Browse guides

Operate

Account and notifications

Email-change verification and per-user scan notifications, including a cross-repository daily digest.

Guide type: Implementation reference

In this guide

Change your email

An account with an enrolled authenticator uses recent authenticator verification instead of a current-password prompt. An account without an authenticator must prove its current password. Removing a password field does not remove identity verification, and an identity-provider error must not bypass the authenticator check.

The new address receives a single-use confirmation link valid for thirty minutes. The address does not change until that mailbox is verified. Successful confirmation ends existing browser and CLI sign-ins; sign in again with the new address. The old address receives a change notification. Already-issued disconnected grants remain subject to their signed limits.

Choose how often scans send email

Choose how often scans send email
ModeWhen email is sent
Every scanEach completed uploaded scan eligible for notification.
New findingsWhen an uploaded run introduces findings at or above your chosen minimum severity: critical, high, medium or low.
Daily digestOne digest per user and organisation for the daily window, combining activity across that organisation's repositories rather than one email per repository.
OffNo per-scan or daily scan notification email from this preference.

The default is new high or critical findings. During migration, legacy scan-email preferences move to this quieter default except explicit opt-outs, which stay off. This includes previously enabled every-scan notifications; select Every scan again if that is your preference.

Current delivery scope: immediate Every scan and New findings emails are eligible for organisation Super Admins and admins and the scan uploader, subject to their preferences. Selecting one of those modes as another member does not subscribe you to every repository's immediate alerts. Daily digest is available to any current organisation member.

Notification settings belong to the signed-in user within the selected organisation. A multi-organisation user can receive a separate digest for each organisation. Organisation report schedules are separate from the scan mode and are part of Business and Enterprise; a member's own daily digest is available on every plan. Local scans without --upload do not create dashboard scan emails.

Delivery and account access

Delivery requires configured mail and background workers. A queued notification is not proof that a mailbox received it. Digests carry repository activity counts and console links; access is checked again before sending. Security emails and invitations are not disabled by selecting Off for scan notifications.

SSO is enabled by organisation policy and your identity-provider setup. CLI access additionally requires the SuperUser product role and CLI permission. Internal administration is separate from customer organisation roles; being an organisation's Super Admin does not grant internal access.

Single sign-on and SCIM

  • Super Admins and admins add and verify email domains. Only a Super Admin connects or replaces the SAML identity provider and changes the sign-in policy, after confirming their identity again.
  • App tile: put the app tile sign-in URL from Settings, Single sign-on into your identity provider's portal. Opening the tile shows a Continue page on MAGDOX; the sign-in starts when the person chooses Continue.
  • SCIM 2.0: the base URL is https://console.magdox.io/scim/v2. A Super Admin creates the SCIM token under Settings, Single sign-on; it is shown once, so store it in your identity provider, and revoke it from the same page. A token stops working if the person who created it is no longer the Super Admin.
  • Provisioning a person sends an invitation on one of your verified domains. Deactivating or deleting a person removes their membership, ends their sessions and tokens for your organisation and removes their link to your identity provider. SCIM never changes the Super Admin.