Sign-in security

Why people sign in without a password, how sign-in links are protected, how join links and leavers are handled, and how single sign-on fits in.

Part of every platformThis has no switch. Every organisation has it.

People sign in with their email address and a link sent to it, so they have no password to guess, reuse or write down. Access depends on having the mailbox the employee record points at.

Each link works once. If it has expired or been used, the person is asked to enter their email again and a fresh link is sent.

The link goes only to the email address on the employee record.

Opening the link shows a page with a button, and the sign-in completes only when the person presses it. Some email security systems open every link in a message to check it, and the button stops them from using up the link before the person gets to it.

A sign-in page that reveals nothing

The sign-in page shows the same message whatever email is typed, and the same reply comes back whether or not the address is known. Nobody can use it to work out who works where, or which companies use the platform.

After sign-in, the platform only ever sends a person on to a page inside the platform. A link that tries to bounce someone off to another website after sign-in is ignored.

Who gets in where

Every screen of the employee app needs a signed-in session. The only exceptions are the sign-in pages, join links and an organisation's standing support page.

The admin portal goes further. It opens only for people whose record gives them an admin or line manager role, and for Alltoogether's own staff, and sends everyone else back to the sign-in page.

Sign out in Settings ends the session on our servers as well as in the browser.

Leavers

Once a person's leaving date has passed, their record is marked as a leaver overnight. They cannot set up a new sign-in after that, and the admin portal will not send them an invitation. A leaving date entered in advance takes effect when the date arrives.

A join link lets people add themselves to an organisation's roster. It lasts 30 days, and an admin can generate a fresh one at any time. Opening it never adds anyone by itself; the person signs in with their work email, ticks to accept the terms and privacy notice, and presses Join.

The printable joining poster carries a QR code and a short web address, and no personal data. A fresh link is created each time the poster is opened.

Single sign-on

Switched on per organisationThis is built and working, and is switched on for each organisation on request. Ask your account manager, or reply to any email from us naming it.

Single sign-on through an organisation's own work accounts is set up per organisation, on request. Where it is set up, entering a work email sends the person to their organisation's sign-in page instead of emailing a link.

Questions

On this page