# Sign-in and SSO

> See how people sign in to Mindset, how new colleagues join your org by email domain, and what single sign-on isn't supported.

After this page, you know how your people sign in, how colleagues on your email domain can join your org without an invite, and what to tell your security team about single sign-on. The finance team who review the invoice exceptions agent's work sign in this way.

## What this is

Each person signs in to one org at a time, at that org's own sign-in page. There are three ways in:

| Method | How it works |
|---|---|
| **Email and password** | Enter your email, click **Continue**, enter your **Password** and click **Sign in**. A password needs at least 8 characters |
| **Emailed sign-in link** | On the password step, click **Email me a link**. The link works once and expires after 1 hour |
| **Google** | **Sign in with Google**. It appears only when the deployment has Google sign-in set up. Otherwise the button isn't there |

Only active members get a sign-in link. A session lasts until it has been idle for 7 days.

## What isn't supported

- **No SAML or OIDC single sign-on.** You can't connect Okta, Microsoft Entra ID or another identity provider.
- **No Microsoft sign-in.**
- **No two-factor authentication** inside Mindset.

If your policy requires SSO, Google sign-in is the only federated option, and only when it's set up for your deployment.

## Invite people

Admins invite people in **Settings → Members** with **Invite member**. Enter the **Email address**, pick the **Role** (**User** or **Admin**) and click **Send invite**. The invite link works once and expires after 7 days. An invited person shows as **Invited · locked** until they accept.

There are two roles. Admins manage the org. Users get the end-user dashboard.

## Let colleagues join by email domain

In **Settings → Members**, the **Auto-group new sign-ins** switch adds people automatically. It's off by default.

When it's on, a person who signs in with an email on the same domain as one of your active admins joins your org as a user. They're active straight away, never an admin.

- There's no domain list to maintain and nothing to verify. The domain comes from your admins' own email addresses.
- Free and disposable email domains never qualify.
- If two orgs with auto-grouping on have admins on the same domain, nobody is grouped into either.
- Someone an admin disabled is never added back.

## Find an organization

A person who doesn't know their org's address can use **Find my organization by email** on Mindset's front door. Mindset emails them a link to the orgs they're a member of, valid for 15 minutes. Following it doesn't sign them in. They pick an org and sign in there.

A person can belong to several orgs. There's no switcher inside the app: they sign in to each org separately.

Listing your org in organization discovery isn't offered in Settings.

## Reset a password

On the password step, click **Reset password**, then **Send reset link**. The link expires after 1 hour. An admin can also send someone a fresh single-use sign-in link with **Reset access** on their row in **Settings → Members**.

## What can go wrong

- **"We couldn't sign you in."** Mindset shows the same message for every failed sign-in. Check the org name and use the email the person was invited with.
- **The Google button is missing.** Google sign-in isn't set up for this deployment. Use email and password or an emailed link.
- **Signed in, but no access to this organization.** The account isn't a member. An admin invites them, or turns on **Auto-group new sign-ins** if they share an admin's domain.
- **A colleague on your domain wasn't grouped.** Auto-grouping is off, their domain matches admins in more than one org, or an admin disabled them.
- **"Too many attempts."** Sign-in is rate limited. Wait, then try again.
