There is no self-service sign-up. You enter SAQ through an invitation from a workspace Owner or Admin, or, as a client user, through a login link sent to the address a workspace user registered for you. This page covers the first login and the rules that apply afterwards.
Accept an invitation
An invitation is emailed and is valid for 7 days. One live invitation exists per address; an expired one has to be sent again.
- Open the link in the invitation email. The page shows the workspace and the role you were invited as.
- If you have no SAQ account yet, fill in Name and New password (the email is fixed) and select Create account and join.
- If you already have an account, log in and select Join the workspace. If you are logged in with a different address, select Log out and log in with the invited one.
The page tells you when a link is no longer valid: "This invitation has expired", "This invitation has already been used", or "This invitation was withdrawn".
Login methods
The login page is identity-first: enter your Email and select Continue, and SAQ shows the methods that apply to that address.
| Method | Who | Notes |
|---|---|---|
| Password | Anyone with a password | At least 8 characters. Length matters more than symbols; passwords seen in known breaches are refused. |
| Passkey | Anyone who added one under Account → Security | Log in with a passkey is on the first step. A passkey counts as a second factor. |
| Magic link | Client users who have no password or passkey yet | Email me a link instead. The link is valid for 15 minutes and can be used once. |
| Single sign-on | Workspaces with an active OpenID Connect connection | Continue with {workspace} SSO. |
The Email me a link instead option is always shown, but a link is only sent to an address that can use one. Workspace users need a password, a passkey, or single sign-on; once anyone sets a password or adds a passkey, their magic links stop working.
Two-factor authentication
Owners and Admins must have two-factor authentication before they can enter a workspace: either an authenticator app (TOTP) or a passkey. If you log in as an Owner or Admin without it, SAQ sends you to Account → Security with the message "Owners and admins must use two-factor authentication. Enable it below to enter the workspace." Members and client users are not required to enrol, but it is recommended.
With TOTP enabled, every password login asks for the six-digit code from your authenticator app. If you lose the app, select Use a recovery code; each recovery code works once. Save the codes when you enrol, and generate new ones under Account → Security when you run low.
A workspace with single sign-on can accept the identity provider's own MFA through an assurance rule; otherwise Owners and Admins still need local two-factor after signing in through SSO.
Forgot password
Select Forgot password? on the password step. The reply is always "If {email} has an account, a password reset link is on its way." Setting a new password logs out your other sessions.
What a full login is
A full login is a session started with a password, a passkey, or single sign-on. A magic-link session is not a full login. This matters for client users: elevation on a project, the billing contact flag, API tokens, and account deletion all work only in a full-login session. A client user gets a full login by setting a password under Account → Security (the page says "This account has no password yet; set one to get a full login.") or by adding a passkey. See Client user.
Forced single sign-on
When your email domain is forced to single sign-on in the workspace you are trying to enter, the login page sends you straight to the identity provider after you enter your email. If you are already logged in with a password, entering that workspace redirects you to its SSO login instead. Domains are forced by an Owner or Admin under Authentication; see Single sign-on.
Choose a workspace
After login, SAQ opens the workspace you used last. If you belong to several, the Choose a workspace page lists them; it is also reachable through All workspaces in the sidebar's workspace switcher. If the list is empty you see "You are not a member of any workspace yet. Ask a workspace owner or admin for an invitation."
Read-only banner
A banner on every page saying "This workspace is read-only" means the subscription has lapsed or the workspace is pending deletion. Everyone can still read and export; only an Owner can restore it under Settings → Organization. See Plan and subscription.
Common problems
- "This session was not verified with a second factor. Log in again to enter the workspace." You have two-factor enabled but this session was started without it, for example with a magic link. Select Log in again.
- The email never arrives. Sign-in links and invitations come from
no-reply@saq.no. Check the junk folder, and ask whoever runs your mail to allow that address. The address itself is unattended; a reply reaches SAQ support instead. - "That login link is invalid or has expired. Request a new one." Magic links expire after 15 minutes and work once.
- "The passkey prompt was cancelled or no passkey matched." Try again, or continue with your password.
- "There is no account for this address, and this workspace does not create accounts on first login." The workspace's SSO connection does not provision new accounts. Ask an Admin for an invitation.