Signing in
Sign in with a password, a passkey, a security key or single sign-on; set up multi-factor authentication; reset a forgotten password; and choose your acting team.
Each organization signs in at its own address: https://<your-org>.vigilfield.com/login.
Sign in
- Go to
vigilfield.com/login. Enter your organization's short name under Organization and select Continue. You land on your organization's own sign-in page. If you already use your organization's address, you skip this step. - Enter your Email Address and select Continue.
- What happens next depends on your email domain:
- If an admin has connected an identity provider for your email domain, Vigilfield sends you to that provider to sign in. You come back signed in. See Single sign-on and SCIM.
- Otherwise, a Password field appears. Enter your password and select Sign In. Select change to go back and use a different email.
- Finish with your second factor:
- If you use an authenticator app, enter the 6-digit Authentication code it shows and select Verify.
- If you use a security key or passkey instead, select Use security key or passkey and follow your browser's prompt.
- If your account has no second factor yet, sign-in stops and asks you to finish setting up your account from the link in your email (see Set your password). No link? Use Forgot your password? to get one.
Multi-factor authentication is required for everyone who signs in with a password. Users who sign in through single sign-on are covered by their identity provider instead.
Signing in on a browser first ends any session that browser already held.
Sign in with a passkey or security key
If you added a passkey or a FIDO2 security key (see Multi-factor authentication), select Use a passkey or security key instead under the password field, then Continue with passkey or security key. Your browser asks you to confirm with your fingerprint, face, device PIN, or the key's PIN. You are not asked for a password or an authenticator code: the passkey counts as both factors on its own.
Forgot your password
- On the sign-in page, select Forgot your password?
- Enter your Organization (if asked) and your Email Address, then select Send Reset Link.
- Open the email and follow the link to set a new password.
The page always says Check your email, whether or not the address has an account. This stops anyone from using the form to find out who has an account.
- The link expires 72 hours after it is sent and works only once. Requesting a new link replaces the old one.
- Federated users (who sign in through single sign-on) and apps never get a link. Federated users recover their access through their identity provider.
- Inactive users do not get a link.
Set your password
You reach this page from a link in an email: after you accept an invitation, after you ask for a reset, or after an admin resets your password.
- Enter a Password and repeat it in Confirm Password.
- Select Set Password.
- If your account has no second factor yet, choose Authenticator app, Security key or Passkey on this device and finish its set-up. You cannot sign in until you do.
Only an emailed link can set up your first factor — your password alone never can. So someone who learns your password before you finish cannot add their own authenticator and lock you out.
The rules:
- At least 12 characters. There are no rules about capitals, digits or symbols.
- Passwords known from public data breaches are refused.
- The link works once and expires after 72 hours. If it has expired, ask for a new one with Forgot your password?, or ask an admin.
Setting a password makes your account Active and signs out every session you had open.
Your profile
Select your name at the bottom of the sidebar to open Profile. It shows your name, email, role, how you sign in (Authentication), your Status, and when you joined. An admin changes your name, role and teams.
The profile also holds Appearance (light, dark, or your system's setting) and, if you sign in with a password, Security.
Acting team
If you belong to more than one team, Acting Team lets you choose which team you act as. Pick a team and select Save. Your choice is remembered in that browser.
What you can see and do comes from all of your teams together, not just the acting team. The acting team is the team each action is recorded under.
Security
Every change here first asks for your current password, and for an authenticator code if you have one. Federated users do not see this section: their identity provider manages passwords and extra factors.
Change your password
Select Change next to Change Password. Enter your current password, then the new one twice. The same rules apply as when you set your password.
Multi-factor authentication
Multi-factor authentication (MFA) means signing in with at least two different kinds of proof, so a stolen password alone is not enough. Vigilfield offers two kinds, and you can use both:
- Authenticator app. After your password, you enter a 6-digit code from an app such as Google Authenticator, Microsoft Authenticator or 1Password. Select Manage, then Set up, and scan the QR code with the app (on a phone, Open in authenticator app does the same). Enter the code the app shows and select Turn on. You can have one authenticator app at a time; Turn off removes it.
- Passkeys and security keys. A passkey lives on your device or in your password manager. A security key is a FIDO2 hardware key, such as a YubiKey. Use one instead of your password, or after it as your second factor. Either way it is unlocked with your fingerprint, face or PIN. Select Manage, then Add passkey or Add security key, and follow your browser's prompts. You can add several (a laptop, a phone and a spare key, for example) and remove any of them.
You cannot remove your last factor; add another one first. Every change asks for your password again.
If a password manager such as LastPass, 1Password or Bitwarden offers to save a passkey when you select Add security key, choose its option to use a security key or another device (or pause it for this site). Vigilfield refuses to record a passkey as a security key.
Passkeys and security keys are the stronger choice: they only work on your organization's real Vigilfield address, so a fake sign-in page cannot capture them. An authenticator code can be typed into a fake page just like a password.
Add more than one method so that losing a phone or a key does not lock you out. If you lose all of them, an admin can reset your multi-factor authentication. You are then emailed a link to set up a new factor.
Sign out
Select the Sign out icon next to your name at the bottom of the sidebar. Signing out ends your session on the server as well as in the browser.
Related API reference: