v0.48.1
July 12, 2026
Federated identity (Phase 2) — cross-install: an external consultant or collaborator can now operate across *different* FlowSharp installations (companies with separate systems, not just tenants of the same installation) with a single sign-in. The hosting company invites by email; the invitee accepts from a dedicated page and can then switch between their own workspace and the hosting one with one click. Revocation always stays with the hosting company: the moment it is revoked, the external session drops immediately, even if already open.
-
Feature
Cross-install federated identity (Phase 2)
**One sign-in, multiple companies, even on different systems.** Beyond switching between tenants of the same installation (Phase 1), you can now invite a person who works on a completely different FlowSharp installation (another domain, another database). The invite arrives by email with an acceptance link; once accepted, the new workspace appears in the invited user's selector and they enter it with one click, without a second password. **Revocation always stays host-side.** The inviting company remains in control of access at all times — revoking it immediately interrupts the external session, even if the person is already operating on the hosting tenant. **Authenticated cross-install exchange.** The link between the two installations happens through a digital signature verified at every step, with one-time, short-lived access codes — no shared credentials between the two companies.
-
Improvement
External-user management (Phase 1 follow-ups)
**"External" badge in the user list:** anyone with federated access is now recognisable at a glance in the users list. **Row-by-row revocation:** each external access can be revoked individually, without having to act elsewhere. **More robustness on edge cases:** extra protections to avoid a tenant being left without any active Admin, and to keep the displayed name of whoever accepted an invite always up to date.