Feature referenceAccount and security · 02 of 04

Account and security

Registration and sign-in

Stand registration creates an account from an accepted email setup or supported provider flow, while sign-in discovery offers only the methods configured for that account.

Availability
All plans
Configured in
stand.chat registration; app.stand.chat login; Dashboard → Profile → Security & sign-in
Category
Account and security
Reference status
Current
01

Create an account

  • Open registration accepts an email, initial site information where requested, and explicit terms acceptance.
  • Email-based setup sends a link so the recipient can finish creating the account.
  • Google signup can create an account through that provider when enabled.
  • An invited team member uses the invitation’s email and any required-provider rule rather than creating unrelated membership.
02

How sign-in discovers methods

Login begins with the account email. Stand resolves the account’s allowed methods and then presents only relevant choices: password, Google, passkey, or recovery-code fallback where configured. This avoids suggesting a method that cannot authenticate that account.

03

Sign-in methods

MethodWhen shown
PasswordA direct Stand password remains configured and the account is not in a passkey-protected mode that replaces ordinary password login.
GoogleThe provider is linked and allowed for the account or required invitation.
PasskeyThe account has enabled passkey protection and registered a usable passkey.
Recovery codeA passkey-protected account needs its one-time fallback path.
04

Dashboard session behavior

  • Successful authentication establishes the dashboard session for the current browser.
  • Signing out ends that session.
  • Disabling a member invalidates organization access and signs the member out.
  • Sensitive account changes can require a fresh recent sign-in even when the dashboard session is otherwise valid.
05

Failures and boundaries

  • A temporary identity-service interruption produces maintenance or retry guidance rather than pretending the password is wrong.
  • A provider requirement does not silently attach an existing account to that provider.
  • The email setup link must be used by its intended recipient and can expire or be superseded.
  • Registration creates Stand access; it does not authenticate visitors using the customer’s website chat.