Skip to content

Qualytics Team Access

  • Managed deployment

Qualytics team access lets Qualytics team members sign in to your deployment for onboarding, support, and diagnostics. It is enabled by default on managed deployments. An administrator can turn it off whenever access is no longer needed.

Permissions

Only users with the Admin role can change Qualytics team access. This feature is not available on self-hosted deployments.

How Access Works

When access is enabled, the deployment's sign-in page ends with a Qualytics team member? prompt and a Sign in link. Team members follow that link to the Qualytics team sign-in page and use Sign in with Qualytics SSO to authenticate with their active Qualytics work account. Customers continue using their configured sign-in providers. While access is turned off, the team sign-in page shows a Staff access is turned off notice instead of the button.

Staff accounts follow the same Qualytics roles and Team permissions as other personal accounts:

Situation Result
A staff member already has an active account with the same email They sign in to that account with its existing role and Team memberships.
A staff member is new to an established deployment An account is created with the Member role and membership in the Public team. An Admin can grant the access needed for support.
A staff member creates the very first account in an empty deployment The account receives the Admin role so they can help set up the deployment.
A staff member's Qualytics account in the deployment is deactivated Staff sign-in is refused and does not reactivate the account.

Hand Off a New Deployment

After a Qualytics team member establishes the first Admin account, they can invite a customer administrator with the Admin role. Invitations require email and password sign-in. With working email delivery, the invitation is sent automatically. Otherwise, copy the link shown under Share this invite link manually and share it securely with the customer administrator. The customer accepts the invitation and sets their own password, then can configure the organization's SSO providers.

If the customer receives an empty deployment directly, they can instead complete Create Administrator with their own email address and password. Initial enrollment is available only before any personal account has been created. After that, use an invitation or an enabled sign-in provider.

Before ending onboarding, confirm that a customer Admin can sign in independently and manage Settings > Access.

Disable Qualytics Team Access

  1. Sign in using a customer-managed sign-in method with an Admin account.
  2. Open Settings > Access > Providers.
  3. Find the Qualytics team access card at the top of the tab, above the search field and the provider list.
  4. Choose Disabled in the Enabled / Disabled switch.
  5. Confirm with Turn Off and Sign Staff Out in the dialog that opens.

Turning off access immediately ends sessions started through Qualytics team sign-in and prevents new staff sign-ins. The Qualytics team member? prompt disappears from the sign-in page when it is reloaded. The setting remains off until an Admin turns it back on, including after application restarts and upgrades.

Customer sign-in providers keep working. Existing accounts, roles, and Team memberships are retained. If a staff member also has a separate customer-managed sign-in method, that method can still provide access. Deactivate the personal account to prevent all sign-ins by that account.

Re-enable Access

Return to Settings > Access > Providers and choose Enabled in the Qualytics team access card. The change applies immediately, without a confirmation. Staff members must sign in again because previous sessions are not restored.

The card can only be enabled or disabled. The lock icon beside the switch notes that it cannot be edited or removed like other providers. If the card is missing on a managed deployment, contact your Qualytics account team to confirm that staff access is configured for the deployment.

Review Activity

Administrators can review sign-in activity and changes to the access setting under Settings > Access > Log. See View the Sign-In Log.

For roles and data access, see Personal Account Permissions and Team Permissions.