Inviting customers

Create portal accounts, send invitations, handle lost authenticators.

Accounts

Portal accounts live separately from analyst accounts and are locked to exactly one organization for life. Create them in Settings › Organizations › the organization › Portal users.

Invitation

  • Add the customer's email. The console produces a one-time activation link valid for seven days; the token is stored hashed.
  • Send the link to the customer through a channel you trust.
  • The customer opens the link, sets a password of at least twelve characters, and must enrol an authenticator app before the account activates.

Sign-in

Password plus authenticator code, rate-limited per address and per account. Sessions last eight hours.

Lost authenticator or password

Re-invite the account from the console. Re-invitation resets both the password and the authenticator enrolment and produces a new activation link. Every reset goes through you, so account recovery is always deliberate.

Removing access

Disable the account. Every sign-in, activation and ticket action is in the audit trail.