Skip to content

Organisation founding pilot

Coordinate programmes without taking ownership of the professional.

Merentra now supports controlled organisation tenants, seats, programme teams, cohorts, placements, purpose-limited consent, member-accepted credentials and auditable access. Joining an organisation never grants automatic access to a member-owned portfolio and does not reveal a member’s private workspace.

Controlled availability: the Organisation workspace is available for approved founding pilots with governed onboarding. It is not an unrestricted self-service organisation product.

Member-owned by defaultInvitation is not portfolio access.
Purpose-limited consentScope, reason and expiry are explicit.
Auditable organisation actionsEvery sensitive read or change leaves a receipt.
Separate service boundarySigned mirror and reconciliation before pilot promotion.
Organisation workspace

The tools a real programme needs—without WordPress Admin.

Role-specific screens keep the workflow focused on the organisation, programme and member relationship rather than exposing the underlying website administration.

01

People and seats

Invite members, allocate bounded seats, suspend access and keep the final active owner protected.

02

Programmes and cohorts

Structure programmes, cohorts and placements with clear dates, responsible teams and status.

03

Purpose-limited roles

Owners, administrators, programme leads, supervisors, reviewers and support roles receive only the actions needed for their purpose.

04

Consent centre

Request a defined summary or credential scope. Members can grant, decline or revoke directly from the App.

05

Credentials

Issue bounded claims with provenance, expiry and revocation. A credential remains pending until the member accepts it.

06

Audit and boundary health

Review sensitive actions, signed service health, mirror state and exact reconciliation before a pilot is promoted.

Ownership model

One relationship. Three clearly labelled data domains.

Merentra does not blur member information and organisation records into one invisible pool.

Member owned

The private professional workspace

Work, Record, Practice, Training, Opportunities, private notes, Mara drafts and individual feedback stay with the member.

  • No automatic organisation access
  • No raw evidence transfer by membership alone
  • Member export and erasure controls remain available
Shared by consent

A bounded summary for one purpose

A member may approve a defined view with a reason, scope and expiry.

  • Grant, decline and revoke controls
  • Every read creates an audit receipt
  • Individual feedback responses are excluded
Organisation owned

Programme administration and credentials

Seats, cohorts, placements, organisation roles and issued credentials form the organisation’s service record.

  • Retention follows contract and law
  • Member links can be revoked or pseudonymised
  • No hidden claim over the wider portfolio
Purpose-limited roles

Support staff should not inherit supervisor visibility.

Role boundaries are explicit and the final active owner cannot be removed accidentally.

Owner / administratorTenant profile, people, seats, programmes, consent administration, credentials, audit and data-boundary controls.
Programme leadProgramme, cohort, placement and approved review workflows without owner-level authority.
Supervisor / reviewerOnly the programme context and member-consented summary needed for the assigned purpose.
SupportInvitation and member administration without programme, consent-summary, credential, audit or data-boundary visibility.
Separate production boundary

Keep WordPress as the bridge—not the final organisation data authority.

Pass 23 includes an optional companion data-service package for a separate HTTPS service estate. It receives a deterministic, pseudonymous organisation snapshot rather than the member portfolio.

Merentra App

Member and pilot workspace

The App prepares a bounded organisation export and retains local data during pilot migration.

  • No raw WordPress user IDs
  • No invitation email addresses
  • No evidence or feedback responses
  • No provider credentials
Separate data service

Encrypted tenant snapshot

Signed requests use timestamp, nonce, content hash and HMAC. The service stores encrypted snapshots and exposes only a hash manifest for reconciliation.

  • Replay protection and bounded clock skew
  • Current and previous secret rotation
  • Key-continuity health check
  • Exact local/remote hash comparison

Promotion control: an organisation pilot remains blocked until signed health, storage, key continuity, an exact mirror, reconciliation and a tested restore are evidenced. Mirroring never requests local deletion.

Credentials

Issue a claim the member can accept—and anyone can verify safely.

Credential verification reveals bounded issuer claims and current status, not the member’s identity or private portfolio.

01

Consent

The member grants a credential-specific scope for the stated purpose.

02

Issue

The organisation creates a bounded claim with provenance and expiry.

03

Accept

The credential remains pending until the member accepts it.

04

Verify or revoke

A public verification route shows status; revocation requires a recorded reason.

Founding-pilot readiness

A guided route from interest to controlled use.

The Organisation workspace is real, but each pilot still needs named owners, a lawful purpose, configured roles, a separate service, restore evidence and support arrangements.

Discuss your pilot

1

Define the workflowUsers, purpose, official systems, success measures and boundaries.
2

Configure roles and seatsLeast-privilege owners, programme teams, supervisors and support.
3

Deploy the separate serviceStable encryption key, signed client secret and key-continuity evidence.
4

Mirror and reconcileExact deterministic snapshot hash with local data retained.
5

Test restore and incident responseRecovery evidence, named support and a controlled runbook.
Organisation founding pilot

Run one real workflow with explicit ownership and consent.

Start with one programme, one cohort or one credential route. Merentra will define the minimum authority and deployment evidence needed for a controlled pilot.

Live acceptance · founding cohort

New accounts open only while evidence, capacity and support are current.

Merentra now uses one server-enforced gate for free registration, paid access and launch-stage promotion. Existing members keep access when the cohort is paused; new accounts reopen only after the live-acceptance run, named ownership and capacity controls allow it.

New Merentra accounts are pausedMerentra is not currently accepting new public accounts. Existing members can continue to sign in.

Share with