Signing in
Both the portal and the capture app open on the same sign-in screen shape: email and password, Google, Apple, or your organisation’s own single sign-on. This article covers every option and the two-factor challenge you may see partway through.
What it is
The portal offers email/password, Continue with Google, Continue with Apple, Company SSO, and — on a device that supports it — Sign in with a passkey. The capture app offers the same set except passkeys, which are portal-only today. Company SSO works by domain: enter your work email and the app looks up which identity provider your organisation has configured (Microsoft Entra ID, Google Workspace, or any SAML provider) and hands you to it automatically — you never choose a provider yourself. If manager, org-admin or owner-level two-factor authentication is enforced on your account, a six-digit code prompt appears immediately after any of these methods succeeds, before you reach the app.
How to do it
- On the sign-in screen, enter your work email and password and select Sign in — or choose Continue with Google / Continue with Apple if your account uses one of those.
- To use your organisation’s own identity provider, select Company SSO, enter your work email, and continue — the app resolves your organisation from the domain and redirects you.
- On the portal, if your device supports it, select Sign in with a passkey instead of typing a password, and complete your device’s biometric or hardware-key prompt.
- If a Two-factor authentication screen appears, enter the six-digit code from your authenticator app and select Verify & sign in.
- Forgotten your password? Select Forgot password?, enter your email, and follow the reset email — check spam if it doesn’t arrive.
How it integrates
Every sign-in method — password, Google, Apple, SSO, passkey — converges on the same account and the same organisation membership; which methods are available to you depends on what your organisation has configured (SSO needs a domain set up under Settings → SSO & provisioning) and what you’ve personally enrolled (a passkey needs adding first under Settings → My account). The two-factor prompt is a server-side requirement tied to your role, not a client setting — manager, org-admin and owner accounts are challenged regardless of which method got them this far. Once you’re signed in, your access claims — which organisations you belong to, and your role in each — travel with your session and are re-checked on every privileged action, never trusted from the client alone.
Common problems
- Company SSO says no single sign-on is configured for my domain. Your organisation hasn’t set one up yet — an admin can do this under Settings → SSO & provisioning, or you can sign in with email/password or Google/Apple instead if your account has one of those set up.
- I don’t see a passkey option. Passkey sign-in is available on the portal only, and only once you’ve added one under Settings → My account — see Sessions, passwords and 2FA.
- My authenticator code is rejected even though it’s current. Sign out and back in — a stale session can carry an out-of-date second-factor claim even though your enrolment is fine server-side.