# Account

Manage user, organization & RBAC in Fours Console.

---

## Signup & Login

1. Fours uses [Auth0](https://auth0.com/) as the authentication & authorization provider. Both `Sign in` and `Sign up` share the same entry https://console.suger.io/login.

### Standard Login (Email and Password)
Follow these steps if you have a registered Fours account with an email and password.

1. Email Address: Enter the email address associated with your Fours Console account.

2. Password: Type your password.

3. Complete Login: Once both fields are filled, click the "Continue" button to proceed to your account dashboard.

### Alternative Login Options

Fours supports `sso` with `Google`, `Microsoft` and `OKTA` (available upon request). If you need `sso` with other identity providers like `OKTA`, please contact us at support@suger.io.

* **Continue with Google:** Click the "Continue with Google" button to sign in instantly using your existing Google account credentials.

* **Continue with Microsoft:** Click the "Continue with Microsoft" button to sign in using your existing Microsoft account credentials.

If Fours has set up a custom SSO configuration for your organization, **Settings → SSO** shows it in a read-only **Custom SSO** section. The section lists whichever of these values are set: **Auth Provider**, **Auth0 Application Client ID**, and **Auth0 Enterprise Connection Name**. **Edit in Organization settings** opens the **Organization** tab, where those values are edited. If the organization has no self-service SSO connection, the SSO page says *"This organization has a custom SSO configuration (below) rather than a self-service SSO connection."* instead of *No SSO connections configured yet*.

### Creating a New Account

If you are a new user and do not yet have an account:

1. On the login form, look for the text **"Don't have an account?"**

2. Click the **Sign up** button

3. Choose how you'd like to register — enter an email and password, or continue with **Google**, **Microsoft**, or **Okta**.

4. If you don't belong to an organization yet, Fours then opens **Join an Organization**. If your company's organization is listed there, ask to join it — see [Join an Existing Organization](#join-an-existing-organization). Otherwise, click **Create New Organization** and follow the on-screen prompts to name and create your organization.

This will direct you to the registration page where you can create your new account credentials.

:::info
The account used to create the organization is automatically assigned the `ADMIN` role, and your organization's email domain is inherited from this account. New organizations require approval from Fours Support before they become active — see [Organization](#organization) below.
:::

### Join an Existing Organization

If your company already has a Fours organization, ask to join it instead of creating a second one. While you're signed in but not yet a member of any organization, Fours opens **Join an Organization**, which lists the active organizations on your email domain.

1. Next to your company's organization, click **Join**.
2. Choose a **Requested Role**: **Viewer** (read-only access), **Editor** (view and edit), or **Admin** (full access, including user management). It starts at **Editor**.
3. Write a **Message** of 10 to 1,000 characters saying why you need access, then click **Submit Request**.

Fours confirms with *"Join request submitted successfully!"*, marks the organization **Pending**, and emails its Admins. An Admin approves or rejects the request (see [Review Join Requests](#review-join-requests)), and Fours emails you the decision. If your request is rejected, click **Re-submit** to ask again.

**Joining a partner organization is normally immediate.** Fours approves the request as soon as you submit it and shows *"You have joined the organization."* A request for **Admin** is granted as **Editor**. If the organization shows **Pending** instead, an Admin there reviews your request as usual. See [Let teammates join on their own](/prm/add-portal-users/#let-teammates-join-on-their-own).

### Password Management and Security

If you cannot remember your password:

1. Click the **"Forgot password?"** link located above the **Continue** button.

2. Follow the on-screen prompts to initiate the password reset process.

### Multi-Factor Authentication (MFA)

Fours supports Multi-Factor Authentication (MFA) for an additional layer of account security. When MFA is enabled, the **"Secure Your Account"** screen prompts you to register an authenticator during login.

Before you start, make sure your device's clock is set to automatic date & time (e.g. **Settings → Date & Time → Set Automatically** on iOS, **Settings → System → Date & time → Automatic date & time** on Android). Your authenticator's codes are generated from the current time, so a device with an incorrect or manually-set clock will generate codes that don't match what Fours expects, and verification will keep failing even when you've entered the code correctly.

1. Open an authenticator app (for example, **Microsoft Authenticator** or **Google Authenticator**), or a password manager with a built-in one-time-password feature such as **1Password**.

2. In your authenticator, add a new account and scan the **QR code** shown on the Fours screen.

3. Enter the 6-digit code generated by your authenticator in the **"Enter your one-time code"** field, then click **Continue**.

> <img src="/img/mfa/mfa-setup-qr.jpg" alt="Fours Secure Your Account MFA setup screen with QR code" style="max-width:320px;width:100%;display:inline;margin:0 auto;box-shadow:5px 5px 5px #eee" />

:::tip
If scanning the QR code does not register successfully (a common issue with Microsoft Authenticator), use manual entry instead:

1. On the Fours screen, click **Trouble Scanning?** to reveal the **setup key** (a text code).
2. In your authenticator app, choose **Add account** → **Other account**, then select **Enter code manually** (usually a small button near the bottom of the screen).
3. Type in the setup key from the Fours screen.

Scanning the QR code and entering the setup key register the **exact same token** — scanning is only a shortcut, not a requirement.
:::

:::note
Register the setup key in **only one** authenticator. You can use Microsoft Authenticator **or** 1Password, but adding the same key to multiple apps can cause confusion during login.
:::

On later logins, the **"Verify Your Identity"** screen asks for the current 6-digit code from your authenticator. You can select **"Remember this device for 30 days"** to skip the one-time code on that device on future sign-ins — within the limits described below.

> <img src="/img/mfa/mfa-verify-identity.jpg" alt="Fours Verify Your Identity screen with one-time code field and Remember this device for 30 days option" style="max-width:320px;width:100%;display:inline;margin:0 auto;box-shadow:5px 5px 5px #eee" />

:::caution
**"Remember this device for 30 days" may not keep you signed in for a full 30 days.** For account security, how long a device is remembered is tied to your sign-in session, and the platform does not let the two be configured separately. In practice, a trusted device is currently remembered for **up to 14 days**, and you'll be asked for your one-time code again after **3 days without signing in**.
:::

:::note
You may be asked for your one-time code again — even within that window — whenever the "remembered device" record stored in your browser is cleared. Common causes:

- clearing your browser's cookies or site data;
- signing in from a different browser or device, or in a private/incognito window;
- a browser or extension configured to clear cookies when it closes.
:::

:::tip
To stay remembered for as long as possible, sign in from the **same browser** on the same device and avoid clearing cookies or using private/incognito mode. Keep your authenticator app handy for when the prompt does return.
:::

## Organization

1. All Fours resources are organized & managed under organization. Each user must belong to at least one organization.

2. When you sign up for Fours for the first time and don't belong to an organization yet, you will be prompted to join your company's existing organization or create a new one (see [Join an Existing Organization](#join-an-existing-organization)). However, please note that a new organization will require approval from Fours in order to become active. To initiate the approval process for your newly created organization, please get in touch with [Fours Support](mailto:support@suger.io).

3. **At most two organizations per email domain may await approval at once.** A third create is refused with a `409` naming how many are already in the queue. Wait for the pending ones to be reviewed before creating another.

4. The user who creates the organization has the `ADMIN` role as default. It is allowed to add new users, edit user role or delete the users. There are 3 predefined standard roles: `ADMIN`, `EDITOR` & `VIEWER`. Their permission scope is defined below:

   | User Role | Recommended for                              | RBAC Permissions                                                                                       |
   | --------- | -------------------------------------------- | :----------------------------------------------------------------------------------------------------- |
   | `ADMIN`   | Business Technology, Sales Ops, IT/CRM Admins | Full access, including management of users, organizations, API Client & Webhook.                       |
   | `EDITOR`  | Sales, Partnerships, Alliances, Deal Desk     | Full access, but excluding the access to management of users, organizations, API Client & Webhook.     |
   | `VIEWER`  | Finance, Accounting, Executives               | Can only access Fours services with `read` access, no permission to `create/edit/delete` any resources. **Exception:** Partner Management grants Viewers no access at all, not even read — see [Who can use Partner Management](/prm/#who-can-use-partner-management) |

   :::tip

   - The `email domain` of the organization inherits from the user who created it.
   - For security purpose, only the users who has the same `email domain` as the organization can be added to that organization.
:::

## Invite Your Team

Once your organization is active, an Admin can add teammates. Inviting a user **pre-approves** their email for the Fours Console — it does **not** create an account. The invitee still has to sign up themselves to activate access.

### Invite a New Team Member

1. Go to [**Settings > Users & Roles**](https://console.suger.io/settings?tab=users_roles).
2. Click **New User** at the top right of the user table.
3. In **Add New User**, enter the user's **First Name**, **Last Name**, and professional **Email**, then select a **Role** — **Admin**, **Editor**, or **Viewer** (or a [custom role](#custom-role-with-granular-permissions)).
4. Click **Save**. Fours emails the user an invitation with a link to sign up.

If that person had already asked to join your organization, Fours normally resolves their pending join request at the same time. When it does, it tells you: *"This user already had a pending join request for this organization — it has been resolved automatically."*

:::warning
Fours only allows invites to email addresses that share your organization's domain. A user with a different domain can't be added — this is a common reason an invite silently fails to reach the intended person.
:::

### Manage Users

- **Monitor status**: Check the **Status** column in the user table to see whether an invite is still **Pending** or the user is **Active**.
- **Update roles**: Click the **Edit** icon next to a user, then select a new role from the dropdown.
- **Revoke access**: Click the **Delete** (or **Revoke**) icon next to a user to remove their access to the organization immediately.
- **Reset MFA**: If a member is locked out of their authenticator, click the **Reset MFA** icon next to them to clear their registered factors so they can enroll a new one. See [Reset a Member's MFA](#reset-a-members-mfa).

### Review Join Requests

When someone on your email domain asks to join your organization, Fours emails your organization's Admins and lists the request under **Pending Join Requests**, at the top of [**Settings > Users & Roles**](https://console.suger.io/settings?tab=users_roles). Only Admins can see and act on these requests, and the table appears only while at least one is waiting.

- **Approve**: in the **Approve Join Request** dialog, choose the **Grant Role** — **Viewer**, **Editor**, or **Admin**. It starts at the role they asked for. Click **Approve**, and they join with that role.
- **Reject**: optionally give a **Reason**, then click **Reject**.

Either way, Fours emails the requester the decision, including your reason if you gave one.

**When the requester is already a member.** Someone can get access another way before anyone reviews their request — for example, you add them with **New User**, or they sign in through your company's single sign-on. Fours normally closes their pending request by itself when that happens. A request that stays open for someone who is already in your organization is marked **Already a member**:

- Click **Approve** to clear it. No role dialog opens, and the role they already have doesn't change.
- **Reject** is unavailable for that row. Its tooltip reads *"Already a member — use Approve to clear this request"*.

Requests to join a **partner** organization are normally approved on submit, and only appear here if that automatic approval fails. See [Let teammates join on their own](/prm/add-portal-users/#let-teammates-join-on-their-own).

```d2
direction: right
submit: "Teammate submits\na join request"
pending: "Pending\nAdmins are emailed"
approved: "Approved\nthey are a member"
rejected: "Rejected\nrequester is emailed"
submit -> pending: "any other organization\n(or partner approval fails)"
submit -> approved: "partner organization:\napproved on submit"
pending -> approved: "an Admin approves"
pending -> rejected: "an Admin rejects"
pending -> approved: "usually closed when they\nget access another way"
rejected -> submit: "Re-submit" { style.stroke-dash: 4 }
```

### Reset a Member's MFA

If a teammate loses their phone, switches devices, or is otherwise locked out of their authenticator, an Admin can reset that member's MFA so they can enroll a new one — no need to contact Fours Support.

1. Go to [**Settings > Users**](https://console.suger.io/settings?tab=users_roles).
2. Find the member in the user table and click the **Reset MFA** icon in their row.
3. Confirm the action in the dialog that appears.

![Reset MFA icon in a user row on the Users & Roles page in the Fours Console](images/reset-mfa.png)

What happens next:

- The member's registered MFA factors (authenticator-app codes and passkeys) are cleared.
- On their next login, the **"Secure Your Account"** screen prompts them to register a new authenticator — the same as [first-time MFA setup](#multi-factor-authentication-mfa).

:::note
- Only **Admins** can reset MFA, and only for members of their own organization.
- The reset itself is **account-wide, not scoped to your organization**. The confirmation dialog says so: it clears MFA for the member's entire Fours account, including any other organizations they belong to.
- Resetting MFA does **not** change the member's password, remove them from the organization, or affect their role.
- It temporarily lowers the member's account security until they re-enroll, so only reset MFA when the member has genuinely lost access to their authenticator.
:::

### Complete the Onboarding (For Invited Users)

Once invited, a new teammate follows these steps to activate their account:

1. **Open the invitation email**: Check your inbox for an email from Fours with the subject line **"Hi [Your Name], you have been invited to Fours"**, then click the **Create your account** button.
2. **Establish credentials**: The button takes you straight to the Auth0 **Sign Up** form with your email address already filled in — you don't need to switch over from the login form or retype your address.
   - **Standard signup**: Set a secure password to create your account.
   - **If SSO is enabled**: Use **Continue with Google**, **Microsoft**, or **Okta/SSO** to register with your company credentials instead of a password.
3. **Verify your email**: After you set a password, a **"Verify your email"** dialog appears — _"Your account is created. We sent a verification link to [your email address]."_ Open that link from your inbox to activate the account. Following the link brings you back to Fours and logs you in automatically; if you'd rather finish in the tab you already have open, click **I've verified — continue** there once you've opened the link.
4. **Access the console**: After a successful login, you land on the Fours Dashboard with the access level your Admin assigned.

## Custom Role with Granular Permissions

Custom roles offer precise control over permissions, allowing you to go beyond the limitations of predefined standard roles, which may be overly broad. This flexibility enables assigning specific permissions at a more granular level — you can toggle **Read**, **Write**, and **Delete** per console module (for example, **Billing**, **Co-Sell**, or **Private Offers**).

### Create Custom Role

1. Navigate to the [settings page](https://console.suger.io/settings) of your organization.
2. Locate the `Roles` section under the `Organization & Users` tab.
3. Click the `Add Custom Role` button.
4. Fill in the name and description fields.
5. Set permissions according to your specific requirements.

> <img src="/img/custom-roles/creating-a-role.jpg" alt="Add Custom Role form with name, description, and permissions" style="max-width:590px;width:100%;display:inline;margin:0 auto;box-shadow:5px 5px 5px #eee" />

### Assign Custom Role to User

Once custom roles are created, you can apply them during the creation or modification of a user.

1. Visit the [settings page](https://console.suger.io/settings) of your organization.
2. Find the `Users` section under the `Organization & Users` tab.
3. Add a new user by clicking the `Add User` button or edit an existing user by clicking the edit button in each user row.
4. Set the role field in the `Add User`/`Edit User` dialog to the desired custom role.

### Edit Custom Role

1. Visit the [settings page](https://console.suger.io/settings) of your organization.
2. Locate the `Roles` section under the `Organization & Users` tab.
3. Click the edit button in each custom role row.
4. Modify the name, description, and permissions as needed. Once saved, the updated permission set applies to every user currently assigned to that role.

   > <img src="/img/custom-roles/editing-a-role.jpg" alt="Edit Custom Role form with name, description, and permissions" style="max-width:880px;width:100%;display:inline;margin:0 auto;box-shadow:5px 5px 5px #eee" />

## Use Okta as Identity Provider

Fours supports **Okta** as an identity provider, allowing centralized user authentication and access management through your Okta account.

Refer to [Okta SSO](/integrations/okta-sso) for more details.

## Troubleshooting

| Issue | Possible cause | Resolution |
| --- | --- | --- |
| QR code won't scan when setting up MFA | Common with Microsoft Authenticator specifically | Click **Trouble Scanning?** on the Fours screen to reveal the setup key. In your authenticator, choose **Add account → Other account → Enter code manually**, then type in the setup key. Scanning the QR code and entering the setup key register the exact same token. |
| MFA code is rejected even though you entered it correctly | Device clock isn't set to automatic date & time, so the authenticator generates a code for the wrong moment in time | Turn on automatic date & time in your device's settings, then wait for a new code to generate before retrying. |
| Invite doesn't reach the intended person | Email address doesn't share the organization's domain | Confirm the invitee's email matches your org's domain. Fours only allows invites within the same domain. |
| **Reject** is greyed out on a join request | The row is marked **Already a member** — the person got access another way before anyone reviewed the request | Click **Approve** to clear the request. Their existing role doesn't change. |

## Frequently Asked Questions

**Q: Does inviting someone create their Fours account?**
A: No. It only pre-approves their email for signup. They must complete registration themselves.

**Q: Can I invite someone with a personal or different-company email?**
A: No — invites are restricted to users sharing your organization's email domain.

**Q: What's the difference between a standard role and a custom role?**
A: Standard roles (Admin, Editor, Viewer) are fixed. Custom roles let you toggle Read/Write/Delete permissions per module for more granular control.

**Q: Do I have to enter my MFA code every time I log in?**
A: No — select **"Remember this device for 30 days"** on the Verify Your Identity screen to skip MFA on that device for 30 days.

**Q: A teammate lost the phone with their authenticator — how do they get back in?**
A: An Admin can reset that member's MFA from **Settings > Users**. On the member's next login, they'll be prompted to set up a new authenticator. See [Reset a Member's MFA](#reset-a-members-mfa).
