Add trusted accounts

Dina Bennett
Dina Bennett
  • Updated

Trusted accounts let administrators create a trusted relationship between separate Ziflow accounts. This allows trusted users to be added more easily to reviews. Trusted accounts synchronize user information (either one way or both ways) and simplify authentication for users. For more information, see Understand multiple accounts and trusted accounts.

A trusted relationship does not give trusted users access to another Ziflow account. The only way for a user to access an account is to be added as a licensed user to that account. 

Available for Ziflow administrators on: Enterprise

Trusted accounts enable:

  • Trusted users: Users from the trusted account are synchronized to your account, so you can add them to proofs. Trusted users can be selected to review proofs, but they are not added as licensed users to your account and cannot access your account. When added to proofs, trusted users are able to access proofs from their own account dashboard.
  • Controlled proof sharing: Administrators can limit proof sharing to users in their own account and trusted accounts, helping ensure proofs are shared only with approved users and domains.
  • Authentication: Administrators and users can switch between Single Sign-On (SSO)–enabled accounts without re-authenticating each time. This also applies to two-factor authentication (2FA) and trusted device setups.

A trusted user is not the same as a Ziflow guest:

  • A guest has no Ziflow account, they access proofs that are shared with them through an emailed link, without signing in to Ziflow. See Understand users, guests, and lite users.
  • A trusted user is a licensed user in another account. Synchronization doesn't change their account status anywhere. To view trusted user permissions, see Permissions by person type.
  • This status is ongoing and automatic. As long as the trust relationship exists, active users from the trusted account continue to appear as selectable recipients in your account. Removing the trust relationship removes them from that list.

Before you begin

  • Trusted accounts require at least two separate Ziflow accounts, hosted in the same regional data center (US or EU). You cannot create a trusted relationship within a single account, and accounts in different regions can never be connected. For more information, see Understand the EU data center and regional separation
  • You must be an administrator in the account. 
  • Trusted relationships can be established between accounts using different email domains, as long as the required trust IDs are exchanged. 
  • Users who need to access both account dashboards must be added as licensed users in each account.

Open Trusted accounts

To open, go to Settings > Security > Trusted Accounts

 

open-trusted-acocunt.jpg

Your trust ID is at the top of the Trusted Accounts page. Share this ID with other Ziflow accounts to establish trust.
By sharing your trust ID, you allow another account to synchronize information about your active users as trusted users.

Add a Trusted account

  1. Select Add Account.
  2. Enter the Trust ID of the account you want to trust.

    add-trusted-account.jpg

    Ziflow confirms the connection and adds the account to your list.

Synchronization modes

Trusted account synchronization is controlled by two independent settings for each trusted account connection: We trust them and They trust us.

  • We trust them: Their active users are synchronized to your account as trusted users. 
  • They trust us: Your active users are synchronized to their account as trusted users.

You can enable either setting on its own, or both together:

  • We trust them only — one-way trust, inbound. You receive their users as trusted users; they do not receive yours.
  • They trust us only — one-way trust, outbound. They receive your users as trusted users; you do not receive theirs.
  • Both enabled — two-way trust. Each account synchronizes its users to the other.

To enable two-way trust, repeat the setup in the other account: add your Trust ID to their Trusted Accounts list, and have them add their Trust ID to yours. Once both sides have added each other, both accounts stay synchronized automatically.

To check your current configuration for a trusted account, look at the Trust relationship column on the Trusted Accounts page. It shows which of the two settings are enabled for that connection.

one-way-trust.jpg

Synchronizing users across more than one trusted account

If your account has We trust them enabled for more than one trusted account, it collects trusted users from each of them. If They trust us is also enabled for those same accounts, everything your account has collected, including users it pulled in from its other trusted accounts, is shared back out to them.

This means two accounts can end up seeing each other's users even if they were never directly trusted with each other, as long as they're both trusted with the same third account in both directions. See Two-way trust across three accounts below.

There is currently no way to connect two accounts to a shared third account while keeping those two accounts isolated from each other's trusted users, if the shared account has both We trust them and They trust us enabled for both connections. This is a known limitation. If you need this kind of isolation, consider using We trust them only (one-way) on the connections where inbound users aren't required, or contact Ziflow Support to discuss your setup before connecting more than two accounts.

trusted-account-configurations.png

Authentication behavior

When accounts are trusted, users who have access to both accounts can switch between them without signing in again. This also applies when 2FA is enabled.
For example, if your primary account doesn’t use 2FA but a secondary trusted account does, you won’t need to authenticate again with 2FA when switching.

 

 

Related to

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.