Sign-In Troubleshooting
- Managed deployment
- Self-hosted
Start with the sign-in method the person selected and the time of the attempt. An Admin can review Settings > Access > Log, check Link approvals, and run Test on the relevant SSO provider.
Permissions
Only Admins can inspect provider configuration, link requests, invitations, and the sign-in log. Other users should share the sign-in method, time, and visible message with their administrator. Do not share passwords, invitation links, reset links, or client secrets in support reports.
Providers and First Sign-In
| Symptom | What to check |
|---|---|
| The initial administrator form is missing | Enrollment is available only before any personal account has been created. Use an existing sign-in method or ask an Admin for an invitation. Deactivating accounts does not reopen enrollment. |
| An SSO button is missing | Confirm the customer provider is Enabled under Providers. A Google Workspace provider configured to fetch groups also needs its administrator authorization completed before it can be enabled. |
| The email and password form is missing | Confirm the Email & Password provider is enabled. Password reset and invitations are unavailable while it is disabled. |
| The Qualytics team sign-in link or card is missing | This feature is for managed deployments. An Admin can check Qualytics team access under Providers. If the card itself is absent, ask your Qualytics account team to confirm deployment configuration. See Qualytics Team Access. |
| Provider Test passes but a user cannot sign in | Diagnostics check configuration and connectivity. They do not prove that a particular account meets domain, group, provisioning, or linking policies. Review the sign-in log and complete a real sign-in. |
| An OIDC sign-in reports a redirect mismatch | Register the exact Redirect URI shown for that saved provider in your identity provider's application. Use the address for this deployment and provider. |
| A private identity provider cannot be reached | Self-hosted operators should check network reachability, certificate trust, and private-network identity provider settings. |
Existing Accounts and Link Approvals
| Symptom | What to check |
|---|---|
| An existing user cannot use a new provider | Confirm the provider presents the email of the existing account and that Cross-provider account linking is enabled. If approval is required, review Link approvals and tell the person to sign in again after approval. |
| No link request appears | The request may have been linked automatically, already rejected, or refused by another policy. A new user with no matching account follows Automatic user provisioning, rather than existing-account link approval. Check Log for the result. |
| An approved user still cannot sign in | Approval does not bypass a disabled provider, deactivated account, or provider access restrictions. Ask the user to retry, then inspect the new sign-in event. |
| A request was rejected by mistake | The tab shows pending requests only. An Admin can reverse a rejection through the Link Approvals API. |
| A user signs in but cannot see the expected data | Check the account's role and Team memberships. Successful authentication does not grant access to every datastore. See Team Permissions. |
Invitations and Password Recovery
| Symptom | What to check |
|---|---|
| The Invitations tab is missing | It requires an Admin account and an enabled Email & Password provider. |
| An invitation email could not be sent | The invitation is still created. Copy the link under Share this invite link manually in the invitation dialog and send it securely to its intended recipient. Self-hosted operators can review SMTP configuration. |
| An invitation disappeared | Accepted invitations are normally removed after activation; revoked invitations are hidden from the default list. Check the Users tab and the Invitation Accepted event in Log for completed enrollment. |
| An invitation expired | Send a new invitation. There is no resend action. If another unused invitation is still valid and should no longer work, revoke it separately. |
| An SSO user cannot accept a password invitation | Adding password sign-in to an existing account follows the Email & Password provider's linking policy. It is not allowed by default. See Inviting an Existing User. |
| No password reset email arrives | Confirm that the person already has password sign-in, used the correct email, and that email delivery is working. The request confirmation intentionally does not disclose whether an account exists. |
| A password reset link no longer works | Use the most recent reset email. A newer reset link invalidates older ones, and each link is single-use and expires. See Reset Your Password. |
| Password sign-in is temporarily locked | Wait for the configured lockout period or complete password recovery. Repeated requests may also be rate-limited. |
Sessions and Access Changes
Disabling a customer provider ends sessions issued through it. Deactivating a personal account prevents that account from signing in through any provider. Turning off Qualytics team access ends sessions created through staff sign-in; it does not disable customer providers.
For OIDC session duration, offline access, and identity provider outages, see Sessions. To review an incident, see View the Sign-In Log.