Signing in
The sign-in page is the first thing you see of roleALPHA — including when your session has expired and you unexpectedly end up there again.
Set language and theme before you sign in
Section titled “Set language and theme before you sign in”Two controls sit in the top right corner:
- DE / EN switches the interface language.
- Moon / sun switches between the light and dark theme.
Both take effect immediately and are remembered on this device. You do not have to sign in first to see the interface in your language.
With a passkey (the fastest route)
Section titled “With a passkey (the fastest route)”If you have set up a passkey on this device, you do not have to type anything at all.
The normal case: click into the address field. Your browser offers the matching passkey on its own. A fingerprint, a look at the camera or your device PIN — and you are signed in.
If the suggestion does not appear, choose Sign in with a passkey. You need that button for a security key you have to plug in first, for example, or when you dismissed the suggestion a moment ago.
The button only appears if your device supports passkeys at all. If it is missing, there is nothing wrong with your account — use the email code.
No email address is asked for. The passkey itself tells us who you are. If you belong to several tenants, you then pick once which one you want.
Nothing else is asked after the passkey. Your device already checked you before it signed — possession and confirmation are both established. Additionally demanding an authenticator app would not add security, only another opportunity to lock yourself out.
If it does not work, we do not tell you why — whether a passkey was missing or something else went wrong. That is deliberate: otherwise one could read off who has an account here. The email code route is open to you in any case.
With a code by e-mail (the regular route)
Section titled “With a code by e-mail (the regular route)”Enter your work e-mail address and choose Continue. Within seconds you receive a mail with a six-digit code; type it into the window that is already open. The code is valid for ten minutes and can be used once.
- Where did the code go? The page shows the address masked, so you can check.
- Prefer to click? The same mail also contains a sign-in link. It leads to a page with a button — only your click signs you in. That is deliberate: security scanners in mail systems open links automatically, and a link that signs you in on mere opening would be spent before you ever saw it.
- Nothing arrived? Look in your spam folder. After a minute you can choose Send again; the previous code then stops working.
- Mistyped? You have five attempts. After that, request a new code.
- More than one organisation? If your address belongs to several, the page asks after the code where you would like to go.
For security the answer always looks the same — even when no account exists for an address. That way nobody can find out from the outside who has an account here.
No more passwords
Section titled “No more passwords”Since October 2026 you no longer sign in to roleALPHA with a password — not even if your account used to have one. Your ways in are the passkey, the code or sign-in link by email and your organisation’s account (single sign-on). The sign-in page no longer has a “use password” link.
Only the platform’s own administrators still have a password (together with an authenticator app) — and they sign in to the separate Platform Admin, not here.
With your organisation’s account (single sign-on)
Section titled “With your organisation’s account (single sign-on)”If your organisation uses an identity provider — Microsoft Entra ID or Google Workspace, for example — a button with its name appears below the form. One click is enough; you need neither a code nor a passkey.
The button only appears when the sign-in page knows which organisation you belong to. That is the case when you arrived through your company’s address or an invitation link. See Single Sign-On (SSO) for details.
With your Google or Microsoft account
Section titled “With your Google or Microsoft account”Below the form you find Sign in with Microsoft and Sign in with Google, if your organisation allows it. If you are already signed in with the provider, one click is enough.
- The first time, roleALPHA checks whether the e-mail address confirmed by the provider matches your sign-in address. If so, your account is linked. This never creates a new access — without an existing one you get a message that there is no access for this account.
- Microsoft: work or school accounts only, no personal accounts (outlook.com, hotmail.com).
- Google: with a company address only if your company manages the Google account itself (Google Workspace). A privately created Google account with a company address is not enough.
- After that, roleALPHA recognises you by your account at the provider, no longer by the address. You can see which accounts are linked in your profile under Linked sign-ins, and unlink them there.
- If you belong to several tenants, the selection follows as with the code. If your tenant requires a second factor, roleALPHA then asks for the authenticator app.
If your organisation uses its own single sign-on, this route is blocked for it — then the section above applies.
Two-factor confirmation
Section titled “Two-factor confirmation”If your organisation requires an additional second factor after single sign-on (see Sign-in methods) and you have set up an authenticator app, sign-in then asks for the six-digit code. Instead of the code you can enter one of your recovery codes — each one works exactly once. See Two-Factor Authentication (MFA).
Access to several tenants
Section titled “Access to several tenants”If you work for several organisations in roleALPHA, you still have one account with one sign-in address. After signing in you choose the tenant and can switch later without signing in again. Your roles apply per tenant.
Sometimes switching asks you to sign in again. Each tenant decides which sign-in methods it allows. If you came in through another organisation’s account (single sign-on), or the target tenant has switched off the route you used, you sign in again for the target tenant, for example with a code or a passkey. With a passkey or an email code you switch without being asked, provided the target tenant allows that method.
One sign-in page for everyone
Section titled “One sign-in page for everyone”If roleALPHA has a shared sign-in page configured, opening your organisation’s address sends you there, and after signing in you are brought back automatically. You do not have to do anything for this.
The reason is the passkey: it is cryptographically bound to exactly one address. Without a shared sign-in page you would need a separate one for every address of your organisation.
You come back via a handover ticket that is valid for 60 seconds and works exactly once. If you land on a page saying the handover has expired, simply sign in again. Nothing has been lost.
Nothing changes for single sign-on. Signing in with your identity provider still runs via your organisation’s address — your IT does not have to add anything there.
When you can reach neither your device nor your mailbox
Section titled “When you can reach neither your device nor your mailbox”Then you need a recovery code — one from the set you were given and wrote down when you set up your first passkey or your authenticator app.
You find the way there on the screen that asks for the code from the email: No access to your device or mailbox?
There you enter your email address or your username — either works, since someone without a reachable mailbox can hardly identify themselves through an address — together with one of your codes.
Each code works exactly once. After signing in you should set up a new passkey straight away.
If you have run out of codes too, only your organisation’s administration can help: they can reset your sign-in methods. You will be notified about it.
When something does not work
Section titled “When something does not work”| What you see | What is behind it |
|---|---|
| “Your session has expired” | You were signed in and the session ran out. Simply sign in again. |
| “User account is deactivated” | Your access has been blocked. Contact your tenant’s administration. |
| “Too many sign-in attempts” | A protection against automated guessing. Wait a few minutes and try again. |
| “SSO sign-in failed” | The route through the identity provider did not work. Sign in by code or passkey if your tenant allows it, or contact your administration. |
| “That code is not right” | Mistyped. The page shows how many attempts are left. |
| “Signing in by e-mail is not set up” | This installation has no mail transport. Sign in with a passkey or single sign-on, or contact operations. |
| “Your organisation does not allow this sign-in method” | Your tenant has switched this route off. Use the other route offered. |
There is no forgotten password any more: if you used to have one, simply sign in by email code.
Related
Section titled “Related”- Two-Factor Authentication (MFA) — setting up an authenticator app
- Single Sign-On (SSO) — signing in through the identity provider
- First Steps — what comes after signing in