Help

Staff logins and security

Who can get in, what they can do once they are in, and how to get somebody out.

Where staff sign in

At your organization's own address, yourgroup.sembr.co/login.

There is no shared front door. app.sembr.co/login returns a 404 by design, because that host belongs to no organization and a staff route only resolves where a tenant exists. Somebody who does not know your address has nothing to guess at.

How many logins

Essential includes 3. Growth includes 10. Every feature is identical between the two; seats are one of only two things that differ. See pricing.

Permissions

Staff carry named permissions rather than a single blunt role. Ask Sembr, for example, sits behind its own permission, so being able to sign in does not mean being able to run AI queries against your roster.

Sign-in protection

Repeated failed sign-ins lock the account rather than letting somebody grind through passwords. Sembr also runs a bot check on the sign-in and sign-up forms.

Signing out everywhere

There is a control that ends every session for a user, on every device.

It signs out the device you are using, too. That is on purpose. Somebody clicking this has usually lost a phone or thinks a password is compromised, and a version that politely leaves the current session alive would fail at the one job it has. It is worth knowing before you press it, because you will be asked to sign in again immediately.

The same control exists for members in their portal, and behaves the same way.

What gets recorded

A successful staff sign-in is written to the audit log: who, when, and which door they came through.

The audit log is append-only and each entry is sealed against the one before it, so an entry cannot be altered or removed without breaking the chain. It deliberately does not record IP addresses or browser user agents. Those columns were removed so that erasing a member is complete by construction rather than by remembering to go and scrub a second table.

API tokens

Tokens are minted and revoked in settings, and a revoked token stops working immediately. Treat one like a password: it carries the same access, and it does not expire on its own. See the REST API.

What we have not built

Two-factor authentication for staff sign-in is not there yet. It is the honest gap in this page and we are not going to describe it as coming soon with a date attached.

Single sign-on is not built either.

Read the trust centre.

Every commitment, with its real status.