Heimdallone Docs
Administration

Migrated logins & access

How admins check migrated user access, how first-login and Google sign-in work, how no-login employees appear, and how to invite or reset users.

AdminHR AdminTenant OwnerSecurity

When an organization moves to Heimdallone, sign-in accounts come across with it. This page is for admins checking who has access after a migration and helping people get signed in.

Check migrated access

Go to App → Migration status (visible to HR Admin and Tenant Owner / Admin). It groups every migrated person by their login state:

StateMeaningAction
Login activeMigrated, signed in, and reviewed their profileNone
Pending acknowledgementMigrated but hasn't yet seen/acknowledged the welcome noticeNone — happens at their first sign-in
Pending reviewAcknowledged but hasn't reviewed their profile yetGentle nudge if needed
No login (has email)No account yet, but an email is on fileInvite them if they should have access
No login (missing email)Intentionally no login (seasonal/contractor/payroll-only)Add a real email only if they need access

The summary tiles show totals: how many logins were preserved, how many are pending acknowledgement or review, and how many people are no-login.

How first sign-in works

Migrated users see a one-time welcome notice the first time they sign in, asking them to review their details. It must be acknowledged once and then never appears again. The full employee-facing explanation is on Your first sign-in.

How sign-in carries over

  • Email & password — the same password keeps working; it is never reset or weakened by the migration.
  • Google sign-in — where someone used Google before, Google sign-in continues to work. The Google connection itself is configured by an administrator (see Google sign-in); credentials live in secure configuration, never in the app or in documentation.
  • Couldn't carry over safely? — the person is guided through a secure password reset or invitation instead. Passwords are never fabricated or stored in plain text.

No-login employees

Some people are migrated without a login — for example seasonal staff, contractors, or payroll-only records. They appear normally in Employees, are paid, and show up in attendance, but they can't sign in. No placeholder email addresses are ever created. To give someone access, add their real email on their employee record and invite them.

Creating a login for a staff member

HR AdminAdmin

When someone has no account — a no-login employee who now needs access, or someone who lost access after the migration — HR or Admin can create a login for them directly from the Migration status page.

Go to App → Migration status and find the person (they'll be in a No login state).
Choose Create login for that employee.
Supply or override the email. If the employee's profile already has an email it's used; you can override it. If the profile has no email, you must supply a real one — it becomes their sign-in identity.
Pick the portal role that controls what they can do once signed in.
Confirm. A one-time temporary password is generated and shown once.

The temporary password is shown only once

The temporary password appears a single time on screen. Copy it and share it with the person out of band (in person, or over a secure channel — not in an email or ticket). It is never logged or stored in plain text, so it can't be retrieved later. If it's lost, create the login again or use a password reset.

  • Idempotent — if the employee already has a login, creating one again won't produce a duplicate account.
  • Tenant-scoped — the login is created within your organisation; it doesn't grant cross-organisation access.
  • Real emails only — no placeholder addresses are ever created. If a profile has no email, you must provide a genuine one.

Invite or reset a user

To give a no-login employee access, open their record in App → Employees, add a real email, and send an invite.
To change what someone can do, adjust their role in Workspace settings — see Users & roles. Only Tenant Owner / Admin can change roles.
If a user can't sign in, have them use the password-reset option on the sign-in screen, or re-send the invite.

Platform owner vs tenant owner

  • A Tenant Owner owns a single organization and has every permission within that organization.
  • A Platform Owner is a separate, cross-organization account used to administer the platform itself and switch between organizations. Being an owner inside one organization does not make someone a platform owner.

Roles in depth

For what each role can do, see Roles & access and Users & roles.

On this page