Docs/Start Here

Accounts, Sign-In, and Security

Accounts, sign-in and security cover how Manifold users sign in, recover access, use social sign-in and keep data secure.

For: All users4 min read5 sections

Account Functions

Accounts, sign-in, and security in Manifold cover how each person proves who they are, recovers access after a forgotten password, and how the workspace enforces account security. Give every person their own account rather than sharing a login, so sign-in, approvals, and audit history stay attributable to one name.

  • Email and password sign-in with clear error messages.
  • Social sign-in with Google, Microsoft, or Apple, once Manifold switches it on for the service. It is not available yet, so sign in with email and password.
  • Invitation acceptance for new office users and engineers.
  • Forgot-password and reset-password flows.
  • Role-aware redirects that send each user to the right workspace after sign-in.
  • Sign-out controls in the console and the mobile check flow.

Social Sign-In (Google, Microsoft, Apple)

Where it is enabled, users can sign in or sign up with an existing Google, Microsoft, or Apple identity instead of an email and password. It is an alternative front door. The workspace, roles, and permissions behind it are exactly the same.

  • The "Continue with Google / Microsoft / Apple" buttons appear only once Manifold has enabled those providers for the service. Until then, only email and password sign-in is shown, and there is nothing to switch on in your workspace settings.
  • A brand-new account created this way is provisioned through the same finish-setup step as email sign-up, so a first-time user still lands in a fully set-up organisation.
  • An existing account links by its email address, so signing in with Google using your work email reaches the same account as your password.

Troubleshooting

  • No social buttons appear: social sign-in is not enabled on the service yet. Sign in with email and password.
  • Social sign-in lands on a finish-setup screen: provisioning did not complete; follow the on-screen prompt, which is safe to repeat.

Security Expectations

  • Give every person their own account so record generation, approvals, and audit history stay attributable.
  • Keep export destination credentials and API keys out of shared notes, screenshots, and browser-visible fields.
  • Deactivate users who leave instead of reassigning their email to someone else.
  • Treat tenant-delivery and share links as client-facing distribution links.
  • Passwords must be at least 8 characters, and common passwords are rejected at sign-up, invitation and reset.
  • Manifold does not offer two-factor authentication today, so a strong, unique password for each person matters.
  • A deactivated account cannot sign in; the person sees an account-deactivated message on the sign-in page.

Troubleshooting Sign-In

Troubleshooting

  • Invalid credentials: reset the password or confirm the user is using their invited email address.
  • Invitation expired or wrong user: ask an admin to send a fresh invite.
  • Password reset did not take: open the most recent reset email (each new request replaces the last) and set the new password within 10 minutes of clicking the link. If the link has expired, request another.
  • Sign-in loops: clear site cookies, check third-party cookie restrictions, then contact Manifold support if it persists.

Least-Power Access

Give each person the least powerful role that still lets them do their job. It keeps client data controlled and keeps the audit trail meaningful.

  • Use the engineer role for field staff; do not grant office controls they do not need.
  • Use client portal users for landlords and agents rather than sharing office credentials.
  • Give everyone their own account so records, approvals, and changes stay attributable.
  • Deactivate leavers instead of recycling their account for someone new.

Was this page useful?