Coordinate programmes without taking ownership of the professional.
Merentra now supports controlled organisation tenants, seats, programme teams, cohorts, placements, purpose-limited consent, member-accepted credentials and auditable access. Joining an organisation never grants automatic access to a member-owned portfolio and does not reveal a member’s private workspace.
Controlled availability: the Organisation workspace is available for approved founding pilots with governed onboarding. It is not an unrestricted self-service organisation product.
The tools a real programme needs—without WordPress Admin.
Role-specific screens keep the workflow focused on the organisation, programme and member relationship rather than exposing the underlying website administration.
People and seats
Invite members, allocate bounded seats, suspend access and keep the final active owner protected.
Programmes and cohorts
Structure programmes, cohorts and placements with clear dates, responsible teams and status.
Purpose-limited roles
Owners, administrators, programme leads, supervisors, reviewers and support roles receive only the actions needed for their purpose.
Consent centre
Request a defined summary or credential scope. Members can grant, decline or revoke directly from the App.
Credentials
Issue bounded claims with provenance, expiry and revocation. A credential remains pending until the member accepts it.
Audit and boundary health
Review sensitive actions, signed service health, mirror state and exact reconciliation before a pilot is promoted.
One relationship. Three clearly labelled data domains.
Merentra does not blur member information and organisation records into one invisible pool.
The private professional workspace
Work, Record, Practice, Training, Opportunities, private notes, Mara drafts and individual feedback stay with the member.
- No automatic organisation access
- No raw evidence transfer by membership alone
- Member export and erasure controls remain available
A bounded summary for one purpose
A member may approve a defined view with a reason, scope and expiry.
- Grant, decline and revoke controls
- Every read creates an audit receipt
- Individual feedback responses are excluded
Programme administration and credentials
Seats, cohorts, placements, organisation roles and issued credentials form the organisation’s service record.
- Retention follows contract and law
- Member links can be revoked or pseudonymised
- No hidden claim over the wider portfolio
Support staff should not inherit supervisor visibility.
Role boundaries are explicit and the final active owner cannot be removed accidentally.
The member sees who is asking, why, what and for how long.
A programme relationship is not treated as blanket permission.
Keep WordPress as the bridge—not the final organisation data authority.
Pass 23 includes an optional companion data-service package for a separate HTTPS service estate. It receives a deterministic, pseudonymous organisation snapshot rather than the member portfolio.
Member and pilot workspace
The App prepares a bounded organisation export and retains local data during pilot migration.
- No raw WordPress user IDs
- No invitation email addresses
- No evidence or feedback responses
- No provider credentials
Encrypted tenant snapshot
Signed requests use timestamp, nonce, content hash and HMAC. The service stores encrypted snapshots and exposes only a hash manifest for reconciliation.
- Replay protection and bounded clock skew
- Current and previous secret rotation
- Key-continuity health check
- Exact local/remote hash comparison
Promotion control: an organisation pilot remains blocked until signed health, storage, key continuity, an exact mirror, reconciliation and a tested restore are evidenced. Mirroring never requests local deletion.
Issue a claim the member can accept—and anyone can verify safely.
Credential verification reveals bounded issuer claims and current status, not the member’s identity or private portfolio.
Consent
The member grants a credential-specific scope for the stated purpose.
Issue
The organisation creates a bounded claim with provenance and expiry.
Accept
The credential remains pending until the member accepts it.
Verify or revoke
A public verification route shows status; revocation requires a recorded reason.
A guided route from interest to controlled use.
The Organisation workspace is real, but each pilot still needs named owners, a lawful purpose, configured roles, a separate service, restore evidence and support arrangements.
Run one real workflow with explicit ownership and consent.
Start with one programme, one cohort or one credential route. Merentra will define the minimum authority and deployment evidence needed for a controlled pilot.
New accounts open only while evidence, capacity and support are current.
Merentra now uses one server-enforced gate for free registration, paid access and launch-stage promotion. Existing members keep access when the cohort is paused; new accounts reopen only after the live-acceptance run, named ownership and capacity controls allow it.