Project access and exact scientific assets
This is a tested private native-backend pilot. OSDU-backed parity, public signup and production customer distribution are separate qualifications.
Create a project and grant access
Section titled “Create a project and grant access”An organization owner opens Projects → New project. This grants the creator project administration, publishing and compute permissions; it does not promote the account to a global administrator. Ordinary organization members cannot create projects. Invite a colleague and wait for verified acceptance, then open Project access and explicitly grant viewer or member access. Organization membership alone does not grant scientific data access.
Effective access shows direct grants, inherited team grants and project blocks. Revoking a direct grant may leave team access. Review block removes direct access and suppresses team access for that person in this project. It does not change another team member’s permissions. Review unblock makes existing team grants effective again; deleted direct grants need to be granted again separately. A new direct grant does not override an existing block.
Remove someone deliberately
Section titled “Remove someone deliberately”Use Organization → Members → Offboard. Review affected projects and confirm. The operation removes membership and blocks direct/team access to every project currently associated with the organization. It requires organization ownership and project administration for every affected project. Missing permissions or removing the last effective administrator causes the entire operation to fail without changes. Ask another administrator to establish a replacement or provide the required authority.
This does not revoke global sign-in sessions, unrelated project access or downloaded copies. Projects associated later require another review. Membership-only removal remains a separate action. Another owner must offboard your own account.
Understand what was published
Section titled “Understand what was published”Data searches authorized loaded assets by name, identity and metadata and filters by type. Open an asset and select an exact revision. Its scientific description shows:
- The authoritative backend, asset identity and exact revision.
- Units, finite range, missing sample count and curve/depth or grid/coordinate meaning.
- Whether the original was retained for this revision, and normalized/derived representations.
- Source revision, source metadata and recorded derivation where present.
- The supported exchange profile and its conformance result.
Download the exact revision link or scientific description. A link does not grant access; the recipient must still be authorized. Existing export actions retrieve the original bytes or exact normalized snapshot. A derived revision may have no original file of its own. Historical originals are attached to their original revisions.
An unknown depth datum or vertical reference remains unknown. Horizontal CRS is not vertical datum, and scalar values are not automatically elevation. Publication readiness and profile conformance do not mean scientific approval.
See scientific exchange contracts and Workspace foundations.
Invitation accepted with the wrong account
Section titled “Invitation accepted with the wrong account”Opening an emailed link is not acceptance. Choose Create an account and accept invitation if you have no provider account for the invited address. Register, verify that address, and complete the return to Workspace. Existing users choose Accept invitation and sign in with the invited address. A demo identity cannot accept an invitation sent to your personal address.
Failed admission returns to the invitation with an error and retry controls, even when another Workspace session already exists. Reopen the email link if you reload the page and lose the retry controls. After successful acceptance, the owner uses Refresh invitations and members on Organization → Members. Project access is a separate grant: choose the joined account from the account field’s suggestions; typing a new name does not create an account. Keep at least one project administrator. An invitation for an existing member reuses their issuer/subject identity and never creates a duplicate member.
Choosing a password during signup
Section titled “Choosing a password during signup”The hosted Keycloak 26.7.4 flow is email-first: enter profile details, open the verification email, then choose and confirm an Ophiolite password. There is no password field on the initial registration form. This is a separate credential from the password for your email inbox. The registration and verification pages now explain the sequence explicitly; verification remains required.
If you already registered, do not create another account. Complete the verification email. If its link has expired, use Accept invitation → Forgot password with the same email address to request recovery, then reopen the invitation after finishing any required verification/password steps. Organization admission and project grants remain separate. Customer-managed identity providers may offer another credential flow.
Collaboration walkthrough
Section titled “Collaboration walkthrough”- Sign in with your own verified account. An existing owner grants organization ownership in Members and grants project administration separately in Project access. Keep the previous administrator until the replacement has been tested.
- Invite a second person. A second pending invitation for the same email is refused; use Resend instead. Resend replaces the old link. Successful acceptance retires legacy duplicate pending links for that organization and address.
- Refresh invitations and members. In Project access, search organization members by name, select the joined person, and grant Viewer. An invitation does not itself grant access to project data. Unassigned projects retain the account-ID interface.
- In a separate browser, verify the viewer can read the asset but cannot publish, compute or administer. Block their project access and retry the read. Existing downloaded snapshots are not erased by revocation; new server reads are denied.
- As a project member with Compute permission, import the public elevation fixture from the documented CRS examples, review its meaning and publish it. Open the lightweight View in another tab with Follow enabled. Run scalar offset +10. The following tab should advance; selecting the earlier revision should retain its original values. This deliberately alters a test surface, not a corrected real-world elevation model.
- Connect QGIS using its separately configured credential. Keep one following and one pinned layer. Verify the live update and source/project CRS distinction. Browser login does not automatically provision QGIS credentials.
Shared Workspace surface editing
Section titled “Shared Workspace surface editing”Workspace GeoTIFF imports (workspace-geotiff-v1) are shared editable surfaces.
A project member with compute permission may publish a new revision of an existing
Workspace raster imported by another person. This policy is checked in the native
service against the registered source adapter, mapping, raster key and scalar-map
kind, with a nonzero expected revision. Project membership, compute access,
optimistic concurrency, scientific invariants and original-payload authorization
remain enforced. Connector-managed sources retain exclusive publisher ownership.
New revision metadata records publishedBy from the authenticated principal.
The operator button displays progress, success or the failure beside the button. After success, clients with Follow enabled update; pinned clients stay unchanged. If another user already advanced the asset, select the latest revision and submit again. The right-hand lightweight View is an optional second consumer, not a required extra step in publishing.
Sign out and change accounts
Section titled “Sign out and change accounts”Workspace Sign out revokes its session. It does not sign you out of other applications using the same identity provider. Continue with Ophiolite Account now requests fresh authentication instead of silently signing in. If the provider remembers the wrong identity, choose Use a different account, confirm provider sign-out, then Continue. The hosted provider now shows an editable username/email and password form. Provider sign-out ends its remembered SSO session and may also affect other applications using that session. Other providers control their own authentication screen and may use passkeys or corporate login rather than a password form.
