Manage account access and security

Understand sign-in, password recovery, invitations, sign-out, and permanent account deletion.

Sign-in methods

Customer accounts can use Google, GitHub, or email and password. Social sign-in begins from a clean local session to avoid accidentally linking a different identity.

Password recovery

  1. Select Forgot password? on the sign-in screen.
  2. Enter the account email and open the secure reset link.
  3. Choose a password of at least 12 characters.
  4. Sign in again after the password is updated.

Workspace invitations

An invitation link is tied to a token and expires after seven days. Confirm it while signed in with the invited identity. If the token is missing, expired, or already used, ask an owner or admin to issue a new invitation.

Delete an account

In Settings, type DELETE and confirm. This permanently deletes the sign-in and personal account data, signs the user out on every device, removes personal memberships and resources, and anonymizes retained audit entries. Shared workspaces remain available to their other members.

Account deletion is irreversible

Before deleting the last operational account, transfer ownership, rotate credentials owned by that person, and export any required audit evidence.

Staff isolation

ALLM staff identities are isolated from customer workspaces and must use the operator console. A staff session cannot be used to access customer app data.