Signing In

Everything between opening the address of your application and seeing your first screen: the sign-in card and its three panels, the alternatives to a password, two-factor codes, invitations, forgotten passwords, and the handful of screens that appear when something is wrong on the other end.

What This Is

Your application lives at a web address your organization was given. Opening it while you are not signed in shows the sign-in screen: your organization's logo, a card with the sign-in form, and — depending on how your application is set up — buttons for signing in with a Google or Microsoft account.

Two things are worth knowing before anything else:

  • Your account is created for you. Someone with administrator rights adds you as a user and sends you an invitation. The Google and Microsoft buttons on the sign-in screen only sign you in; they never create an account. Some applications offer self-service registration on a separate page, but many do not.
  • What you can do after signing in depends on your role. Two colleagues who sign in the same way can land on completely different screens. See Roles, Groups And Permissions.

The wording quoted throughout this chapter is the English wording. If your application runs in another language you will see the equivalent phrases in that language, in the same places.

The Sign-In Screen

Below the logo sits a single card containing three panels stacked on top of each other. Only one is open at a time — clicking a panel's heading opens it and closes the others.

PanelHeadingWhat it does
FirstLoginSign in with your e-mail address and password
SecondMagic link loginHave a one-click sign-in link mailed to you
ThirdLost password?Ask for a link that lets you set a new password

All three panels are always there. They are not something an administrator switches on, and they cannot be hidden — even in an organization that expects everyone to sign in with a company Google or Microsoft account, the password panel and the two e-mail-based panels remain on the screen.

The Login Panel

This panel is open when the page loads. It contains, from top to bottom:

  1. A box for your e-mail address. It has no visible caption — the gray text inside it reads User identity (e-mail) until you start typing.
  2. A box for your password, showing the gray word Password until you start typing.
  3. A checkbox labeled Remember me.
  4. A full-width Login button.

Both boxes are required. If you submit with one empty, a red note appears under it (Enter user identity (e-mail) or Enter password) before anything is sent.

Signing in here reloads the whole page. If you arrived because you clicked a link into the application — a link to a specific record in an e-mail, say — you are taken to that page once you are in, rather than to the home screen.

About "Remember Me"

The checkbox controls how long your sign-in survives between visits, and it behaves less simply than the label suggests.

  • Ticked, your sign-in is set to expire roughly a week after your last visit.
  • Left unticked, no such expiry is set, and how long you stay signed in is governed by the application's own session lifetime — which is typically longer than a week.

Either way the clock restarts every time you use the application, so a person who signs in daily will not notice a difference. The practical advice: on a shared or public computer, leave the box unticked and use the sign-out control when you finish. Do not rely on the box to keep you signed in for a long absence.

The Social Sign-In Buttons

Inside the same card, below the three panels and only if your application offers it, a thin divider reads Or continue with, followed by one full-width button per available provider: Login with Google and/or Login with Microsoft. These are the only two providers that exist. Their labels stay in English even when the rest of the application is in another language.

Some applications show a small link under the card — by default labeled Register, though your administrator may replace both the wording and where it goes. If you do not see it, your application does not accept self-registration, and the only way to get an account is to be invited.

Signing In With Google Or Microsoft

If the buttons are there, this is usually the quickest route.

  1. Click Login with Google or Login with Microsoft.
  2. You leave your application briefly and land on the provider's own sign-in page. Sign in there as you normally would.
  3. You are returned to your application, signed in.

The Account Must Already Be Connected

Social sign-in matches you to an existing user account. It never creates one — and it does not match on your e-mail address. It recognizes the specific Google or Microsoft account that has been connected to a user record in your application. You make that connection yourself, from your profile page, while signed in with your password; connecting and disconnecting are covered in Your Profile And Account. Until a provider account is connected, the buttons have nothing to match you to.

If the account you signed in with at Google or Microsoft is not connected to anyone here, you come back to the sign-in screen and a small pop-up window opens by itself:

Account Not Found — We couldn’t match your Google account to any user here. Please check your login or contact us if this seems wrong.

The pop-up says "Google" whichever provider you actually used, so do not read anything into that word. The usual causes are that you never connected an account, that your browser is signed in to a different provider account than the one you connected (a personal Google account rather than the work one is the classic case), or that you have never been added as a user at all.

You may also see a pop-up titled Login Error. That means the sign-in attempt lost its thread somewhere between the two sites — try once more, and tell your administrator if it keeps happening.

Example — Jana is added to the projects application as jana.novakova@stavbyplus.cz and signs in with that address and a password. On her second day she tries the Google button instead. Her browser is signed in to Google as her private jana.n@gmail.com, which she has never connected here, so Google takes her away and back in three seconds and she lands on the sign-in screen with "Account Not Found". The fix is not a different button: she signs in with her password once more, connects her work Google account from her profile page, and from then on the button works.

If You Have Two Accounts

If the provider account you used is connected to more than one user record — which happens when someone has, for instance, both a normal account and a limited one — you get an intermediate page listing the matching accounts by name and e-mail. Click the one you want to use.

The Magic link login panel lets you sign in without typing a password. It explains itself on screen: give your e-mail address, and if it matches an account, a message arrives with a button that signs you in when you click it.

  1. Open the Magic link login panel.
  2. Type your e-mail address and press the button.
  3. The panel is replaced by a green line: Please check your e-mail and follow instructions.
  4. Open the message titled Confirm login and press its Verify & complete button.

Three things to know:

  • The confirmation you see on screen is the same whether or not your address exists. It is deliberately uninformative, so it is not a sign that anything worked.
  • The link is short-lived — about three minutes. The e-mail does not say so. If you read mail on a phone that syncs every fifteen minutes, the link will usually be dead by the time you tap it.
  • An expired link says nothing. Clicking it just puts you back on the ordinary sign-in screen with no message at all. If that happens, request a fresh one or use your password.

If your role requires two-factor authentication, magic-link sign-in is not available to you. No e-mail is sent, and if you somehow follow an older link you are returned to the sign-in screen with:

Magic-link sign-in is not available for accounts with multi-factor authentication. Please sign in with your password.

This is deliberate: a link mailed to your inbox proves only that you can read your inbox, which would defeat the point of the second factor.

Two-Factor Authentication

Two-factor authentication asks for a second proof after your password — a short numeric code.

It is switched on by role, by an administrator. There is no setting in your profile that turns it on or off, and nothing you can do to opt out. It is entirely normal for it to apply to some colleagues and not others, because it follows roles rather than people. If several of your roles disagree, the strongest requirement wins.

There are two methods you may meet:

MethodShown asHow you get the code
A code by e-mailMail codeA message arrives with a six-digit code, valid ten minutes
An authenticator appAuthenticator appYour phone app generates a fresh six-digit code every 30 seconds

The Verification Screen

After your password is accepted you are sent to a page headed Two-factor authentication, with the line Complete the verification below to continue. underneath. You are not signed in yet.

The screen shows the method that applies to you, a short prompt, and one wide, centered box for the code with the gray word Enter code in it. The cursor is already in the box, and phone keyboards open in numeric mode. Press Submit.

  • If the code is wrong, the card refreshes in place with a red line: Provided code does not match. You can try again straight away.
  • If it is right, you are signed in and taken into the application.

Below the card is a Back to sign-in link, which abandons the attempt and returns you to the sign-in screen.

The One-Time Setup For An Authenticator App

The first time you sign in on a role that uses an authenticator app, the same screen also walks you through setup:

  1. A short instruction: Scan this QR code with an authenticator app (Google Authenticator, Authy, 1Password…), then enter the 6-digit code it shows to finish setup.
  2. A square QR code on a white plate.
  3. Underneath, Can't scan? Enter this key manually: followed by a string of letters and digits you can select and copy.

Open your authenticator app, add a new entry, and either scan the square or paste the key. The app immediately starts showing a six-digit code that changes every 30 seconds. Type the current code into the box and press Submit. From then on the QR code is gone and you are only ever asked for the current code.

Work briskly: the whole verification, setup included, is valid for ten minutes. If you take longer — hunting for the app in the store, say — the code you finally type is refused with "Provided code does not match", and you have to start the sign-in over. The manual key is the reliable route when you are scanning from the same device that shows the QR code and cannot point a camera at it.

The Honest Limitations

These are worth knowing before you rely on the feature:

  • There is no "trust this device." You are asked for a code on every sign-in, on every device, forever.
  • There are no recovery or backup codes. Nothing is printed for you to keep in a drawer.
  • There is no "resend code" button. If the e-mailed code does not arrive, the only option is to go back and sign in again, which sends a new one.
  • A lost or wiped phone needs an administrator. You cannot re-enroll a new authenticator app yourself; the old enrollment has to be cleared for you. Treat a phone replacement as something to arrange before you wipe the old device, not after.
  • Accounts with two-factor cannot use magic-link sign-in, as described above.

Being Invited: Your First Sign-In

You do not create your own account. An administrator adds you and then sends the invitation, at which point you get a message headed Activate your account with a Set a New Password button.

  1. Open the message and press the button (or copy the long address underneath it into your browser).
  2. You land on an activation page showing your organization's logo, your full name and a welcome line. The browser tab reads Activate user account.
  3. Fill in New password and Repeat password. The gray note under the first box states the password rules your organization uses — commonly a minimum of eight characters with at least one capital, one lowercase letter and one number, but your application may require something else.
  4. Press Submit.

You are signed in immediately and land on your profile page. From here on you sign in normally.

The invitation link is good for about a week, and the e-mail states the deadline in its own text. After that it is dead.

A stale invitation link behaves unhelpfully: instead of explaining itself, it signs you out (if you happened to be signed in) and drops you on the sign-in screen with no message. If a link seems to do nothing but return you to the sign-in card, assume it has expired and ask for a new one.

Your account holds exactly one of these one-time links at a time. Starting any new link-based flow quietly kills any earlier one. So:

  • Asking for a password reset cancels a pending invitation link.
  • Asking an administrator to re-send an invitation makes the first invitation e-mail useless.
  • Requesting a magic link cancels a pending reset link.

Always use the newest message in your inbox and delete the older ones, otherwise you will spend a frustrating ten minutes clicking a link that was superseded.

Example — Petr is invited on Monday and forgets. On Thursday he tries the link, it does not work, so he asks the office manager to resend it. Both e-mails now sit in his inbox with the same subject. He opens Monday's out of habit and is bounced back to the sign-in screen with no explanation. Only Thursday's link works.

Forgotten Password

You can reset your own password without asking anyone, as long as your account has been activated and has a password on it. (An invited colleague who never set a first password has nothing to reset; the on-screen note in the panel says as much.)

  1. On the sign-in screen, open the Lost password? panel.
  2. Type your e-mail address and press Continue.
  3. The panel is replaced by a green line: Your request has been submitted. You see this whether or not the address matched anything.
  4. Open the message titled Password reset and press Choose a new password.
  5. Fill in New password and Repeat password, then Submit.

Two useful facts about what happens next:

  • Following the link signs you in directly. You do not have to go back to the sign-in screen. A green confirmation appears and you land on your profile page — not on whatever you were trying to reach.
  • Your old password keeps working until you replace it. Requesting a reset does not lock you out, so it is safe to request one and then remember your password ten seconds later.
How the reset was startedRoughly how long the link works
You, from the Lost password? panelAbout a day
An administrator, using the reset action on your user recordAbout three days

Both e-mails print the exact deadline in their text. When an administrator starts the reset, your current session is ended and your account is marked as needing a new password. Your old password still gets you through the sign-in screen, but you land straight on the forced password-change page described below and cannot go further until you have set a new one — which is the point of that version.

If something goes wrong on the final step you get Password could not be changed. together with the reason: Chosen passwords do not match., Password does not comply with security rules. or User account not active.

Forced Password Change

Sometimes you sign in normally and land on a password-change page instead of your usual screen — the browser tab reads Password expired. It shows a two-panel card. The first, already open, is headed:

Your password has expired. Please change it.

and contains the password form. The second panel is the familiar Lost password? form, in case you cannot remember the current one.

You cannot get on with your work until this is done. Clicking a link into the rest of the application bounces you straight back here with the message Your password has expired. Please change your password. Set a new password, or sign out; there is no way to postpone it.

This is the normal result of an administrator running a password reset on your account, and it is also what a scheduled password-expiry policy looks like from your side.

Why Sign-In Fails

Every failed sign-in produces exactly the same message, as a colored strip above the card:

Login failed.

That single message covers all of it: a mistyped password, an address that is not a user here, an account that has been deleted, one whose validity dates have passed, and one that has not started yet. This is intentional — the screen must not become a way for a stranger to work out which addresses are real. The specific reason is recorded in the application's own log, which your administrator can look at.

Practical order of things to check:

  1. Is the e-mail address exactly the one your account was created with? Work versus personal addresses, and an old surname, are the two most common traps.
  2. Is Caps Lock on? Did your password manager fill in a password for a similar-looking site?
  3. Are you on the right address? Organizations often have a test copy of the same application at a near-identical web address, and your account may not exist in both.
  4. If none of that helps, use Lost password? rather than guessing further — which brings us to the lockout.

The Ten-Attempt Lockout

After ten failed attempts, the account is locked for ten minutes, and the message changes to:

Maximum login attempts limit exceeded. Please try again after 10 minutes.

The important part: during those ten minutes even the correct password is refused. The lock is checked before your password is looked at, so a person who finally remembers the right password on attempt eleven will conclude, wrongly, that it is also wrong. The counter clears on the first successful sign-in, or on its own once ten quiet minutes have passed.

So when you see that message, stop typing. Make a cup of coffee, or use the Lost password? panel — the reset e-mail is sent regardless of the lock, and following it signs you in without touching the password box at all.

The lock follows the account, not the computer, so switching to your phone or another browser will not shorten it.

Being Signed Out

Your Session Simply Ran Out

If you have been away long enough, your next click returns you to the sign-in screen with a strip reading:

Please sign in to continue.

Sign in again and you are delivered to the page you were trying to reach. There is no warning beforehand, no countdown, and no notice in another open tab — the first sign is the sign-in screen itself. If this catches you mid-form, see When Something Goes Wrong for what is and is not recoverable.

An Administrator Signed You Out Or Blocked Your Account

Administrators can sign a user out, and can block an account outright. The two look different from your side:

What was doneWhat you see on your next clickCan you sign back in?
Signed outYour login has expired. Please sign in again.Yes, straight away
Account blockedLogged in user does not exist.No — sign-in fails with Login failed.

The same Logged in user does not exist. message is what a deleted account, or one whose valid-until date has passed, looks like. All three are questions for an administrator.

Neither takes effect instantly. They mark your account, and the mark is noticed on your next request to the application. If you are reading a screen and not clicking anything, you may carry on looking at it for some time after the decision was made. Your very next click applies it.

Signing Yourself Out

The sign-out control lives in the menu behind your avatar at the top right — see The Application Window. There is no confirmation step and no goodbye message; you are simply returned to the sign-in screen. On a shared computer, use it rather than just closing the tab.

Screens That Mean "Not You, Us"

Three full-screen pages have nothing to do with your account. Recognizing them saves you from resetting a perfectly good password.

Scheduled Maintenance

A centered card on a softly animated colored background, showing your organization's logo, a small tools icon, and:

We are down for a short scheduled maintenance.

If whoever started the maintenance recorded an expected finish, a rounded pill underneath shows We expect to be back online on followed by a date and time, with the time zone printed below it. If there is no pill, no return time was given.

Nothing you do speeds this up, and no part of the application is reachable while it lasts. Wait, then reload the page.

App Is Not Active

A plain page reading App is not active, explaining that the application is temporarily suspended and that content and data are safe but access to its functions has been disabled.

This is a commercial or administrative state of the whole application, not of your account. Nobody can sign in while it lasts. It is a matter for whoever owns the application's contract.

App Not Found

A plain page reading App not found. Almost always a typo in the web address, or a bookmark pointing at an address the application no longer uses. Check the address against a colleague's bookmark before reporting anything.

Both of these last two pages carry the platform's own logo rather than your organization's, which is itself a useful clue: if the page does not look like your application, the problem is upstream of it.

"Login As": Someone Viewing The Application As You

Administrators with sufficient rights can open the application as another user, to see exactly what that person sees. This is the standard way to answer "why can't I see the invoice tab?"

If Someone Is Doing It To Your Account

You see nothing. Your own session is untouched — you are not signed out, nothing appears on your screen, and nothing changes about what you are doing. The other person is working in their own browser, with your view of the application.

Anything created or changed while someone is working as you is stamped with their name, not yours. A record edited during such a session shows the administrator as the person who changed it, so the history does not blame you for work you did not do.

If You Are The One Doing It

You start it from the user's record, using the action for logging in as that user. Afterwards, a strip confirms whose identity you are using, and you land on that person's home screen.

While you are in this mode, an extra entry appears in the menu behind your avatar:

Exit Login as (43 min.)

The number counts down the minutes left on your return ticket. Clicking the entry drops the borrowed identity and puts you back in your own. Two cautions:

  • When the countdown reaches zero the entry disappears. The borrowed session keeps working, but the one-click way back is gone — you then have to sign out and sign in again as yourself.
  • The countdown is about an hour. Do not treat "log in as" as a place to sit and work; use it to look at something specific, then come straight back.

Worked Example: A First Day With Two-Factor

Marta joins the accounts team on a Monday. Her role requires an authenticator app.

  1. 09:10 — Marta gets an e-mail headed Activate your account and presses Set a New Password. She lands on a page showing her name and a welcome line, sets a password twice, and presses Submit. She is signed in and looking at her profile page. So far no code was needed: the activation link itself proved she can read her inbox.
  2. 09:40 — She closes her laptop and goes to a meeting.
  3. 13:15 — She reopens the application. It shows the sign-in screen. She types her address and the password she chose, and presses Login.
  4. The page changes to one headed Two-factor authentication, with a QR code, an instruction to scan it, and a line of letters and digits underneath labeled Can't scan? Enter this key manually:.
  5. Marta installs an authenticator app on her phone, adds a new entry, and points the camera at the square. The app immediately shows a six-digit code with a shrinking timer next to it.
  6. She types the six digits into the wide box and presses Submit. She is in.
  7. Tuesday morning — She signs in again. This time there is no QR code, only the line Enter the 6-digit code from your authenticator app. and the box. She opens her phone, reads the current code, types it, and is through in about ten seconds.

Where this goes wrong, and how Marta avoids it: at step 5 she spends twelve minutes looking for the right app, and the code is refused with Provided code does not match. because the setup was only valid for ten minutes. She goes back to the sign-in screen, signs in with her password again, gets a fresh QR code, and this time — with the app already installed — finishes in twenty seconds.

When The E-Mail Never Arrives

Every route through this chapter except plain password sign-in depends on a message reaching you. When it does not, work down this list:

  1. Check your spam or junk folder, and any rule that files mail from unknown senders. The messages come from an address your organization configured, which your mail system may not know yet.
  2. Check the address on your account. You may be typing a work address while your user record holds an old or personal one. Only an administrator can tell you which address is on the account.
  3. Check whether you already used the link. These links are one-time; a link that worked once will not work again. If you already set a password, just sign in normally.
  4. Check whether a newer request canceled it. Only the most recent link is alive — see A New Request Invalidates The Old Link above.
  5. Consider timing. Magic links last only about three minutes; a slow mail server can outlive them. Invitations and resets last days, so with those the message is genuinely missing rather than stale.
  6. Wait a few minutes if several people were invited at once. When an administrator invites more than a handful of users in one go, the messages are queued rather than sent immediately, so yours may lag behind the confirmation your administrator saw.
  7. Ask your administrator to send it again — and then use only the newest message.

Tips And Gotchas

  • The confirmation lines are deliberately vague. "Please check your e-mail and follow instructions." and "Your request has been submitted." appear whether or not your address matched anything. Never treat them as proof that an e-mail is on its way.
  • Messages on the sign-in screen do not disappear by themselves. Unlike the little pop-up confirmations inside the application, the colored strips above the sign-in card stay until you navigate away, so you can read them at leisure.
  • A link into the application takes you where you were going. If you click a colleague's link to a specific record while signed out, you are asked to sign in first (Please sign in to continue.) and then delivered to that record rather than to the home screen.
  • Seeing "You do not have sufficient privileges to access this page." on the sign-in screen does not mean you were signed out for security reasons. It usually means the page you asked for is not available to your role. Sign in and use the navigation.
  • The verification code box behaves like a code box, not a password box: it is centered, spaced out, opens the numeric keypad on a phone, and accepts one-time codes offered by your phone's keyboard.
  • Your last sign-in time is stamped when your password is accepted, before any code is entered. A sign-in you abandoned at the verification step will still have moved the "last login" figure on your profile.
  • A password reset does not ask for a code, even on an account with two-factor. Setting the new password signs you in directly.
  • Bookmark the sign-in page, not a page inside the application. Deep bookmarks work, but they route you through the sign-in screen every time your session has lapsed, which reads like an error the first few times.

What To Ask Your Administrator For

Things you cannot do for yourself, phrased as requests you can paste into a message:

  • "Please check which e-mail address is on my user account — I am signing in with X and it is being refused."
  • "Please send me a new invitation link; the one from Monday has expired."
  • "Please reset my password" — use this when the self-service Lost password? panel produces no e-mail.
  • "I have replaced my phone and lost my authenticator app. Please clear my two-factor enrollment so I can set it up again." This one genuinely cannot be done by you.
  • "Please unblock my account" — when sign-in fails immediately and consistently with a password you are certain of, and the ten-minute lockout is not the cause.
  • "Is Google (or Microsoft) sign-in available for our application?" — the buttons only appear if it has been enabled.
  • "Why does my role require two-factor when my colleague's does not?" — it follows roles, and the answer will be about roles.

For your administrator — the configuration side of all of this (identity providers, per-role two-factor, password rules, account validity and expiry) lives in the implementer documentation rather than in this guide.