Identity and access

Identity, verification, and account switching

The account application is the identity front door. After authentication, a user can move between the products they are entitled to without repeatedly entering credentials.

1. Account flow

  1. Register with a work email and password.
  2. Verify the email address with an OTP or verification link.
  3. Log in through the account surface and establish the secure session.
  4. Open the CRM, agency console, webmail, or another product through an authorized handoff.

2. Switching rules

  • Users with multiple workspaces can switch between their own companies.
  • Agency owners and agency members can return to the agency context and open related client workspaces.
  • A user without agency membership sees only the workspaces and products they own or belong to.
  • The switcher is derived from server-checked memberships and relationships; a client-supplied workspace ID is never trusted by itself.

3. Recovery and security

  • Password reset and email verification mail use dedicated CrownvMail sender identities.
  • Two-factor authentication and session revocation belong to the account security boundary.
  • Temporary API or gateway failures should be retried and logged without exposing bearer tokens in the browser.

Still need help? Contact support.

Identity, verification, and account switching | Crownvo Docs