Migrated logins & access
How admins check migrated user access, how first-login and Google sign-in work, how no-login employees appear, and how to invite or reset users.
When an organization moves to Heimdallone, sign-in accounts come across with it. This page is for admins checking who has access after a migration and helping people get signed in.
Check migrated access
Go to App → Migration status (visible to HR Admin and Tenant Owner / Admin). It groups every migrated person by their login state:
| State | Meaning | Action |
|---|---|---|
| Login active | Migrated, signed in, and reviewed their profile | None |
| Pending acknowledgement | Migrated but hasn't yet seen/acknowledged the welcome notice | None — happens at their first sign-in |
| Pending review | Acknowledged but hasn't reviewed their profile yet | Gentle nudge if needed |
| No login (has email) | No account yet, but an email is on file | Invite them if they should have access |
| No login (missing email) | Intentionally no login (seasonal/contractor/payroll-only) | Add a real email only if they need access |
The summary tiles show totals: how many logins were preserved, how many are pending acknowledgement or review, and how many people are no-login.
How first sign-in works
Migrated users see a one-time welcome notice the first time they sign in, asking them to review their details. It must be acknowledged once and then never appears again. The full employee-facing explanation is on Your first sign-in.
How sign-in carries over
- Email & password — the same password keeps working; it is never reset or weakened by the migration.
- Google sign-in — where someone used Google before, Google sign-in continues to work. The Google connection itself is configured by an administrator (see Google sign-in); credentials live in secure configuration, never in the app or in documentation.
- Couldn't carry over safely? — the person is guided through a secure password reset or invitation instead. Passwords are never fabricated or stored in plain text.
No-login employees
Some people are migrated without a login — for example seasonal staff, contractors, or payroll-only records. They appear normally in Employees, are paid, and show up in attendance, but they can't sign in. No placeholder email addresses are ever created. To give someone access, add their real email on their employee record and invite them.
Creating a login for a staff member
HR AdminAdminWhen someone has no account — a no-login employee who now needs access, or someone who lost access after the migration — HR or Admin can create a login for them directly from the Migration status page.
The temporary password is shown only once
The temporary password appears a single time on screen. Copy it and share it with the person out of band (in person, or over a secure channel — not in an email or ticket). It is never logged or stored in plain text, so it can't be retrieved later. If it's lost, create the login again or use a password reset.
- Idempotent — if the employee already has a login, creating one again won't produce a duplicate account.
- Tenant-scoped — the login is created within your organisation; it doesn't grant cross-organisation access.
- Real emails only — no placeholder addresses are ever created. If a profile has no email, you must provide a genuine one.
Invite or reset a user
Platform owner vs tenant owner
- A Tenant Owner owns a single organization and has every permission within that organization.
- A Platform Owner is a separate, cross-organization account used to administer the platform itself and switch between organizations. Being an owner inside one organization does not make someone a platform owner.
Roles in depth
For what each role can do, see Roles & access and Users & roles.
Migration & cutover
What data comes across from a legacy system, what users should expect, and how admins verify migrated employees, payslips, attendance, finance, and devices inside Heimdallone.
Your first sign-in (migrated users)
What migrated employees see the first time they sign in to Heimdallone v2 — the welcome notice and how to review and update your profile.