# Account

Manage user, organization & RBAC in Suger Console.

---

## Signup & Login

1. Suger use [Auth0](https://auth0.com/) as the authentication & authorization provider. Both `Sign in` and `Sign up` share the same entry https://console.suger.io/login.

### Standard Login (Email and Password)
Follow these steps if you have a registered Suger account with an email and password.

1. Email Address: Enter the email address associated with your Suger Console account.

2. Password: Type your password.

3. Complete Login: Once both fields are filled, click the "Continue" button to proceed to your account dashboard.

### Alternative Login Options

Suger supports `sso` with `Google`, `Microsoft` and `OKTA` (available upon request). If you need `sso` with other identity providers like `OKTA`, please contact us at support@suger.io.

* **Continue with Google:** Click the "Continue with Google" button to sign in instantly using your existing Google account credentials.

* **Continue with Microsoft:** Click the "Continue with Microsoft" button to sign in using your existing Microsoft account credentials.

### Creating a New Account

If you are a new user and do not yet have an account:

1. On the login form, look for the text **"Don't have an account?"**

2. Click the **Sign up** button

3. Choose how you'd like to register — enter an email and password, or continue with **Google**, **Microsoft**, or **Okta**.

4. Follow the on-screen prompts to name and create your organization.

This will direct you to the registration page where you can create your new account credentials.

:::info
The account used to create the organization is automatically assigned the `ADMIN` role, and your organization's email domain is inherited from this account. New organizations require approval from Suger Support before they become active — see [Organization](#organization) below.
:::

### Password Management and Security

If you cannot remember your password:

1. Click the **"Forgot password?"** link located above the **Continue** button.

2. Follow the on-screen prompts to initiate the password reset process.

### Multi-Factor Authentication (MFA)

Suger supports Multi-Factor Authentication (MFA) for an additional layer of account security. When MFA is enabled, the **"Secure Your Account"** screen prompts you to register an authenticator during login.

Before you start, make sure your device's clock is set to automatic date & time (e.g. **Settings → Date & Time → Set Automatically** on iOS, **Settings → System → Date & time → Automatic date & time** on Android). Your authenticator's codes are generated from the current time, so a device with an incorrect or manually-set clock will generate codes that don't match what Suger expects, and verification will keep failing even when you've entered the code correctly.

1. Open an authenticator app (for example, **Microsoft Authenticator** or **Google Authenticator**), or a password manager with a built-in one-time-password feature such as **1Password**.

2. In your authenticator, add a new account and scan the **QR code** shown on the Suger screen.

3. Enter the 6-digit code generated by your authenticator in the **"Enter your one-time code"** field, then click **Continue**.

> <img src="/img/mfa/mfa-setup-qr.jpg" alt="Suger Secure Your Account MFA setup screen with QR code" style="max-width:320px;width:100%;display:inline;margin:0 auto;box-shadow:5px 5px 5px #eee" />

:::tip
If scanning the QR code does not register successfully (a common issue with Microsoft Authenticator), use manual entry instead:

1. On the Suger screen, click **Trouble Scanning?** to reveal the **setup key** (a text code).
2. In your authenticator app, choose **Add account** → **Other account**, then select **Enter code manually** (usually a small button near the bottom of the screen).
3. Type in the setup key from the Suger screen.

Scanning the QR code and entering the setup key register the **exact same token** — scanning is only a shortcut, not a requirement.
:::

:::note
Register the setup key in **only one** authenticator. You can use Microsoft Authenticator **or** 1Password, but adding the same key to multiple apps can cause confusion during login.
:::

On later logins, the **"Verify Your Identity"** screen asks for the current 6-digit code from your authenticator. Select **"Remember this device for 30 days"** to skip MFA on that device for 30 days.

> <img src="/img/mfa/mfa-verify-identity.jpg" alt="Suger Verify Your Identity screen with one-time code field and Remember this device for 30 days option" style="max-width:320px;width:100%;display:inline;margin:0 auto;box-shadow:5px 5px 5px #eee" />

## Organization

1. All Suger resources are organized & managed under organization. Each user must belong to at least one organization.

2. When you sign up for Suger for the first time, you will be prompted to create a new organization. However, please note that your organization will require approval from Suger in order to become active. To initiate the approval process for your newly created organization, please get in touch with [Suger Support](mailto:support@suger.io).

3. The user who creates the organization has the `ADMIN` role as default. It is allowed to add new users, edit user role or delete the users. There are 3 predefined standard roles: `ADMIN`, `EDITOR` & `VIEWER`. Their permission scope is defined below:

   | User Role | Recommended for                              | RBAC Permissions                                                                                       |
   | --------- | -------------------------------------------- | :----------------------------------------------------------------------------------------------------- |
   | `ADMIN`   | Business Technology, Sales Ops, IT/CRM Admins | Full access, including management of users, organizations, API Client & Webhook.                       |
   | `EDITOR`  | Sales, Partnerships, Alliances, Deal Desk     | Full access, but excluding the access to management of users, organizations, API Client & Webhook.     |
   | `VIEWER`  | Finance, Accounting, Executives               | Can only access Suger services with `read` access, no permission to `create/edit/delete` any resources |

   :::tip

   - The `email domain` of the organization inherits from the user who created it.
   - For security purpose, only the users who has the same `email domain` as the organization can be added to that organization.
:::

## Invite Your Team

Once your organization is active, an Admin can add teammates. Inviting a user **pre-approves** their email for the Suger Console — it does **not** create an account. The invitee still has to sign up themselves to activate access.

### Invite a New Team Member

1. Go to [**Settings > Users**](https://console.suger.io/settings?tab=users_roles).
2. Click the **Add User** (or **Invite User**) button at the top right.
3. Enter the user's professional email address, then select a permission level from the dropdown — **Admin**, **Editor**, or **Viewer** (or a [custom role](#custom-role-with-granular-permissions)).
4. Click **Save**. Suger generates a secure invitation link and emails it to the user.

:::warning
Suger only allows invites to email addresses that share your organization's domain. A user with a different domain can't be added — this is a common reason an invite silently fails to reach the intended person.
:::

### Manage Users

- **Monitor status**: Check the **Status** column in the user table to see whether an invite is still **Pending** or the user is **Active**.
- **Update roles**: Click the **Edit** icon next to a user, then select a new role from the dropdown.
- **Revoke access**: Click the **Delete** (or **Revoke**) icon next to a user to remove their access to the organization immediately.
- **Reset MFA**: If a member is locked out of their authenticator, click the **Reset MFA** icon next to them to clear their registered factors so they can enroll a new one. See [Reset a Member's MFA](#reset-a-members-mfa).

### Reset a Member's MFA

If a teammate loses their phone, switches devices, or is otherwise locked out of their authenticator, an Admin can reset that member's MFA so they can enroll a new one — no need to contact Suger Support.

1. Go to [**Settings > Users**](https://console.suger.io/settings?tab=users_roles).
2. Find the member in the user table and click the **Reset MFA** icon in their row.
3. Confirm the action in the dialog that appears.

![Reset MFA icon in a user row on the Users & Roles page in the Suger Console](images/reset-mfa.png)

What happens next:

- The member's registered MFA factors (authenticator-app codes and passkeys) are cleared.
- On their next login, the **"Secure Your Account"** screen prompts them to register a new authenticator — the same as [first-time MFA setup](#multi-factor-authentication-mfa).

:::note
- Only **Admins** can reset MFA, and only for members of their own organization.
- Resetting MFA does **not** change the member's password, remove them from the organization, or affect their role.
- It temporarily lowers the member's account security until they re-enroll, so only reset MFA when the member has genuinely lost access to their authenticator.
:::

### Complete the Onboarding (For Invited Users)

Once invited, a new teammate follows these steps to activate their account:

1. **Accept the invite**: Check your inbox for an email from Suger with the subject line "Invitation to join [Organization Name]," then click the **Join Organization** / **Accept Invitation** link.
2. **Establish credentials**:
   - **If SSO is enabled**: Click **Continue with Okta/SSO** to log in with your company credentials.
   - **Standard login**: Enter your name and set a secure password to create your account.
3. **Access the console**: After a successful login, you land on the Suger Dashboard with the access level your Admin assigned.

## Custom Role with Granular Permissions

Custom roles offer precise control over permissions, allowing you to go beyond the limitations of predefined standard roles, which may be overly broad. This flexibility enables assigning specific permissions at a more granular level — you can toggle **Read**, **Write**, and **Delete** per console module (for example, **Billing**, **Co-Sell**, or **Private Offers**).

### Create Custom Role

1. Navigate to the [settings page](https://console.suger.io/settings) of your organization.
2. Locate the `Roles` section under the `Organization & Users` tab.
3. Click the `Add Custom Role` button.
4. Fill in the name and description fields.
5. Set permissions according to your specific requirements.

> <img src="/img/custom-roles/creating-a-role.jpg" alt="Add Custom Role form with name, description, and permissions" style="max-width:590px;width:100%;display:inline;margin:0 auto;box-shadow:5px 5px 5px #eee" />

### Assign Custom Role to User

Once custom roles are created, you can apply them during the creation or modification of a user.

1. Visit the [settings page](https://console.suger.io/settings) of your organization.
2. Find the `Users` section under the `Organization & Users` tab.
3. Add a new user by clicking the `Add User` button or edit an existing user by clicking the edit button in each user row.
4. Set the role field in the `Add User`/`Edit User` dialog to the desired custom role.

### Edit Custom Role

1. Visit the [settings page](https://console.suger.io/settings) of your organization.
2. Locate the `Roles` section under the `Organization & Users` tab.
3. Click the edit button in each custom role row.
4. Modify the name, description, and permissions as needed. Once saved, the updated permission set applies to every user currently assigned to that role.

   > <img src="/img/custom-roles/editing-a-role.jpg" alt="Edit Custom Role form with name, description, and permissions" style="max-width:880px;width:100%;display:inline;margin:0 auto;box-shadow:5px 5px 5px #eee" />

## Use Okta as Identity Provider

Suger supports **Okta** as an identity provider, allowing centralized user authentication and access management through your Okta account.

Refer to [Okta SSO](/integrations/okta-sso) for more details.

## Troubleshooting

| Issue | Possible cause | Resolution |
| --- | --- | --- |
| QR code won't scan when setting up MFA | Common with Microsoft Authenticator specifically | Click **Trouble Scanning?** on the Suger screen to reveal the setup key. In your authenticator, choose **Add account → Other account → Enter code manually**, then type in the setup key. Scanning the QR code and entering the setup key register the exact same token. |
| MFA code is rejected even though you entered it correctly | Device clock isn't set to automatic date & time, so the authenticator generates a code for the wrong moment in time | Turn on automatic date & time in your device's settings, then wait for a new code to generate before retrying. |
| Invite doesn't reach the intended person | Email address doesn't share the organization's domain | Confirm the invitee's email matches your org's domain. Suger only allows invites within the same domain. |

## Frequently Asked Questions

**Q: Does inviting someone create their Suger account?**
A: No. It only pre-approves their email for signup. They must complete registration themselves.

**Q: Can I invite someone with a personal or different-company email?**
A: No — invites are restricted to users sharing your organization's email domain.

**Q: What's the difference between a standard role and a custom role?**
A: Standard roles (Admin, Editor, Viewer) are fixed. Custom roles let you toggle Read/Write/Delete permissions per module for more granular control.

**Q: Do I have to enter my MFA code every time I log in?**
A: No — select **"Remember this device for 30 days"** on the Verify Your Identity screen to skip MFA on that device for 30 days.

**Q: A teammate lost the phone with their authenticator — how do they get back in?**
A: An Admin can reset that member's MFA from **Settings > Users**. On the member's next login, they'll be prompted to set up a new authenticator. See [Reset a Member's MFA](#reset-a-members-mfa).
