleting existing users, and changing the number of required approvers. Once all changes have been made, click on the Create button.

    image-20240604-135237.pngImage Removedimage-20241224-190952.pngImage Added

  • You will receive confirmation that the new group has been created.

    image-20240604-135346.pngImage Removedimage-20241224-191022.pngImage Added

Replacing an Approval Group

...

  • Select the checkbox of the group you want to delete, and then click on the trash can icon.

    image-20240604-135444.pngImage Removedimage-20241224-191056.pngImage Added

  • Click Yes to confirm.

    image-20240604-135526.pngImage Removedimage-20241224-191128.pngImage Added

  • You will receive a notification that the group has been deleted.

    image-20240604-135608.pngImage Removedimage-20241224-191150.pngImage Added

Info

Note: You will not be able to delete an Approval Group if it is currently assigned to an activity. If this is the case, that Approval Group will need to be replaced before it can be deleted. See the Replacing An Approval Group section above for steps on how to do this.

...