Choose how people sign in
Decide which email addresses can sign in to Flowstate and how long people stay signed in. This page also explains what people see when they sign in, so you can help them when something goes wrong. First time setting up? Start with Sign-in and access.
You need to be a Flowstate admin.
What people see when they sign in
- They enter their work email at platform.flowstate.inc, or select Login with Google or Login with Microsoft.
- If their email domain uses single sign-on, they see “Redirecting to …” and sign in with your identity provider.
- If they have a passkey, they can use it and they’re signed in. Otherwise, Flowstate emails them a six-digit code. The code expires in 10 minutes.
- After the code, or Google or Microsoft, they confirm it’s them with a second factor:
- The first time, they choose Passkey (recommended), such as Face ID, Touch ID, Windows Hello or a security key, or Authenticator app, such as Google Authenticator or 1Password.
- After that, people with an authenticator app enter its 6-digit code. People who chose a passkey sign in with the passkey instead of an email code.
People add and remove their own passkeys and authenticator apps in the Security section of their profile. They always keep at least one.
Limit sign-in to your email domains
- Go to Organisation → Sign-in & security → Authentication. If your organisation doesn’t use Organisation yet, go to Settings → Organisation → Authentication.
- Under Allowed Email Domains, type a domain into Add domain and select Add.
- Repeat for each domain.
To remove a domain, select the cross on it.
Good to know:
- No domains means any domain. The page says “No domain restrictions. All email domains are currently allowed.”
- Subdomains are included. Adding
company.comalso allowsuk.company.com. - Invited people can sign in the first time even if their domain isn’t listed. After that, their domain must be on the list.
- Single sign-on domains must be listed too, if you’ve added any domains.
Set how long people stay signed in
- Go to Organisation → Sign-in & security → Authentication.
- Under Session Duration, choose 1 hour, 8 hours, 1 day, 7 days, 14 days, 30 days or 90 days. It’s 7 days unless you change it.
The change saves as soon as you choose, and applies from each person’s next sign-in. It covers every way of signing in. Using Flowstate doesn’t extend it, and people are also signed out after a period of inactivity.
Decide whether people need an invitation
Organisation → People & roles → User enrolment decides whether people who haven’t been invited get an account the first time they sign in, and which role they get. If your organisation doesn’t use Organisation yet, that’s Settings → Organisation → User Enrollment. See Invite people and manage their access.
Send people to your identity provider
Organisation → Sign-in & security → Single sign-on sends everyone on a provider’s Email Domains to your identity provider. If your organisation doesn’t use Organisation yet, that’s Settings → Organisation → Single Sign On. Each domain belongs to one provider. Set-up guides: Set up SAML single sign-on and Set up OAuth single sign-on.
- To switch a provider off, turn off the switch on the provider’s row. People on its domains sign in with an email code again, as long as their domain is allowed under Allowed Email Domains. Turn the switch back on to send them to your identity provider again.
- To delete a provider, open its menu and select Delete Provider. See Switch off or delete a provider.
If something’s not right
“We could not complete that step. Check your details and try again.” Their code was wrong or more than 10 minutes old. Ask them to start again for a new code.
The sign-in page says to check email, but nothing arrives. Their domain isn’t under Allowed Email Domains. Add it, or invite them.
“You are not authorised to access this organisation.” Automatically enroll new users is off and they haven’t been invited. Invite them.
“Too many failed attempts. Please try again later.” They entered 5 wrong authenticator codes. They can try again after 15 minutes.
“This account uses a passkey to sign in. Please try again using your passkey, or contact support if you have lost access.” They asked for an email code but only have a passkey set up. They should sign in with their passkey. If they’ve lost it, select Reset MFA on their row. See Reset someone’s second factor.
Someone has lost their phone or passkey. See Reset someone’s second factor.