Claiming Your Account: The Invitation Flow
How an invited team member claims their Quartyl account: the 72-hour onboarding link, the details you set, MFA enrolment after the claim, and failed-link states.
Quartyl accounts are not self-serve signups: you enter a firm when the firm invites you. That is deliberate — a tenancy is a client engagement boundary, and no one should be able to walk into a firm’s studies, records or settings from the outside. The invitation link is the only creation path, and the claim itself is short.
How the invite works
- The Firm Admin — or a Partner, who shares the team console — opens team management and sends an invitation: an email address and a role, the role having to sit inside the firm’s role scope.
- The invite carries a one-time onboarding link. Only a hash of the claim token is stored, so a leaked database cannot mint live links, and the link is valid for 72 hours.
- You open the link, set your own name and password, and the account exists under the role you were invited with — no password was ever chosen for you, and none travels by email.
Resending an invitation rotates the token: the link in the new email works and the older emailed link stops working, even inside its 72 hours.
Step-by-step: claiming
- Open the onboarding link from the invitation email. The page validates the token and shows the firm you are joining — the company name always, and the firm’s own brand name and accent colour when the firm’s plan includes white-label branding. White-label covers the workspace and this page; the generated Word, PDF and Excel deliverables keep the platform report brand whatever the firm configures.
- Enter your name — first and last. Your email address comes from the invitation and is fixed: it is the identity you sign in with, and there is no separate username.
- Set your password and accept the Terms of Service. The claim records which terms version you accepted; a later version change asks you again at sign-in.
- You are in. Claiming issues a session directly, so you land in the workspace as the role you were invited with — see the workspace tour.
- Enrol MFA if your role requires it. Superadmin and Firm Admin are always mandated; Analyst, Manager and Partner are mandated when the firm’s security settings say so. If you are mandated, the app routes you into TOTP enrolment (scan the QR code or enter the secret, confirm a code) and shows your ten recovery codes once — and until that is done, data-bearing calls are refused. If you are not mandated, enrolment stays optional until the firm turns it on or you switch it on yourself.
The claim is single-use: once your account exists, the onboarding link is spent. Opening it again does not create a second account and does not reset your password — a forgotten password goes through the reset flow instead.
Pending, expired or the wrong link
| Situation | What the page says | What to do |
|---|---|---|
| Invite not yet sent | Nothing arrives | Ask for the invitation; there is no other path in |
| Link already used (you already claimed) | “Invitation has already been accepted” | Sign in normally with your existing account; if you didn’t claim it, tell the Firm Admin — someone else used your invite |
| Link older than 72 hours | “Invitation token has expired” | Ask the Firm Admin to re-issue; the old link never works again |
| Invite withdrawn | “Invitation has been revoked” | Ask for a fresh invitation |
| Firm account closed | “This invitation is no longer valid” | Nothing to fix on your side — the tenancy is gone |
| Email already belongs to an account | “An account with this email already exists” | Sign in to that account; if it is not the role you were promised, that is a team-management change, not a second claim |
| Invited to the wrong firm | The page shows a company or brand name you don’t recognise | Do not complete the claim. Tell the Firm Admin before entering details, and have them revoke and re-issue |
The last row matters: because the page shows the firm’s identity before you type anything, you can confirm you are joining the firm you expect. The role itself is not shown on the claim page — it appears in the workspace header once you are in, and the Firm Admin can correct it without re-inviting you.
After claiming: the first-session checklist
- Confirm the role — the workspace shows what you can do; if it is not the role you were promised, that is a team-management fix, not a sign-out-and-reclaim.
- Keep your recovery codes safe (if you enrolled MFA) — they are the single-use fallback if you lose your authenticator. The MFA guide covers how they work.
- Check the firm’s brand and settings — branded firms show their name and accent throughout the workspace; if yours doesn’t, that is a firm settings configuration (or a plan without white-label), not an error.
- Run a study — the first-study quickstart takes about ten minutes and is the fastest way to confirm your role can do the work you were hired to do.
FAQ
Can I claim an account without an invitation? No. The invitation link is the only creation path; there is no public signup into an existing tenancy. This is the multi-tenant boundary — the firm’s data is reachable only by members the firm invited.
What if I leave the firm? The Firm Admin or a Partner revokes your access in team management; your sessions stop working when they do, and the records you created remain in the tenancy under the audit trail — your name stays attached to the actions you took, which is the point of the governance model.
Do I get a different username than my email? No — your email is the identity. The claim binds your name and password to that email under the invited role; there is no separate username to remember.
Can I sign in with Google instead? Once the account exists, yes: a Google identity can be bound to it, and one identity binds to one account. The claim still has to happen first — Google is a way into an existing account, not a way of creating one. A firm that enforces its own SSO for your email domain routes password sign-in to that provider.
See it working in your workspace
Sign in to run the steps above on a real study — or book a demo and we will walk the workflow end to end.
Related docs
Sign In and MFA: TOTP Setup, Recovery Codes and Rate Limits
Signing into Quartyl by password, Google or firm SSO, with TOTP two-factor where it applies: enrolment, the ten one-time recovery codes, and how mandates resolve per role.
Read docRoles & Permissions: Analyst to Superadmin
The five Quartyl roles — Analyst, Manager, Partner, Firm Admin, Superadmin — what each may do to a study, the MFA mandate, and the plan-feature boundary.
Read doc