Sign-in, SSO and two-step verification
The application answers at https://cranotify.eu. You sign in with an email and password or with your corporate Google or Microsoft identity; two-step verification is per user and is switched on from your own profile.
Signing in with a password
- Enter your email and password on the sign-in page.
- If two-step verification is on, the application asks for the six-digit code from your authenticator app.
- On confirmation the case cockpit opens.
Passwords must be at least 10 characters. They are stored only as a cryptographic digest: nobody, support included, can read one or tell you what it was.
Sign-in, password reset and sign-up attempts are rate-limited per source address. After too many attempts in quick succession the answer becomes «too many requests»: wait a few minutes — it is not an account lock. The sign-in page is also guarded by an invisible anti-bot check (Cloudflare Turnstile), which asks nothing of you when all is normal.
Forgotten password
«Forgot password» on the sign-in page sends a single-use reset link valid for 30 minutes. Once opened, you set the new password; a confirmation email follows. If that confirmation arrives and it was not you, change the password immediately and tell support: somebody has access to your mailbox.
Signing in with Google or Microsoft
When the providers are configured, the sign-in page shows «Continue with Google» and «Continue with Microsoft». There are two distinct paths, and it helps not to confuse them.
- Global social sign-in. You enter the existing account tied to that email address — which must be unique. The provider verifies the identity and you skip the password. If no active account exists for that email, sign-in is refused with «no active account»: social sign-in creates nothing. To found a new company, use sign-up.
- Company SSO (per organisation). Whoever arrives through their organisation's SSO address — the one carrying the organisation slug — is created on first sign-in by just-in-time (JIT) provisioning: the corporate identity's groups are mapped to the application's roles, so everyone lands with the right permissions without a manual invitation.
The allowed domains and the group→role mapping of company SSO must be set before the team signs in: they govern who joins and with which role. Global social sign-in, by contrast, founds no organisation — an unknown email is simply turned away.
Two-step verification (TOTP)
Switch it on from Account area › My account › Security. It is a per-user choice, not an organisation-wide one: everyone protects their own access.
- Press «Enable two-step verification». A text key and an
otpauth://address appear, to be captured with an authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, Aegis…). - Type the six-digit code the app shows, to confirm the capture worked.
- Save the recovery codes that appear at this point: they are shown once and only once.
The recovery codes are shown once. Keep them outside the application — a password manager, a company safe. Each code works once and is the only way back in if you lose the phone. Without codes and without the app, getting back in goes through support and takes verification that is not instant: exactly what you do not want during a 24-hour deadline.
Use the same panel to switch it off. The six-digit code changes every 30 seconds and is accepted with a small clock tolerance; if it is rejected over and over, the phone's time is off — synchronise it.
Active sessions
The same page lists the open sessions with device and location; the current one is marked. Each row can be revoked: revocation takes effect immediately and that device has to sign in again. Changing the password and disabling the account invalidate existing sessions.
Good practice. Review the sessions whenever somebody leaves the company or changes laptop. It takes a minute and is one of the easiest diligence facts to demonstrate.
Signing out and expiry
«Sign out» closes the current session and clears the cookie. Sessions have a limited lifetime anyway: after a period of inactivity you are asked to sign in again. The session cookie travels over HTTPS only in production and is not readable by scripts.