Reference · Help
Sign in
← All help topics · Open Sign in →
Account · Help
Email, password, and login 2FA (SMS, session approve, or TOTP).
What it does
Primary sign-in uses email + password, then a pending 2FA step. Approve from another signed-in CallsBack.ai session, enter an SMS code, or use TOTP from an authenticator app. A trusted-device cookie can tap Yes on the waiting screen; a new device cannot self-approve. When owner LDAP is enabled, the owner account may use the Google Workspace password; the local portal password and legacy ops PIN remain break-glass. Staff Workspace logins are not opened. This is not Rachel owner TOTP.
Use cases
- Daily portal access for owners and ops users.
- Complete 2FA after password on a new device.
- Approve a new login from an already-open session.
- Emergency unlock with legacy PIN when 2FA device unavailable.
How to
- Enter email and password; submit Continue.
- Forgot password? opens reset flow — same generic message either way.
- On the waiting screen: approve from another session, send SMS, or enter TOTP.
- Trusted devices can tap Yes on that waiting screen.
- After sign-in, portal verifies inbox access before landing Today.
- Use legacy PIN toggle only when directed by admin.
Tips
- Sessions expire after 12 hours — use Lock to end early.
- Login SMS uses the account phone on Users & access (dry-run unless live).
- Google Authenticator label: CallsBack.ai (your email).
- Delete duplicate CallsBack.ai entries after an admin Reset 2FA.
- New users are provisioned under Users & access.