Appearance
Signing in safely
Ways in
- Email and password.
- Google or Microsoft, if you would rather not have another password.
An account that signed up with Google has no password, and that is fine — SimpliWork asks it for the right thing everywhere it asks for anything.
Two-factor authentication
Profile → Security → Set up authenticator. Scan the QR code with any authenticator app — Google Authenticator, Microsoft Authenticator, 1Password, Authy.
You are shown recovery codes once, when you finish. Save them somewhere that is not your phone. They are the way back in when the phone is lost, and they cannot be shown again.
Setting it up twice
If your account already has an authenticator, SimpliWork refuses to hand out a fresh secret — that would silently replace the one your phone actually uses and lock you out at the next sign-in. Turn it off first.
Making it compulsory
Settings → Security → Require two-factor. Everybody in the workspace is walked through enrolment the next time they sign in.
Worth doing. These accounts hold your clients' addresses and your business's money.
Being asked to confirm again
Some actions ask you to prove it is still you, even though you are already signed in:
- Changing roles or permissions
- Inviting, removing or re-assigning people
- Turning off two-factor
- Creating an API key (see below)
- Saving or removing an Encircle token
- Assigning seats
These are the actions that hand over access. Confirming lasts about ten minutes, so a run of admin work asks once rather than each time.
What you are asked for depends on the account: a password, an authenticator code, or a one-time code emailed to you — for an account that signed in with Google and has no password to re-enter.
Sessions
Signing somebody out of the workspace ends their session immediately. Somebody who was signed in when you removed them does not stay in until their browser next asks.
A password reset link is good for 15 minutes.
Working in more than one workspace
One login, however many companies you work for. Switch between them from the workspace menu; you never see one company's data from inside another.
Your password, your authenticator and your recovery codes belong to you rather than to any workspace. Being removed from one company does not touch your account.
API keys
Settings → API keys. Only relevant if you are having somebody build software that talks to SimpliWork directly — a key lets their program sign in as your workspace without a person typing a password. If that is not something you are doing, ignore this section.
- Shown once. Copy it then.
- Expire after a year unless you ask for shorter. A credential nobody ever has to think about again is one nobody ever revokes.
- Cannot do the account-changing actions above. A key that lives in a config file cannot re-prove a password, so it is refused outright rather than by accident.
If you are locked out
Forgot password on the sign-in screen.
Lost your phone, with two-factor on: use a recovery code. This is what they are for, and it is why they are worth saving somewhere other than the phone.
Out of recovery codes as well — get in touch. Nobody in your own workspace can turn two-factor off for somebody else, which is the point of it.
Next
When something goes wrong — the refusals people actually hit, and what each one means.