Skip to content
Search docs⌘K

    Access and notification issues

    Keep sign-in, role, data scope, and notification channel separate. Correcting one layer does not correct the other three.

    A new employee did not receive the invitation or cannot activate their account

    Check first
    1. The profile email is correct and belongs to the recipient.
    2. HR saw the invitation success message on that profile.
    3. The recipient checked spam and is opening the newest invitation.
    4. The Account tab says Waiting for the employee to set up their account, The link expired before the employee set up their account, or shows an already-active account.
    5. The displayed Expires time has not passed.
    Fix it

    For a missing pending email or an expired link, HR selects Resend link. Rifena invalidates every older unconsumed link, sends a fresh one, and starts a new seven-day expiry. The recipient uses only the newest email, sets a password, and signs in. If the person should no longer activate the account, HR selects Revoke link and confirms, stopping every unconsumed link. Never forward an invitation to another person.

    Expected result: a resend shows a new expiry; revocation stops every unused link; successful activation lets the employee sign in to the correct organisation.

    Still not working? Prepare a partially masked email, latest send time, and activation-page message. Never send the password or complete activation link.

    The password cannot be changed, or an authentication method remains off

    Check first
    1. The current password is correct and the new one is different.
    2. The new password has at least 12 characters, including uppercase, lowercase, and numbers.
    3. Confirmation matches the new password exactly.
    4. For email code or Authenticator, the six-digit code was entered and verified.
    Fix it

    Read the first attempt's message. If Rifena identifies a common password, choose a different, harder-to-guess one. Receiving an email does not enable email verification; complete Verify email. Dismiss recovery codes only after storing the one-time display.

    Expected result: Rifena confirms the password change, or the authentication method becomes On.

    Still not working? Send the method name, state, and error message. Never send passwords, six-digit codes, QR codes, setup keys, or recovery codes.

    I can sign in, but the menu or action I need is missing

    Check first
    1. The correct organisation is selected.
    2. An active role contains the required action.
    3. The direct, group, or position assignment remains valid.
    4. The record state permits the action.
    Fix it

    An administrator opens System → Settings → Roles & Permissions, checks the role permission and every active Assignment, then corrects only the missing permission or scope. Verify with the user's account. Do not grant a broad administrator role merely to reveal one button.

    Expected result: the user sees the function required for their job without gaining data outside the intended scope.

    Still not working? Note the menu or action, role, scope, and state of the open record.

    The user sees too little or too much data for the assigned scope

    Check first
    1. The scope is Organization-wide, By group, or Self only.
    2. Include subtree is on or off as intended.
    3. No other direct, group, or position assignment grants similar access.
    4. The screen filter is not narrowing the result.
    Fix it

    Review every active assignment, not only the one just changed. Correct the scope, save, then test one in-scope and one out-of-scope record with a representative account. When too much data is visible, stop further access before continuing.

    Expected result: the user opens required data and is blocked from data outside the scope.

    Still not working? Send the role, assignment source, group, child-group option, and two de-identified examples.

    SSO is Configured, but users still cannot sign in with SSO

    Check first
    1. The provider is only Configured, or has become Active.
    2. Identity details, domains, and provider configuration match the organisation.
    3. A real test account succeeded before Enforce SSO was considered.
    Fix it

    Read the provider warning and complete the conditions required for Active. Test with a prepared account. Turn on enforced SSO only after the test returns to the correct organisation and a safe administrative recovery path remains.

    Expected result: the provider is Active and the test user returns to the intended organisation after sign-in.

    Still not working? Send the provider name, state, test time, and error message. Never send secrets, tokens, session data, or cookies.

    A push or email notification did not arrive

    Check first
    1. Open Account → Notifications and find the exact notification type.
    2. It is Receiving through the intended channel.
    3. The browser or device allows push notifications.
    4. The source event genuinely reached a state that produces the notification.
    Fix it

    Select In-app, Push, Email, or Push + Email, resume a paused type, and wait for the saved confirmation. For push, allow the correct browser. Then use a safe test event or wait for the next genuine event.

    Expected result: the preference saves and the next notification arrives through the selected channel; old history remains in Notification Center.

    Still not working? Send the notification type, channel, browser-permission state, and event time without sensitive notification content.

    See Roles, access, and account security for the full grant and verification journey.