Users and authentication
See how users sign in and how roles, module access and organisation assignments shape access in Studio.
Each account has one email address, one way to sign in, a role, module access and its organisations. The sign-in page offers only the methods your OmniLab environment has turned on.

How people sign in
| Method | On the sign-in page | Good to know |
|---|---|---|
| Continue with Email | OmniLab emails a one-time link to that address. It expires after 24 hours | |
| Company single sign-on, such as Microsoft | A company sign-in button | Your company's own rules apply, such as multi-factor checks |
Whichever the method, Studio signs people out after 24 hours. To set up single sign-on, see Company sign-in (SSO).
Each account signs in one way
The method is part of the account, not a choice on the sign-in page. Someone set to single sign-on can't get in with an email link, and the reverse. That's what makes single sign-on enforce your company's rules: multi-factor checks apply to OmniLab too, and disabling someone in your company system ends their OmniLab access within 24 hours.
- When your environment offers several methods, the user form shows Authentication Provider, and the admin picks one. With one method, it's set for you.
- Only an admin can change it.
- Turning a method off for the environment blocks everyone set to it.
If someone can't sign in
The sign-in page says why:
| Message | What to do |
|---|---|
| Wrong sign-in method | Use the method set on the account. Signing in the same way again fails the same way |
| User not found | Create the account for that exact address |
| Email domain not allowed | The domain isn't on your environment's allowed list: ask OmniLab |
| No organisation assigned | Add an organisation to the account |
| Wrong organisation | Their company account belongs to another OmniLab environment |
| Sign-in unavailable | Try again in a moment |
What they can do once in depends on their role, module access and organisations: see Roles and permissions.