Skip to main content

Workspace reviews

The Workspace reviews screen is where Sectigo platform reviewers decide which verified workspace requests become workspaces. A request appears here only after the requester has confirmed their work email and proved control of their domain with a DNS TXT record.

Ownership is evidence, not authorisation

Mailbox and DNS proof show who controls the domain. Your review is the separate, human decision that creates the workspace. No review action grants PKI access: approval does not connect a CA or grant any signing permission.

What you need​

  • A platform administrator account with permission to review workspaces. Without it, the screen does not load.
  • A sign-in with MFA completed within the last ten minutes at the moment you record a decision. See The ten-minute rule.

Open the screen​

Go to /console/platform/onboarding. The page is marked PLATFORM-RESTRICTED and has two tabs: Workspace reviews and Signer & keys. Tenant console in the top right returns you to the normal console.

Workspace provisioning review page listing a pending request with organisation, country, domain, verified contact, registration ID and expiry, and Reject and Review and approve buttons
Pending requests, each with its verified contact and registration details.

Read a request​

Use the filter at the top to choose pending, approved, rejected or expired requests, and Refresh to reload. Each request shows:

FieldMeaning
Country · domainThe two-letter country code and the verified enterprise domain.
OrganisationThe organisation name the requester entered.
Statuspending, approved, rejected or expired.
Verified contactThe requester's name and their confirmed work email (which is on the verified domain).
RegistrationThe registration ID (for example reg_3f6c2a91-…) and when the request Expires.
TenantShown on decided requests: the reserved tenant ID and the decision code.

A request expires seven days after the requester signed up. Decide before the Expires time, or the request moves to expired and the requester must sign up again.

Approve a request​

  1. On a pending request, select Review & approve. The APPROVAL dialog opens.
  2. Check the Reserved tenant identifier. It is pre-filled from the domain (for example northwindhealth.com becomes northwindhealth-com). Edit it if needed; see Tenant ID rules.
  3. Choose a Decision code (see Decision codes).
  4. Type APPROVE WORKSPACE exactly, in capitals, in the confirmation field.
  5. Select Approve for provisioning.
Approval dialog with a Reserved tenant identifier field, a Decision code list set to Verified contract, a field to type APPROVE WORKSPACE, a Fresh MFA required notice and an Approve for provisioning button
The approval dialog. The button stays disabled until the confirmation text matches exactly.

On success the dialog closes and a notice reads Organisation was released to the provisioning queue.

What approval does​

  • Reserves the tenant ID for this workspace.
  • Activates the requester's account as the workspace's first administrator. On their next sign-in they are asked to enrol MFA.
  • Does not create other users, connect a CA, or grant certificate-signing authority.

The requester is not emailed about the decision. They find out by signing in. You may want to let them know through your usual customer channel.

Tenant ID rules​

RuleDetail
CharactersLowercase letters a–z, digits 0–9 and hyphens -. The field lower-cases input and removes other characters as you type.
Length3 to 63 characters.
First characterA letter or digit (not a hyphen).
UniquenessMust not already be reserved by another approved workspace.

Choose the ID carefully: it identifies the workspace everywhere, and this screen has no way to change it after approval.

Reject a request​

  1. On a pending request, select Reject. The REJECTION dialog opens.
  2. Choose a Decision code.
  3. Type REJECT WORKSPACE exactly, in capitals.
  4. Select Reject request.
Rejection dialog with a Decision code list set to Domain risk, a field to type REJECT WORKSPACE and a Reject request button
Rejection takes a structured reason only; there is no free-text field.
Rejection is final

A rejection cannot be reversed from this screen. The requester would need to submit a new sign-up.

On success the notice reads Organisation was rejected.

Decision codes​

Decisions use structured codes only; free-text reasons are not accepted.

DecisionCode shown in the listStored codeUse when
ApproveVerified contractverified_contractThe organisation has a verified commercial agreement. (Default for approvals.)
ApproveApproved trialapproved_trialThe workspace is approved for a trial.
ApproveApproved internalapproved_internalThe workspace is approved under an internal arrangement rather than a contract or trial.
RejectDomain riskdomain_riskThe domain or organisation presents unacceptable risk. (Default for rejections.)
RejectDuplicate requestduplicate_requestThe organisation already has a request or workspace.
RejectCustomer withdrewcustomer_withdrewThe requester asked to cancel.
RejectSecurity review failedsecurity_review_failedThe request did not pass security review.
RejectUnsupported regionunsupported_regionThe organisation's country or region cannot be served.

The ten-minute rule​

Recording a decision is a privileged action. It requires that you completed MFA within the last ten minutes. The dialog reminds you with Fresh MFA required. You can browse and open requests at any time; the check happens when you select Approve for provisioning or Reject request.

If your sign-in is older than ten minutes, the dialog shows:

This action requires an MFA-authenticated privileged session issued within the last ten minutes

with a Re-authenticate button next to it.

  1. Select Re-authenticate. Your current platform sign-in ends and the page reloads.
  2. Sign in again, completing MFA.
  3. The dialog for the same request reopens automatically.
  4. Check the tenant ID and decision code again. They return to their defaults (the suggested tenant ID and the default code), so any edits you made before re-authenticating are lost.
  5. Type the confirmation again and submit within ten minutes.
tip

To avoid the prompt, sign in fresh just before working through a batch of reviews, and keep each decision inside the ten-minute window.

If phishing-resistant MFA is required for your account, you may instead see This action requires a recent passkey or phishing-resistant enterprise MFA session. This message does not offer a Re-authenticate button: sign in again to the platform using a passkey or a phishing-resistant enterprise MFA method, then reopen the request.

Troubleshooting​

MessageCauseWhat to do
This action requires an MFA-authenticated privileged session issued within the last ten minutesYour MFA is older than ten minutes.Select Re-authenticate; see The ten-minute rule.
This action requires a recent passkey or phishing-resistant enterprise MFA sessionA phishing-resistant method is required.Sign in again with a passkey or phishing-resistant enterprise MFA, then reopen the request.
Tenant identifier is already reserved by another approved workspaceAnother workspace already uses this ID.Choose a different tenant ID.
Approval requires a lowercase tenant identifierThe ID breaks the rules, for example it starts with a hyphen.Correct the ID.
A permitted structured decision code is requiredNo valid decision code was sent.Choose a code from the list and resubmit.
Workspace review already has a different final decisionSomeone else decided this request differently, for example in another tab or by another reviewer.Select Refresh and check the request under approved or rejected.
Workspace provisioning review has expiredThe request passed its expiry time.No action is possible; the requester must sign up again.
Workspace provisioning review was not foundThe request no longer exists or is not ready for review.Select Refresh.
The review decision was recorded but durable provisioning notification must be retriedYour decision was saved, but a follow-up step did not complete.Submit the same decision again (same tenant ID and code). Repeating an identical decision is safe.
An error banner appears as soon as the page loadsThe list could not be fetched, often because your account lacks workspace-review permission or your platform sign-in expired.Select Refresh. If it persists, sign in again and confirm your platform permissions with whoever manages platform administrator access.