Demonstration system - every donor, donation and person here is invented. This is not real donor data.

Help & guides

Find your next step, understand a result, or learn how the workspace works.

Back to sign-in

Sign-in help is available here before authentication. Sign in to see the workflow guides for your role.

עברית
Skip to instructions

Sign in & access

Start with your own invitation and email address. Never share your password or verification code.

Your first sign-in

  1. Receive an invitation
  2. Choose a password
  3. Enter the MFA code
  4. Open the workspace

For later visits, use your email and password. A remembered browser may skip the code step; signing out removes that trust.

Accept your invitation

An administrator invites you by email. The invitation is for that email address, works once, and expires after seven days. An expired or replaced link needs a new invitation from the administrator.

  1. Open the invitation link in your email.
  2. Choose a password of at least 12 characters and enter it again to confirm.
  3. Enter the verification code sent to your email. You can then open the workspace.

Sign in and enter your code

MFA means multi-factor authentication: the code provides a second check after your password. It helps protect your account even if someone learns your password.

Use the email address you were invited with and the password you chose. There are no shared team credentials. Google or Microsoft sign-in is available only when its button is enabled for this installation.

  1. Open Sign in, enter your email and password, and continue.
  2. Open the newest verification email. Enter the six-digit code; an email code expires after 10 minutes and can be used only once. An authenticator code also works if an authenticator was already set up for your account.
  3. On your own device, you may choose to trust this browser for 30 days. Leave this unchecked on a shared device. Signing out explicitly cancels that browser’s trust.

Set up an authenticator app

An authenticator app on your phone gives a sign-in code that does not depend on your mailbox. It is offered only where the system has it turned on; the emailed code keeps working either way.

Setting it up gives you ten recovery codes, shown once. Each one signs you in once if the phone is lost. Keep them away from the phone. Every change to your authenticator is emailed to you and recorded in the audit trail.

  1. Open Sign-in security with the link below, or from your name at the top of the page on a larger screen.
  2. Confirm it is you with a new code, then start setting up.
  3. Scan the square with the app or type the key, then enter the six-digit code it shows.
  4. Save the recovery codes somewhere safe before leaving the page.

Sign in when your phone is lost

Setting up an authenticator app gives you ten recovery codes. They are shown once, on the screen where you set the app up, and never again. Each code signs you in one time and is then spent.

On the code screen, choose the option to use a recovery code instead of a six-digit code and type one in. Signing in with a recovery code never marks the browser as trusted, because the system cannot tell whether the browser is still yours.

The emailed code also keeps working, so a lost phone never locks you out as long as you can read your mailbox. The Sign-in security screen says how many recovery codes are left, and you can issue ten new ones there - issuing new ones cancels the old ones.

If you have neither the phone nor the codes, an administrator resets your second factor. That signs you out everywhere and returns your next sign-in to the emailed code. It does not change your password.

Why a new authenticator app waits before it can approve an export

On a system set up to require it, taking a copy of the data out asks for a fresh code from your authenticator app, and that code opens one download only, for five minutes. A recovery code is not accepted for this: recovery codes are for getting back in, not for taking the donor file out.

An authenticator app set up in the last 72 hours cannot approve an export yet. The screen says so and tells you roughly how many hours are left. Moving to a new phone starts the 72 hours again.

The reason is simple. Somebody who had your password and your mailbox could set up an authenticator app of their own and take the whole donor file the same minute. The three days give the real owner time to see the email about a set-up they did not make and ask an administrator to reset it. There is no way to shorten the wait.

The code is missing or does not work

Check spam and confirm you are reading the inbox for your sign-in address. Use the newest code from the sign-in session you are completing, without spaces. A code lasts ten minutes. After five unsuccessful attempts, you must sign in again.

The code screen has a Send a new code button. It waits about a minute between codes and allows at most five codes in a quarter of an hour, so if the button reads Send a new code in a number of seconds, wait for it. A new code cancels every earlier one, so always use the last message that arrived.

If you set up an authenticator app, its six digits work on the same screen and do not depend on email at all. If no email arrives after a few tries, contact your administrator.

Forgotten password or lost access

Choose Forgot your password? on the sign-in page and enter your account email. The confirmation is the same for every address to protect account privacy. Google or Microsoft passwords are recovered with that provider.

A reset link lasts 30 minutes and works once. Choose a new password of 12–256 characters and confirm it. You will then sign in again and complete MFA. Resetting a password signs out all sessions and remembered browsers, but keeps enrolled authenticators. Requesting a link alone changes nothing. Never share a reset link.

If no message arrives, check spam and wait a few minutes. Requests are limited to protect your inbox. An expired or used link requires a new request. If you no longer control your email, contact your administrator; do not use someone else’s account. A password-change notification is sent after a successful reset.

If an authenticator or trusted device is the problem, the administrator can reset your second factor. This signs you out everywhere and returns the next sign-in to email verification; it does not change your password. A deactivated account must be reactivated by an administrator.

Journey 4Hope