HGE ID
The HGE ID is the central identity in the Uslimato ecosystem. It hangs off an email address and opens access to one or more tenants — one sign-in, without a separate account per tenant.
#Email verification
Once an HGE ID is created, a verification email goes out. It has to be confirmed within 14 days.
- You can start straight away — the 14 days are a grace period, not a waiting period
- A banner shows how much time is left
- Once the period expires, access is blocked until the address is confirmed
- The email can be requested again at any time, at most three times per hour
To resend, click the link in the banner and then Resend verification email.
#One identity, several tenants
An HGE ID can be a member of any number of tenants. The tenant switcher in the header moves you between them. Permissions are granted per tenant — administering one tenant says nothing about your rights in another.
#What travels with you and what stays
Everything describing *you as a person* applies across all tenants. Everything describing *what you do in one particular tenant* stays there.
| Attribute | Scope |
|---|---|
| Name | Global — HGE ID is the leading source |
| Global, not editable in the app | |
| Profile picture | Global, with a picture stored in the tenant taking precedence |
| Theme (light/dark) | Global |
| Language | Global |
| Favourites and saved views | Per tenant |
| Dashboard layout | Per tenant |
| Permissions and groups | Per tenant |
| Read state of notifications | Per tenant |
Switching tenant therefore always shows the active tenant's data — only the personal shell follows you everywhere.
#Profile pictures
Uploaded profile pictures are re-encoded server-side into a uniform format. That is not a cosmetic step: re-encoding strips EXIF data and anything else that can ride along inside an image file. What remains is image information only — no capture coordinates, no embedded extras.
Globally stored profile pictures do not count against a tenant's storage quota.
#Identity badges
Profile and avatar menu can show two badges:
- **"Part of *tenant*"** — you are not currently working in the tenant that holds your HGE ID. Master tenant explains which one that is
- **"Managed by *tenant*"** — Domain Governance is active for your email domain, and the managing tenant enforces policies on your account
If both apply, both appear side by side.
#Security
- Passwords live solely with the HGE ID identity provider — Uslimato neither stores nor can read them
- Password changes and resets therefore always go through HGE ID, never through the Uslimato interface
- Sign-in attempts are logged
- Industry-standard encryption is used throughout