Sign in
Email + password, or Google / Microsoft SSO if your workspace allows it. SSO domains are configured by your workspace admin.
Multi-factor authentication
Each workspace has an MFA policy: off, optional, or required. When required, every user must set up TOTP on first sign-in. Configure your authenticator app from Settings → Security.
Inviting teammates
Admins invite from Settings → Team. Invitees get an email with a one-time link; the invite expires after 7 days. You can resend or revoke at any time.
Roles and module permissions
- Admin / Editor / Viewer at the workspace level.
- Per-user module permissions can narrow this — e.g. an editor with
projects: viewbutspecs: editonly.
Both are managed at Settings → Team.
Forgot password
Use the Forgot password link on the sign-in screen. The reset link is valid for 30 minutes. The AI agent can also trigger a reset for you on request.
Suspicious activity
The active sessions list at Settings → Security shows every device with a live session. Revoke any you don't recognise; this invalidates the JWT immediately.