Who has an account
Client users, arbitrators and the administrator’s staff have named accounts and sign in at /sign-in. Accounts are created by invitation: you get an email (the link lasts 7 days), set your password and turn on two-step verification. You can also sign in with a passkey once you have added one.
Respondents do not have accounts. They sign in to their case with an Access ID, a case link and one-time codes: see Using the respondent portal.
Passwords
- 12 to 128 characters. Long passphrases are welcome; there are no rules about symbols or capitals.
- Common passwords, passwords made of one repeated character, and passwords that contain your email name are refused.
- New passwords are checked against lists of passwords exposed in known data breaches, without the password itself leaving the platform.
- Passwords are stored only as a slow, salted hash (Argon2id). Nobody, including our staff, can read your password.
If your organisation allows it, you can sign in with your Google work account instead, limited to your organisation’s domain.
Two-step verification
Every account uses a second step after the password. Choose one or more:
| Method | How it works |
|---|---|
| Passkey | Your phone or computer’s screen lock (fingerprint, face or device PIN). The strongest choice: a passkey sign-in counts as both steps. |
| Authenticator app | A 6-digit code from an app such as Google Authenticator or Microsoft Authenticator. Each code works once. |
| Email code | A one-time code to your account email. |
| WhatsApp code | A one-time code to your registered mobile, where your organisation has it turned on. Not available to administrators or arbitrators. |
| Recovery codes | 10 single-use codes, shown once when you set up two-step verification. Print them or keep them in a password manager. |
Administrators and arbitrators confirm the second step at every sign-in. Other users can choose “Remember this device” for 30 days.
Sign-in from a new device or country, or after several failed attempts, always asks for the second step. Sign-ins that look impossible, such as from two distant places minutes apart, are blocked.
Confirming important actions
Some actions ask you to confirm your second step again, even on a remembered device, if you have not done so in the last 5 minutes. Examples: changing your email, authorising or recording a settlement, withdrawing a claim, an interim decision, closing a case, signing an award and setting the challenge period.
Sessions
By default you are signed out after 30 minutes without activity and after 12 hours in all. Your organisation’s administrator may set shorter limits. You can see your signed-in devices and sign any of them out under Settings → Security.
New-device emails and “This wasn’t me”
When you sign in from a device we have not seen in the last 90 days, we email you. If it was not you, use the This wasn’t me link in that email (it works once, for 7 days). It signs your account out everywhere, stops password sign-in, and emails you how to set a new password.
Lost access
- Forgot your password: choose “Forgot password?” on the sign-in page.
- Lost your phone or authenticator: sign in with a recovery code, then set up a new method and print new codes.
- No recovery codes left: ask your organisation’s administrator to reset your second step. They will check who you are first.
Nobody from the platform will ask for your password, a sign-in code or a recovery code, by phone, email or WhatsApp.