Sign-in and security
Signing in, Google and Microsoft, two-factor and backup codes, password reset, requiring 2FA, single sign-on through Okta, Entra ID or SAML, and the audit log.
Answered from these docs only, by a model that cannot see your account. Check the pages it cites.
Checked against the product on September 19, 2026
How people get into your Roiva account, and the settings that control it.
Signing in
On the sign-in page, enter your work email and password and choose Sign in, or choose Continue with Google or Continue with Microsoft. Google and Microsoft sign you in when the email on that account matches your Roiva user and they've verified it. A Microsoft work or school account counts as verified only when its organization has proven to Microsoft that it owns the email's domain; otherwise Roiva refuses it, so sign in another way. If the email doesn't match anyone, Roiva takes you to sign up instead. If you were invited, it accepts the invitation.
If your organization uses single sign-on, sign in from its own sign-in page instead (see below). If it has turned off other ways to sign in, a password, Google and Microsoft are all refused and Roiva sends you to that page.
With Remember me for 30 days checked, you stay signed in on that browser for 30 days. Otherwise you're signed out after 12 hours without activity.
Resetting your password
Choose Forgot password? on the sign-in page, enter your work email, and choose Send reset instructions. The link in the email works for 6 hours. Enter a new password twice and choose Update password.
A password needs at least 8 characters, with at least three of: an uppercase letter, a lowercase letter, a number, and a symbol. The same rule applies when you sign up, accept an invitation, or change your password.
Changing your password or email
Profile → Security. Profile is in the menu under your name at the bottom of the sidebar.
- Enter your current password and the new one twice, then choose Update Password.
- Enter a new email address and your current password, then choose Update Email.
Both changes are recorded in the audit log.
Two-factor authentication for yourself
Two-factor adds a six-digit code from an authenticator app (Google Authenticator, 1Password, Authy, or similar) to signing in.
- Open Profile → Security and choose Enable 2FA.
- Scan the QR code with your authenticator app, or type in the secret shown under it.
- Enter the six-digit code the app shows and choose Enable 2FA.
- Save the backup codes Roiva shows you. Each one signs you in once if you lose your authenticator app, and they aren't shown again.
From then on, after your password, Google or Microsoft, Roiva asks for a verification code. Enter the code from your app, or a backup code, and choose Verify and continue. Roiva can't tell whether your Google or Microsoft account has two-factor of its own, so it asks either way.
Signing in through your organization's own single sign-on doesn't ask for the code. Your identity provider's checks apply instead, because your organization sets them.
To manage it later, open Profile → Security and choose Manage 2FA. There you can see how many backup codes you have left, choose Generate new backup codes (which replaces the old ones), or turn two-factor off with Disable 2FA. Both need your current password. You can't turn it off while your organization requires it.
If you've lost both your authenticator app and your backup codes, email success@roiva.ai.
Requiring two-factor, or allowing only single sign-on
Owners and Admins can change these on Organization Settings → Security, then choose Save:
- Require 2FA for all members: anyone who signs in with a password, Google or Microsoft and hasn't set up two-factor is sent to set it up before they can continue, and can't turn it off. Someone who signs in through your own OAuth or SAML provider isn't asked, because your provider's checks apply. That holds in your account only: a person who signed in through another organization's provider and switches into yours is asked to set it up.
- Allow sign-in with a password, Google or Microsoft: unchecking it means your team signs in only through your own OAuth or SAML provider. A password, Google or Microsoft is refused and the person is sent to your account's sign-in page, which then shows only your providers. People you invite accept by signing in through your provider. You can't uncheck it until an OAuth or SAML provider is enabled, so nobody gets locked out.
Every change here is recorded in the audit log.
Single sign-on
Single sign-on comes with larger rollouts (the Scale and Enterprise plans on your Billing page), where Owners and Admins can let your team sign in through your identity provider. On other plans these pages are grayed out and say what includes them.
- Organization Settings → OAuth Providers: choose Add Okta or Add Microsoft Entra ID. Register the redirect URI shown on the form with your provider, enter the client ID and client secret (plus your Okta domain, or your Entra Directory (tenant) ID, the GUID on your app registration's overview), and choose Add Provider.
- Organization Settings → SAML Providers: choose Add Provider, then Okta, Microsoft Entra ID, OneLogin, Auth0 or Ping Identity. Paste your provider's metadata URL or XML and choose Import metadata to fill in the form, or enter the details yourself. Give your provider the ACS URL shown on the form, then choose Add Provider.
A provider shows as a sign-in option only while Enabled for sign-in is checked. To change or remove one, use the menu on its row.
Your provider signs in only people who belong to your Roiva account. Someone it vouches for who isn't a member is refused and told to ask an admin for an invitation. Someone with an invitation to your account joins when they first sign in through it.
SSO buttons appear only on your account's own sign-in page, not the standard one, because the standard page can't tell which account you belong to. Once a provider is enabled, Organization Settings → OAuth Providers, Organization Settings → SAML Providers and Organization Settings → Security show that page's address to share with your team, with a Copy button.
The audit log
On the Growth plan and above, Owners and Admins can see Organization Settings → Audit Log. It records who did what and when, including:
- Sign-ins, failed sign-ins and sign-outs, password and email changes, and changes to Organization Settings → Security.
- Invitations, role changes and people removed.
- Initiatives created and deleted, stage changes, and value approvals.
- Connections added, disconnected or given new credentials.
- Data exports, and MCP tokens issued, revoked and used.
Search it by action or record type, and choose Export to download what you're looking at as CSV or Excel.
Related
- Inviting your team covers roles and who can open Organization Settings.
- Your data: exports and deletion covers deleting your own user from Profile → Security.
- What Roiva keeps from each platform lists what each connection syncs and stores, and for how long.