m4Mindset docs

Docs / AMS / Govern / Sign-in and SSO

View as Markdown

Sign-in and SSO

See how people sign in to Mindset, how new colleagues join your org by email domain, and what single sign-on isn't supported.

After this page, you know how your people sign in, how colleagues on your email domain can join your org without an invite, and what to tell your security team about single sign-on. The finance team who review the invoice exceptions agent's work sign in this way.

What this is

Each person signs in to one org at a time, at that org's own sign-in page. There are three ways in:

MethodHow it works
Email and passwordEnter your email, click Continue, enter your Password and click Sign in. A password needs at least 8 characters
Emailed sign-in linkOn the password step, click Email me a link. The link works once and expires after 1 hour
GoogleSign in with Google. It appears only when the deployment has Google sign-in set up. Otherwise the button isn't there

Only active members get a sign-in link. A session lasts until it has been idle for 7 days.

What isn't supported

  • No SAML or OIDC single sign-on. You can't connect Okta, Microsoft Entra ID or another identity provider.
  • No Microsoft sign-in.
  • No two-factor authentication inside Mindset.

If your policy requires SSO, Google sign-in is the only federated option, and only when it's set up for your deployment.

Invite people

Admins invite people in Settings → Members with Invite member. Enter the Email address, pick the Role (User or Admin) and click Send invite. The invite link works once and expires after 7 days. An invited person shows as Invited · locked until they accept.

There are two roles. Admins manage the org. Users get the end-user dashboard.

Let colleagues join by email domain

In Settings → Members, the Auto-group new sign-ins switch adds people automatically. It's off by default.

When it's on, a person who signs in with an email on the same domain as one of your active admins joins your org as a user. They're active straight away, never an admin.

  • There's no domain list to maintain and nothing to verify. The domain comes from your admins' own email addresses.
  • Free and disposable email domains never qualify.
  • If two orgs with auto-grouping on have admins on the same domain, nobody is grouped into either.
  • Someone an admin disabled is never added back.

Find an organization

A person who doesn't know their org's address can use Find my organization by email on Mindset's front door. Mindset emails them a link to the orgs they're a member of, valid for 15 minutes. Following it doesn't sign them in. They pick an org and sign in there.

A person can belong to several orgs. There's no switcher inside the app: they sign in to each org separately.

Listing your org in organization discovery isn't offered in Settings.

Reset a password

On the password step, click Reset password, then Send reset link. The link expires after 1 hour. An admin can also send someone a fresh single-use sign-in link with Reset access on their row in Settings → Members.

What can go wrong

  • "We couldn't sign you in." Mindset shows the same message for every failed sign-in. Check the org name and use the email the person was invited with.
  • The Google button is missing. Google sign-in isn't set up for this deployment. Use email and password or an emailed link.
  • Signed in, but no access to this organization. The account isn't a member. An admin invites them, or turns on Auto-group new sign-ins if they share an admin's domain.
  • A colleague on your domain wasn't grouped. Auto-grouping is off, their domain matches admins in more than one org, or an admin disabled them.
  • "Too many attempts." Sign-in is rate limited. Wait, then try again.