Sign-in and security
How members sign in to OpenAleph (email and password, Google, Microsoft), password rules, invitations, several workspaces, and what admins control.
This page explains how members sign in to OpenAleph and what admins can and cannot control about access.
Sign-in methods
On the sign-in page (Log in, "Continue to OpenAleph"), a member can:
| Method | How it works |
|---|---|
| Continue with email | Enter the email address, then the password. |
| Continue with Google | Sign in with a Google account whose email matches their OpenAleph email. |
| Continue with Microsoft | Sign in with a Microsoft (Entra ID / Microsoft 365) account whose email matches their OpenAleph email. |
Google and Microsoft sign-in work without any configuration on your side: they are available to every company, as long as the email of the Google or Microsoft account is exactly the email of the member in OpenAleph.
Note: Company-specific SSO configurations (SAML, custom identity providers) and two-factor authentication are not available. If your company requires them, contact your OpenAleph account manager.
First sign-in and passwords
- The member enters their email and clicks Continue with email.
- If they don't have a password yet, OpenAleph generates one and emails it to them ("Your OpenAleph password"); the screen shows Check your mail 📩. Each Send it again generates a new password.
- Next time, they see Welcome back and enter their password. Forgot? sends a Reset your password email whose link leads to the Create password screen.
Password rules:
- at least 8 characters ("Password must contain at least 8 characters");
- only the link of the most recent reset email works;
- requesting a reset (Forgot?) or a first-login password logs the member out of all their sessions, web and mobile.
Members can change their password from their profile Settings (Change password). Admins can't set a member's password: a change made from another member's profile is not applied. The member-side flow is described in Log in to OpenAleph.
Invitations
Admins invite members from People › Members (invitation email when a member is created or imported, or Send / Resend invitation email). See Add and invite members. A member doesn't need the invitation to log in: entering their email on the login page is enough to receive a first password.
Several workspaces
A person who belongs to several OpenAleph workspaces (for example an external learner in another company's academy) chooses where to go after signing in ("Where would you like to go?").
Who cannot sign in
| Situation | Message shown |
|---|---|
| The email is not known in OpenAleph, or the member is deactivated (email and password sign-in) | The Oops, it seems this email is not registered 🧐 screen |
| The email of the Google or Microsoft account is not known in OpenAleph | "Email not found. Please check and try again." |
| The member is deactivated or not attached to a company (Google or Microsoft sign-in) | "Your account is not active or is not associated with a company." |
Deactivating a member immediately signs them out of every session (web and mobile). See Member data and privacy.
Logging in as another user
Company admins cannot log in as another member. To see what someone sees, check their access level (Access levels) and, for scoped admins, their Preview members tab. If you need help investigating a member's issue, contact OpenAleph support through Help & Support.
Good security practices for admins
- Keep the number of Admin accounts small; use Scoped admin for people who only need part of the company.
- Deactivate leavers on their last day (or make sure your HRIS sends them as inactive).
- Store API keys in a secret manager, give each integration its own key and delete unused keys (API keys and public API).
- Treat exports as confidential documents (Exports and reports).
Common questions
"Continue with Google" says my email is not found.
The Google account's email must be exactly the email of your OpenAleph profile. Sign in with that account, or ask an admin to check your email in People › Members.
I never received the password email.
Check your spam folder, then ask an admin to resend your invitation. If your company uses Google or Microsoft accounts, you can also use Continue with Google or Continue with Microsoft without a password.
Can we force everyone to use Microsoft sign-in?
No. Email and password sign-in remains available to every member.
Still stuck?
Our team answers every question. Tell us what you are trying to do and we'll walk you through it. Contact support