Signing in
How to sign in to FSMCore, which address each role uses, what to do when you forget your password, and how two-factor sign-in works.
What it is for
Every company has its own web address, for example yourcompany.fsmcore.com. You always sign in on your company's address, never on the bare fsmcore.com. If you do not know your company's address, see Find your company.
FSMCore has three areas. Each has its own sign-in page:
- The office, at
/admin. - The crew app, at
/app. - The books, at
/books.
Nobody else knows your password. An owner or admin cannot set, see or change it. You choose it yourself from an invitation link, and you recover it yourself with Forgot password?.
Who can use it
Everyone who is a member of the company and is not archived can sign in. Which area you can enter depends on your role. See Roles.
| Role | Signs in at |
|---|---|
| Owner | The office (/admin) and the books (/books) |
| Admin | The office (/admin) and the books (/books) |
| Supervisor | The office (/admin) |
| Crew | The crew app (/app) |
| Accountant | The books (/books) |
An admin can do everything an owner can.
A person with several roles can enter every area one of their roles allows. A person who is archived cannot enter any area of that company.
Where to sign in
Use your company's address followed by the area:
yourcompany.fsmcore.com/adminfor owners, admins and supervisors.yourcompany.fsmcore.com/appfor crew.yourcompany.fsmcore.com/booksfor accountants. Owners and admins can open it too, to see what the accountant sees.
If you open your company's address with nothing after it:
- Not signed in: you get the office sign-in page.
- Signed in as owner, admin or supervisor: you go to the office.
- Signed in as crew: you go to the crew app.
- Signed in with only the Accountant role: you go to the books.
- Signed in with no role in this company: you get a refusal page.
An accountant who is not signed in yet should use the /books address: the plain address shows the office sign-in page.
The bare fsmcore.com has no sign-in page for any area. If you open fsmcore.com/admin, fsmcore.com/app or fsmcore.com/books, you are sent to Sign in to your company. The same happens on a web address that is no company, for example after a typing mistake. fsmcore.com with nothing after it opens the signup page.
If you work for two companies on FSMCore, you sign in at each company's address separately. There you see only that company.
Find your company
Use this when you do not know or do not remember your company's web address.
- Open
fsmcore.com/login. The page is headed Sign in to your company. - Type your Email address.
- Press Email me my links.
- The page says: "If that email belongs to a FSMCore account, we have emailed you a link to each of your companies."
- Open the email Your FSMCore sign-in links. It lists every company you belong to, each with a link to its sign-in page.
- Press the link of the company you want and sign in there with your email and password.
What to know:
- The page says the same thing for every email, so nobody can use it to find out who has an account. An email is only sent when the address belongs to an account.
- The email lists only companies where you are a member and not archived.
- Each link opens the sign-in page for your role in that company: the office, the crew app or the books.
- The email does not sign you in and does not change your password. If you did not ask for it, ignore it.
- At most 3 emails an hour go to one address. After 10 tries in an hour from one connection the page says "Too many tries. Wait an hour and try again."
- The page also says: "Know your company address? Go to yourcompany.fsmcore.com". Type your own company's address in the browser instead.
Sign in at the top of the help pages (and of the legal pages) takes you back to your company when you opened them from inside FSMCore. If the page does not know your company, it opens Sign in to your company.
Sign in
- Open your area's address. The page is headed Sign in.
- Type your Email address and Password.
- Tick Remember me if you want this browser to keep you signed in.
- Press Sign in.
- If you have two-factor on, the page asks you to verify. See Sign in with two-factor.
Where you land:
- In the office you always land on the Dashboard, even if you opened a link to another page before signing in.
- In the crew app and the books you go to the page you were trying to open, or to the home of that area.
The logo at the top of the sign-in page is a link to the home of that area.
If you do nothing for 120 minutes you are signed out and must sign in again, unless you ticked Remember me.
Forgotten password
Forgot password? is on the sign-in page of all three areas: the office, the crew app and the books.
- On the sign-in page press Forgot password?.
- Type your Email address and press Send email. back to login takes you back.
- You see the notice "We have emailed your password reset link." with the line "If your account doesn't exist, you will not receive the email." under it. Every email address gets this same notice, so the page never tells anyone which emails have an account. The email only arrives if the address belongs to a person who can use this area of this company.
- Open the email. Its subject is "Reset your password for" followed by your company's name.
- Press Reset your password in the email.
- On the Reset your password page type the new Password and Confirm password, then press Reset password. The password needs at least 8 characters, including a letter and a number.
The email says "We received a request to reset the password on your account." The link in the email expires in 60 minutes. You can ask for a new email once a minute: if you ask again sooner, no second email is sent, and the notice is the same. If you did not ask for the email, ignore it. Your password does not change.
The email shows your company's Trading name from Settings > Company (Identity), or the Legal name when there is no trading name. The legal name is what your documents print.
Resetting your password this way also marks you as active if you had an invitation you never used. The unused invitation link stops working.
Two-factor sign-in
Two-factor sign-in asks for a second proof after your password. FSMCore offers two methods:
- Authenticator app: a 6-digit code from an app on your phone, with recovery codes as a backup.
- Email verification codes: a 6-digit code sent to your email address.
You can turn on one or both.
Who must use it:
- Owners and admins must have two-factor on to use the office and the books of their company.
- Supervisors, crew and accountants may turn it on if they want. It is optional in the crew app for everyone.
Two-factor belongs to you as a person. If you work for more than one company on FSMCore, one set-up covers all of them.
Set up two-factor
If you are an owner or admin and have no two-factor yet, every page of the office and the books sends you to the page Set up two-factor authentication until it is on. You are not locked out. You only need to finish the set-up.
- On that page pick a method and press Set up.
- Follow the steps for the method (below).
- Press Continue. You go on to the page you were trying to open.
The logo at the top of this page is a link to the dashboard.
Everyone else sets it up from Password and two-factor in the account menu. See Password and two-factor.
Authenticator app
You need an authenticator app on your phone, for example Google Authenticator.
- Beside Authenticator app press Set up. The window Set up authenticator app opens.
- Scan the QR code with your app. Or type the code under Or enter this code manually: into the app. The app lists the account as FSMCore.
- Type the code from the app into Enter the 6-digit code from the authenticator app.
- Type your Current password and go to the next step.
- Save the recovery codes shown in the window. You can copy or download them all at once. They are shown only once.
- Press Enable authenticator app. You see "Authenticator app has been enabled".
Email verification codes
- Beside Email verification codes press Set up. The window Set up email verification codes opens and a code is emailed to you.
- Type it into Enter the 6-digit code we sent you by email. The email's subject is "Here's your sign-in code". If it did not arrive, press Send a new code by email.
- Press Enable email verification codes. You see "Email verification codes have been enabled".
An emailed code is good for 4 minutes.
Sign in with two-factor
After your email and password the sign-in page shows Verify your identity.
- If you have both methods on, choose under How would you like to verify?: Use a code from your authenticator app or Send a code to your email.
- Type the 6-digit code.
- Press Confirm sign in.
With the authenticator app you can press Use a recovery code instead and type one of your recovery codes into Or, enter a recovery code.
With email codes you can press Send a new code by email.
Recovery codes
Recovery codes are the backup for the authenticator app. Use one when you do not have your phone.
- You get 8 codes when you set up the authenticator app.
- They are shown once. Keep them somewhere safe, not on the same phone.
- Each code works once.
To get new codes:
- Open Password and two-factor in the account menu.
- Beside Authenticator app press Regenerate recovery codes.
- In the window Regenerate authenticator app recovery codes type the current 6-digit code from the app and your password in Enter your current password. Then press Regenerate recovery codes.
- Save the new codes from the window New recovery codes, then press Close.
The old codes stop working at once.
Password and two-factor
This page is in the account menu (your name, top right) in all three areas. It has two parts: a form to change your password, and the section Two-factor authentication (2FA).
The section lists Authenticator app and Email verification codes. Each shows Enabled or Disabled, with Set up or Turn off.
Your name and email address are not on this page. An owner or admin changes those in Settings > Users.
Change your password
- Open the account menu and press Password and two-factor.
- Type the New password. It needs at least 8 characters, including a letter and a number.
- Type it again in Confirm new password.
- Type your Current password.
- Press Save changes. You see "Saved" and stay signed in.
You cannot set a new password here without the current one. If you do not know it, sign out and use Forgot password?.
Turn off two-factor
- Open Password and two-factor.
- Beside the method press Turn off.
- For the authenticator app: type your Current password. Then type the current 6-digit code, or press Use a recovery code instead. Then press Disable authenticator app.
- For email codes: type the code sent to your email, then press Disable email verification codes.
If you are an owner or admin and turn off your only method, the next page sends you to the set-up page again.
Reset another person's two-factor
Use this when someone has a new phone, lost their phone, or has no recovery codes left.
Who can do it: owners and admins of the company. You can reset anyone in your company, owners included. You cannot reset your own here.
- Open Settings > Users.
- Open the ⋮ menu on the person's row and press Reset two-factor. The same action is in the ⋮ menu at the top of the person's record page and edit page.
- Read the window Reset two-factor for the person. It says what will happen.
- Press Reset two-factor. You see "Two-factor reset".
What it does:
- It turns off the person's authenticator app code, recovery codes and email codes.
- An owner or admin is sent to the set-up page at their next page and must set it up again.
- Anyone else signs in with only their password from then on. They can turn two-factor on again from Password and two-factor.
- If the person belongs to other companies on FSMCore, their sign-in there changes too. The window says so.
- The person gets a bell message titled Two-factor sign-in reset and an email with the subject "Your two-factor sign-in was reset". Both say "Your two-factor sign-in was reset by" followed by your name, and "Set it up again at your next sign-in." The email adds: "If you did not expect this, contact" your company "straight away." The email is sent even when the company's email notifications are switched off.
- FSMCore keeps a record of who reset whose two-factor.
The action is greyed out when the person has no two-factor. The tooltip says "No two-factor set up, nothing to reset."
Failed sign-in alerts
When one account collects 10 failed sign-ins within 15 minutes, the owners and admins of the company get a bell message titled Many failed sign-ins. It names the email address, the count and the last IP address, and says: "If this was not them, ask them to change their password and turn on two-factor."
The alert is sent at most once an hour for the same account. It is only sent for an email address that belongs to an account. Wrong tries with an unknown address alert nobody.
The alert goes to the owners and admins of the company whose address was used for the tries, when the account belongs to that company. Otherwise it goes to the owners and admins of every company where the person is a member and not archived.
The count is per account, from any internet connection. It is separate from the "Too many login attempts" message, which stops one connection after too many tries in a minute (see Common mistakes).
FSMCore keeps a record of every failed sign-in with the email address typed and the IP address. The password typed is never recorded.
Account menu
Press your photo or initials at the top right. The menu shows, from top to bottom:
- Your name. It is a label, not a link.
- The theme switcher: light, dark or follow your device.
- Switch to Office, Switch to Crew app, Switch to Books: only the other areas your roles allow. See Switching between the office, the crew app and the books.
- Profile photo: your own photo. See Profile photo.
- Help: opens these help pages in a new tab.
- Password and two-factor.
- Sign out.
There is also a Help link at the foot of every page.
Most pages also have a small grey question mark beside the page title. Many boxes, lists, dashboard cards and windows have one too, at the right of their heading. Point at it to see what it is for ("Help: Bill to"); press it to open the help section about that page or box in a new tab. The question marks are not printed.
The office and the crew app also have a bell beside the menu for messages. The books has no bell.
The office and the crew app use amber as their colour. The books use slate grey, so you can tell at a glance which area you are in.
Profile photo
Profile photo in the account menu opens a page with your photo, or your initials when you have none. It is in the office, the crew app and the books. Your photo shows in the account menu and beside your name on the People list, in every company you work for.
- Press Upload photo (Change photo when you have one). A window opens.
- Pick a JPG, PNG or WebP picture of up to 20 MB.
- Press Save photo. You see "Profile photo saved".
The picture is cut to a square from the middle and saved at 512 by 512 pixels. A new photo replaces the old one. Remove photo asks first, then removes it; your initials show again.
An owner or admin of your company can also change or remove your photo, from your record in People. See Profile photo.
Switching between the office, the crew app and the books
One person has one account. Someone who works in the office and on site holds both roles on the same account, for example Supervisor and Crew. They do not need a second account or a second browser.
You sign in once on your company's address. That one sign-in covers every area your roles allow.
- Press your name at the top right.
- Press Switch to Office, Switch to Crew app or Switch to Books.
- The home of that area opens in the same tab. You are not asked to sign in again.
What to know:
- The menu lists only the areas your roles allow in this company. See the table in Who can use it.
- The area you are in is never listed.
- A person with one area only, for example crew with no office role, sees no Switch to entry.
- It works the same on a phone.
- If your company changed the word for Crew in Settings > Wording, the entry uses that word, for example Switch to Team app.
- Owners and admins must have two-factor on for the office and the books. If it is not set up yet, switching there opens the set-up page first.
- To give a person a second area, an owner or admin adds the role in Settings > Users. See Roles.
What happens after
- Signing in takes you to the home of that area on your company's address.
- A password changed on Password and two-factor, or reset through Forgot password?, marks you as Active in the company's Users list.
- A two-factor reset sends the person a bell message and an email and is recorded.
- Ten failed sign-ins in 15 minutes on one account send a bell message to owners and admins.
Common mistakes
- "These credentials do not match our records." The email or password is wrong. Check for typing mistakes, or use Forgot password?.
- "Too many login attempts". You tried more than 5 times in a minute. The message says how many seconds to wait.
- "Too many attempts. Please try again later." You typed a wrong password or code too many times in a two-factor window. Wait a little and try again.
- You cannot get into an area after signing in. Your role does not reach that area, you are on another company's address, or you are archived in this company. Use the address for your role (see the table above), or ask an owner or admin to check your roles in Settings > Users.
- No reset email arrives. The email is only sent when the address belongs to an account. Check the spelling and your spam folder, and wait a minute before asking again.
- The reset link does not work. It expires after 60 minutes. Ask for a new one.
- "The code you entered is invalid." The 6-digit code is wrong or too old. Type the current code from the app, or ask for a new email code.
- "The recovery code you entered is invalid." That code was already used or was replaced by new codes.
- "Too many resend attempts. Please wait before requesting another code." Wait a little before pressing Send a new code by email again.
- You do not know your company's address, or you see "Sign in to your company" instead of a password field. You are on the bare
fsmcore.com. Type your email there and use the link in the email. See Find your company. - No "Your FSMCore sign-in links" email arrives. It is only sent when the address belongs to an account with at least one company where you are not archived. Check the spelling and your spam folder. Only 3 are sent to one address in an hour.
- You lost your phone and have no recovery codes. Ask an owner or admin of your company to use Reset two-factor.
- "Two-factor not reset" with one of these reasons:
- "Only an owner or admin of this company can reset two-factor."
- "You cannot reset your own two-factor here. Use Password and two-factor in your account menu."
- "This person is not a member of this company."
- "This person has no two-factor sign-in set up, so there is nothing to reset."