Feature referenceAccount and security · 02 of 04

Account and security

Registration and sign-in

Stand registration creates an account from an accepted email setup or supported provider flow, while sign-in discovery offers only the methods configured for that account.

Availability
All plans
Configured in
stand.chat registration; app.stand.chat login; Dashboard → Profile → Security & sign-in
Category
Account and security
Reference status
Current

Before you begin

Plan availability: All plans.

Prerequisite: A valid email address, acceptance of the terms during registration, and access to at least one configured sign-in method.

Key boundary: Available buttons are account-specific. Stand does not silently link an email to a different provider identity.

01

Create an account

  • Public registration accepts an email, initial site information where requested, and explicit terms acceptance.
  • Email-based setup sends a link so the recipient can finish creating the account.
  • Google signup can create an account through that provider when enabled.
  • An invited team member uses the invitation’s email and any required-provider rule rather than creating unrelated membership.
02

How sign-in discovers methods

Login begins with the account email. Stand resolves the account’s allowed methods and then presents relevant choices: password, Google, Microsoft work/school when enabled, passkey, or recovery-code fallback where configured. This avoids suggesting a method that cannot authenticate that account.

03

Sign-in methods

MethodWhen shown
PasswordA direct Stand password remains configured and the account is not in a passkey-protected mode that replaces ordinary password login.
GoogleThe provider is linked and allowed for the account or required invitation.
Microsoft work/schoolMicrosoft is enabled and the linked work/school identity is allowed for the account or invitation. Personal Microsoft accounts are not supported.
PasskeyThe account has enabled passkey protection and registered a usable passkey.
Recovery codeA passkey-protected account needs its one-time fallback path.
04

Provider-only accounts and account conversion

A matching email address does not link providers automatically. Complete Connect while signed in to the existing account. Stand does not offer connecting a second provider while another provider is already linked; use the displayed account controls to manage the supported transition.

Account stateAvailable boundary
Direct password accountCan change its Stand password and email where offered; can connect an enabled provider through the explicit connection flow.
Google-only Gmail or Googlemail accountMay be eligible to add a Stand password. Use only the account actions offered in Security & sign-in.
Google Workspace-only accountCannot add an independent Stand password; its email and access remain under the provider.
Microsoft work/school-only accountCannot add an independent Stand password or change its provider-owned email in Stand.
Remove passwordConverts a linked account to provider-only access and removes Stand passkeys and recovery codes. Read the confirmation before losing those fallback methods.
05

Change an email address or password

  • Open Profile → Security & sign-in. The available actions depend on the account’s current sign-in methods.
  • Where Change email is available, enter the new address and current password. Confirm the link sent to the new address; the current email remains active until confirmation.
  • Where Change password or Add password is available, request the email and follow its link to complete the change. The dashboard confirms that the email was sent, not that the password has already changed.
  • A passkey-protected account uses its passkey and recovery controls. Use password login is a separate conversion that removes saved passkeys and recovery codes after confirmation.
  • If an account action asks for a fresh sign-in, reauthenticate, return to Profile, and retry the action.
06

Dashboard session behavior

  • Successful authentication establishes the dashboard session for the current browser.
  • Signing out ends that session.
  • Disabling a member invalidates organization access and signs the member out.
  • Sensitive account changes can require a fresh recent sign-in even when the dashboard session is otherwise valid.
07

Failures and boundaries

  • A temporary identity-service interruption produces maintenance or retry guidance rather than pretending the password is wrong.
  • A provider requirement does not silently attach an existing account to that provider.
  • The email setup link must be used by its intended recipient and can expire or be superseded.
  • Registration creates Stand access; it does not authenticate visitors using the customer’s website chat.