Your account
Two different things get called "your account", and keeping them apart saves a lot of confusion:
- Your login — your email address and password. Personal to you.
- Your organization — the sites, the billing, and the people who can see them. Shared.
Changing something about your login does not change who has access to the organization. That distinction is the reason for the section on handovers below, which is the part most likely to bite.
Changing your password
From Account settings (click your email at the bottom of the sidebar) → Change password. If you cannot sign in at all, use Forgot your password? on the sign-in screen instead.
You will be asked for your current password. That is what stops someone who has got hold of an open session — a laptop left unlocked, a borrowed machine — from changing your password and locking you out of your own account. You are not asked for it when you arrive from a reset link, because you would not know it; the link itself is the proof.
Two rules apply to the new password:
- At least 8 characters.
- It cannot be a password that has appeared in a known data breach. We check against the public Have I Been Pwned database, and if yours is on that list you will be asked to choose another. Your password is never sent anywhere to do this — only a short fragment of its fingerprint leaves our systems, which is enough to check the list without revealing what you typed. If you see this, the password is not "bad"; it has simply appeared in someone else's breach and is now in the lists attackers try first.
Changing your password signs out your other devices. This is deliberate, not a side effect. If you are changing it because you think someone else has access, a password change that left their session alive would achieve nothing.
The practical consequence: You will need to sign in again on your phone, your other laptop, and anywhere else you were signed in. You will also get an email telling you the password changed — if one ever arrives that you did not expect, treat it as a warning and reset immediately.
Changing your email address
From Account settings → enter the new address → Send confirmation.
You will receive two emails, and both links must be clicked. One goes to your current address, one to the new one. The change completes when the second is clicked; the order does not matter.
This is not a mistake or a duplicate. Anyone who gets hold of a signed-in session — a laptop left unlocked, a borrowed machine, a stolen session — could otherwise move your account to an address they control, then use password recovery to lock you out permanently. Requiring the current address means that cannot happen without access to your existing inbox, and it means you get told when someone tries.
Two things follow from that:
- If an email arrives asking you to confirm a change you did not request, do not click it. Sign in and change your password instead. That email is the warning, not a formality.
- Until both are confirmed, you keep signing in with your old address. Account settings shows a "change pending" notice for as long as that is true.
If nothing arrives, wait a full minute before requesting again — there is a 60-second minimum between emails to the same person, and a faster retry is silently discarded.
Handing an account to someone else
This is the section to read before an agency hands a site to a client, or before someone leaves.
In almost every case, transfer the Owner role — do not hand over a login.
From Organization → Transfer ownership, choose a member and confirm. They become the Owner and take over billing; you become an Admin, so you keep access but not control. Two things to know before you start:
- The recipient must already be a member. Invite them first. Ownership is never granted to an address that was never in the organization.
- You cannot reverse it yourself. Once it lands, only the new Owner can transfer it back. That is why the dialog asks you to type their email.
A client viewer cannot be made Owner. Change their role first if that is genuinely what you want.
If you are handing over the login itself
Sometimes there is no second person to transfer to — a sole trader selling a business, for instance. Then you are transferring the login, and this applies:
Changing the email address is not a transfer of ownership.
An email change leaves the password untouched. Whoever knew the old password still knows it, can still sign in, and can change the email address straight back.
The failure here is quiet, which is what makes it dangerous: The handover looks finished. The new person receives the confirmation, the address updates, the dashboard shows their email — and the previous owner retains complete access with nothing on screen to suggest it.
To genuinely transfer a login, do both:
- Change the email address to the new person's (both confirmations).
- Have them reset the password from Forgot your password?
Step 2 is the one that matters. It is not tidying up — the password reset is what revokes the previous owner's active sessions. Until it happens, the transfer is cosmetic.
Sharing credentials is a poor fit for a handover in any case. If the goal is "my client needs access to their own site", give them their own login and transfer the Owner role instead.
Adding people to your organization
From Organization → invite by email address and choose a role.
The invite is a link you copy and send them yourself. We do not email invitations at the moment. If you are waiting for an invite email to arrive, that is why — check the Organization page for the link.
Roles:
| Role | Can do |
|---|---|
| Owner | Everything, including billing |
| Admin | Everything except transferring ownership |
| Member | Day-to-day work on sites |
| Client viewer | Read-only — reports and scan results |
Only the current Owner can transfer the Owner role, and only to someone who is already a member — see Handing an account to someone else.
If you cannot sign in
- Forgot the password → Forgot your password? on the sign-in screen.
- Would rather not use a password → Email me a magic link instead signs you in from a link, no password needed.
- A confirmation link failed → the sign-in screen explains which of the three causes applies, because the fixes are different: Request a new link, open it in the browser you started in, or try again.
If you no longer control the email address on the account, you are locked out and self-service cannot help — every recovery route sends a link to that address. Contact us rather than creating a second account: a new account will not have your sites, your published configuration, or your consent records.
What we email you
Only account emails: Confirming a new account, signing in by magic link,
resetting a password, and confirming an email change. They come from
noreply@sys.consentinel.co.
We do not currently send scan results, alerts, or marketing to that address.
If you receive something claiming to be from us that asks you to sign in
somewhere else, treat it as suspicious — every genuine link points at
app.consentinel.co.