TeamFor administrators

Sign-in and access

Your team signs in with an email link, with Google or with Microsoft. You can require Google or Microsoft and restrict invitations to your domain.

Custodos has no passwords. People sign in with a link sent by email, or with their Google or Microsoft account. As an admin, you decide under Settings in the Access section whether email links stay allowed and which addresses can be invited.

How people sign in

MethodHow it works
Email linkEnter the Work email and click Continue with email. Custodos sends a sign-in link that works only once.
GoogleClick Continue with Google and sign in with your Google account.
MicrosoftClick Continue with Microsoft and sign in with your Microsoft work account.

An invitation can only be accepted with the invited email address, whichever method the person signs in with.

Moving from an email link to Microsoft

Someone who first signed in with an email link can later use Continue with Google with the same address. With Microsoft this is not possible, for security reasons: sign-in reports that the email address is already registered with a different sign-in method. If your team works with Microsoft 365, ask everyone to use Continue with Microsoft from their very first sign-in. If it has already happened, write to us at [email protected].

Requiring SSO

With Require SSO on, all members must sign in with Google or Microsoft. Email links then no longer work for this workspace.

Sign in with Google or Microsoft yourself

Sign in at least once with Continue with Google or Continue with Microsoft. Until you have, the setting cannot be switched on, so that you do not lock yourself out.

Open Access

In the sidebar under Workspace, click Settings and scroll to the Access section.

The “Access” section with the “Require SSO” switch, the “Restrict invitations to domain” field and the “Activity log” row.

Turn the switch on

Turn Require SSO on. The switch saves immediately.

What your team sees afterwards:

  • People who sign in with Google or Microsoft work as usual.
  • People who have only used email links so far see the notice Sign in with SSO and the Sign out button when they open the workspace. After signing out, they sign in again with Google or Microsoft.
  • Anyone trying to accept an invitation with an email link is told to sign in with Google or Microsoft first. The invitation link remains valid.
The “Sign in with SSO” screen: Kieselmatt Treuhand AG requires Google or Microsoft sign-in, with the “Sign out” button.

If you turn Require SSO off again, email links work again straight away.

Require SSO checks that a person signs in with Google or Microsoft. Which addresses get into the workspace at all is decided by your invitations and the domain restriction.

Restricting invitations to your domain

Enter the domain

In the Access section, enter your domain without the @ in the field Restrict invitations to domain, for example kieselmatt-treuhand.ch.

Save

Click Save.

From now on, only addresses ending in @kieselmatt-treuhand.ch can be invited. For any other address, the invitation form reports that invites are restricted to this domain.

  • Exactly one domain applies. Addresses at a subdomain such as @mail.kieselmatt-treuhand.ch do not count.
  • The restriction applies to new invitations. Existing members and invitations already sent are not affected.
  • An empty field removes the restriction.

Both settings appear in the activity log as "Access changed".

Best practices

  • If your company uses Google Workspace or Microsoft 365, require SSO. Announce it first and ask everyone to sign in once with Google or Microsoft.
  • Enter the domain before you invite the team, so that no invitation goes to a private address.
  • Keep at least two admins who sign in with Google or Microsoft.
  • Remove people who leave the company under Members. Blocking their company account alone does not automatically end an existing Custodos sign-in.

Frequently asked questions

Next steps

The Quickstart shows members how to sign in for the first time. Share the link with your team.

On this page