What an operator sets
Open the account, go to Settings, and set two things on the Organisation card.1
Set the email address
The Email field on the account. One account per address, ignoring case — a second account
claiming the same address is refused rather than silently shadowing the first.A malformed address is refused as you type it, so an address that saved is an address the portal can
match.
2
Leave the account listed
The Listed checkbox, under Advanced. A sign-in link is only ever issued for an account that
is both matched by address and enabled.
What the deployment needs
The panel must be able to send mail, and must know its own public address, or no link can be issued at all. Where either is missing the customer is told plainly that sign-in by email is not available on this panel and to ask their account manager — an honest refusal rather than a link that never arrives. See the control panel’s configuration.What the customer sees, and what you will not be told
After submitting an address the customer always gets the same answer:If that address is on an account, a sign-in link is on its way. It expires in 15 minutes.
That response is identical whether the address exists, belongs to a disabled account, or has never
been heard of. A form that said “no such account” would let anyone test a list of addresses against
your customer base and learn which of your competitors’ customers are also yours.The consequence for support is worth knowing: the panel cannot confirm to you that a customer’s
address was recognised. If a customer reports no link arriving, check the address on the account
rather than looking for a rejection that was never surfaced.