Appearance
Signup review
Every new OpsMerge account is approved by a person before it is created. This article explains what happens between the signup form and the first login, for the platform team doing the approving and for anyone wondering why their account is "being reviewed".
What the signup form checks
The form asks for a company email address. Three outcomes are possible:
- Company domain. The address is on a domain with a mail server. The signup carries on as normal.
- Personal or free mailbox such as Gmail, Outlook.com or iCloud. The signup is accepted, but it is marked as a free mailbox in the review queue and will usually take longer to approve. A managed service provider normally has its own domain, so this is the single strongest sign that a signup is not what it claims to be.
- Temporary mailbox or no mail server. Addresses on throwaway providers, and domains that have no mail server at all, are refused on the form with a message asking for a company address. A verification email could never reach them.
The throwaway provider list is maintained in the open and refreshed periodically.
What applicants see
After the verification link is clicked the page says the email is verified and that the account is reviewed by hand, usually within one working day. Nothing else is needed from the applicant. When the account is approved it is created straight away and the normal welcome email goes out. If it is declined, the applicant receives an email saying so, with a line from the reviewer if one was written, and an address to reply to.
Accounts opened through a warm invite link skip the queue, because those invites were vetted when they were issued.
The review queue
Platform admins find the queue at the top of Brindleford, Signups. Each waiting signup shows:
- The company name, slug and country entered.
- The email address with its domain class.
- Signals gathered automatically a few seconds after verification: how long ago the domain was registered and through which registrar, whether the domain has a website that responds, which country and network the signup came from and whether that matches the country entered, the phone number and the browser used.
- When the email was verified.
The signals are there to make a decision quick, not to make it for you. A brand new domain, no website and a signup from a hosting provider in another country is the usual shape of a junk signup; an established domain with a live website is the usual shape of a real one.
Approve creates the tenant immediately and emails the applicant. Reject asks for an optional note, declines the request and emails the applicant. Either decision is final and recorded in the audit log with who made it. Use Show decided to see past decisions.
Configuration
The queue is on by default. Two environment settings exist for the platform team:
| Setting | Effect |
|---|---|
OPSMERGE_SIGNUP_REVIEW=off | Restores automatic provisioning after email verification. Only for development and test environments. |
OPSMERGE_SIGNUP_REVIEW_NOTIFY | Address that receives the "signup awaiting review" email. Defaults to the platform support address. |