Appearance
Choose how people sign in
Decide which email addresses can sign in to Flowstate and how long people stay signed in. This page also explains what people see when they sign in, so you can help them when something goes wrong. First time setting up? Start with Sign-in and access.
You need to be a Flowstate admin.
What people see when they sign in
- They enter their email address on the sign-in page.
- If their email domain uses single sign-on, they see "Redirecting to …" and sign in with your identity provider.
- Otherwise, Flowstate emails them a sign-in link. The link expires after 15 minutes.
- After following the link, they confirm it's them with a second factor:
- The first time, they choose Passkey (recommended), such as Face ID, Touch ID, Windows Hello or a security key, or Authenticator app, such as Google Authenticator or 1Password.
- After that, people with an authenticator app enter its 6-digit code. People who chose a passkey sign in with the passkey instead of an emailed link.
People add and remove their own passkeys and authenticator apps in the Security section of their profile. They always keep at least one.
Limit sign-in to your email domains
- Go to Settings → Organisation → Authentication.
- Under Allowed Email Domains, type a domain into Add domain and select Add.
- Repeat for each domain.
To remove a domain, select the cross on it.
Good to know:
- No domains means any domain. The page says "No domain restrictions. All email domains are currently allowed."
- Subdomains are included. Adding
company.comalso allowsuk.company.com. - Invited people can sign in the first time even if their domain isn't listed. After that, their domain must be on the list.
- Single sign-on domains must be listed too, if you've added any domains.
Set how long people stay signed in
- Go to Settings → Organisation → Authentication.
- Under Session Duration, choose 1 hour, 8 hours, 1 day, 7 days, 14 days, 30 days or 90 days. It's 7 days unless you change it.
The change saves as soon as you choose, and applies from each person's next sign-in. It covers every way of signing in. Using Flowstate doesn't extend it, and people are also signed out after a period of inactivity.
Decide whether people need an invitation
Settings → Organisation → User Enrollment decides whether people who haven't been invited get an account the first time they sign in, and which role they get. See Invite people and manage their access.
Send people to your identity provider
Settings → Organisation → Single Sign On sends everyone on a provider's Email Domains to your identity provider. Each domain belongs to one provider. Set-up guides: Set up SAML single sign-on and Set up OAuth single sign-on.
- To switch a provider off, turn off the switch on the provider's row. People on its domains get emailed sign-in links again, as long as their domain is allowed under Allowed Email Domains. Turn the switch back on to send them to your identity provider again.
- To delete a provider, open its menu and select Delete Provider. See Switch off or delete a provider.
If something's not right
"This login link is invalid or has expired. Please request a new one." The link is more than 15 minutes old, or an email security tool changed it. Ask them to request a new one.
The sign-in page says to check email, but nothing arrives. Their domain isn't under Allowed Email Domains. Add it, or invite them.
"You are not authorised to access this organisation." Automatically enroll new users is off and they haven't been invited. Invite them.
"Too many failed attempts. Please try again later." They entered 5 wrong authenticator codes. They can try again after 15 minutes.
"This account uses a passkey to sign in. Please try again using your passkey, or contact support if you have lost access." They followed an emailed link but only have a passkey set up. They should sign in with their passkey. If they've lost it, select Reset MFA on their row. See Reset someone's second factor.
Someone has lost their phone or passkey. See Reset someone's second factor.