Getting started on Workelo 👤
-
Understand the different connection methods 🛸
This article describes the three connection methods that allow users to access the platform securely, adapted to each structure's needs.
👉 If you are experiencing difficulties accessing your Workelo space, here are the dedicated resources:
🔏 Password
Password-based sign-in is the classic authentication method where the user enters their email address and password to access Workelo.
⚙️ How it works
- The user enters their email address on the sign-in page
- The password field is displayed automatically
- After entering the credentials, access to the platform is granted
👮 Security
- Required complexity: Minimum 12 characters (1 uppercase, 1 lowercase, 1 number and 1 special character)
- Renewal: Mandatory change every 3 months
- Protection: Account locked after 5 unsuccessful attempts
- Optional MFA: Possibility to enable two-factor authentication via email ➤ see related documentation here !
🪄 Secure link (Magic Link)
The secure link allows users to sign in without a password using a unique link sent by email.
⚙️ How it works
- The user enters their email address on the sign-in page (the password field is not displayed)
- An email containing a secure sign-in link is automatically sent
- The user clicks the link to access Workelo directly
👮 Security
- Unique token: A temporary 16-character token is generated for each user
- Automatic reset: Passwords are reset daily
- Validity period: Maximum of 24 hours
📏 Activation conditions
Activated if defined as the role’s connection strategy.
🛜 SSO (Single Sign-On)
SSO allows users to sign in to Workelo without entering credentials, through their company’s authentication system.
⚙️ How it works
- The user clicks “Sign in with SSO” or is automatically redirected to their company’s authentication portal
- Once authenticated on the company portal, access to Workelo is granted automatically
- Authentication is delegated to the company’s Identity Provider (IDP)
🧑💻 Technical configuration
- Metadata: Exchange of metadata between Workelo and the client system
- Data matching: Matching based on the NameID
📏 Activation conditions
- Activated if a
technical idis provided at employee level - SSO is configured for the account
👉 To learn more: Understanding SSO sign-in 🛜✅ Connection mode priority order
Workelo applies an automatic priority order to determine the appropriate sign-in method:
1. SSO
2. Secure link
3. Password (default)This hierarchy ensures an optimal user experience by prioritizing the most secure and convenient methods depending on each structure's context.
-
I cannot log in to Workelo 🔑
You are currently in a journey, or involved in journeys and cannot log in. Here are the possible cases and the associated solution! 😊
🔐 I cannot send myself a password reset link
Three possible causes:
1. You have not yet created your access
Problem: You did not create your password through the login invitation generated by your company.
💡 If you have never logged in to Workelo, it is essential to use this email to create your access. It is not possible to create your access using a reminder email, for example.
Solution:
- Check that the email address provided to your company is correct.
- Look into your spam or junk folder for the invitation.
- Ask your HR team to resend the invitation.
2. You did not confirm an email address change
Problem: Your company changed the email address associated with your profile, and you did not validate this update via the link sent by email (valid for 24h).
Solution: Ask your HR contact to resend you a confirmation link via the platform.
3. Your journey has been closed or cancelled
Problem: If your journey has been closed or canceled by your company, your access to Workelo is deactivated. You will not be able to log in or receive password reset links.
Solution: Contact your HR team for more information on your journey status.
🔄 I am redirected in a loop on the Workelo interface
Possible cause: The combination of your email address and your technical identifier is not recognized by your company's secure portal (SSO system).
Solution: Contact your HR and IT teams to check that your credentials are correctly configured.
💡 Workelo cannot intervene in any way since this configuration is managed directly by your company.
-
My collaborator cannot log in to Workelo 🛂
⚠️ Prerequisite: access to the employee directory requires the “edit the employee database” permission
You are an HR or an Administrator on Workelo and you want to unblock an employee who cannot sign in, here are the checks to perform :
🎬 Email address change not confirmed
📩 Sign-in invitation not received
👮 Trouble signing in via the company’s secure portal (SSO)
🔐 Password not created yet
Creating an employee in your directory, or a journey for a new hire, does not mean their access is created. they need to take an action
in fact, a user can only access their Workelo space if they have created their access (password, etc.) via an invitation email (link included in a sign-in invitation and in the first Moments of truth)If a user has not created their access using one of the links in those emails, they will not be able to sign in or reset a password, even if they try from another type of email (reminders, etc.)
you can resend a sign-in invitation from your employee directory
💡 You can check whether an employee has already signed in (and therefore created their access) from your “Employees” page, column “signed in on”
🎬 Email address change not confirmed
When changing email (for example, switching from personal to work email), the user receives a link by email at the new address, asking them to confirm it. this link is valid for 24h
💡 You can check whether an employee has confirmed their email change from your “Employees” page, and even send a new link :
📩 Sign-in invitation not received
✅ Checks to perform:
1- Go to the employee’s profile page and check if there is a red error message at the top saying the email address is undeliverable
2- If an email is blocked because the address contains an error, an automatic email is sent to the HR of the new hire to notify them
🥳 If neither of the two cases above apply, chances are the email was sent to the new hire.
You can then ask your employee to:
1- Check their spam and junk folders by searching for emails sent from support@email.workelo.eu
2- Disable any anti-spam or security that might impact deliverability
💡 In case of a delivery issue on a personal email address, ask your collaborator for another one.
👋 Journey closed/canceled
When an employee’s journey is closed or canceled, their access is destroyed, so they can no longer access their journey
👮 Trouble signing in via the company’s secure portal (SSO)
two possible cases:
A. the employee is redirected to the Workelo sign-in page
this means the employee’s technical id does not contain the expected value to allow authentication on the company side
you’ll find this code on the profile page (tab “account”, page “Employees”)
it must be filled in exactly as expected by your SSO connection (user name), because this field is case sensitivethe technical id and the Name ID must match exactly as defined internally
👉 This value is defined and configured by your internal IT team. please check with them to know the expected value and make the necessary adjustment in the platform as Workelo does not have access to this information, support will not be able to assist
💡 If an integration with a third-party tool feeds this code, make sure the “Internal ID” field is filled in
B. An error message appears in your company’s branding
this means access has not been granted by your company. please contact your IT team to grant the employee the right access 👷🏻👉 As Workelo does not have access to this configuration, support will not be able to assist
Examples of messages:
- The signed in user ‘xxx’ is blocked because they are not a direct member of a group with access, nor had access directly assigned by an administrator. Please contact your administrator to assign access to this application.
-
Select account does not exist and cannot access the application. The account needs to be added as an external user in the tenant first.
- the signed-in user ‘xxx’ is blocked because they are not a direct member of a group with access, and no access was directly assigned by an administrator. please contact your administrator to assign access to this application
- the selected account does not exist and cannot access the application. the account must first be added as an external user of the identity provider
-
Understanding SSO connection 🛜
⚠️ Prerequisite: This article is intended for everyone, however, modifying an employee's technical ID requires the "Edit employee database" permission.
1. What is SSO and what are its benefits 🛜
Imagine SSO (Single Sign-On) as a kind of digital passport 🛂
At Workelo, it allows a user to log in without having to enter their username/password.Authentication is delegated to an identity provider (IDP) that recognizes Workelo as one of its service providers (SP). If the user already exists in the system (match between the technical ID and the Name ID), they are logged in to Workelo. If the user does not exist, they are redirected to the password login page.
The benefits of SSO 🔓1. SSO enhances security by requiring unique credentials for each user. This means that a complex password is necessary, making it more difficult for hackers to access sensitive information.
2. If a user leaves the company, simply deactivating their ID at the company account level instantly removes their access to the tools.
3. SSO reduces the risk of phishing attacks, as users do not need to click on links in emails to log in.
4. Finally, SSO can improve compliance with security and privacy regulations by providing detailed audit logs that trace every user's action across all connected systems.2. My employee or my boarder can't log in with SSO
Two possible cases:
A. The employee cannot log in and is redirected to the Workelo login portal.
This means that the technical ID field for this employee does not contain the expected value required to enable authentication on the company side.
You can find this code on the profile page (Account tab, Employees page).
It must be filled in exactly as expected in your SSO configuration (user name). ⚠️ This field is case sensitive.🕵️♀️ The Technical ID and the Name ID must match exactly as defined internally.
🧑💻 This value is defined and configured by your internal IT team. Please check with them to identify the expected value and make the necessary adjustment in the platform.
👉 As Workelo does not have access to this configuration, our support team will not be able to assist.
💡 If this code is populated via an integration with a third-party tool, make sure that the “Internal ID” field is correctly filled in.
B. An error message appears in your company's colors; contact your internal IT department to grant access to the employee 👷🏻
👉 As Workelo does not have access to this configuration, our support team will not be able to assist.
Examples of messages:- The signed in user ‘xxx’ is blocked because they are not a direct member of a group with access, nor had access directly assigned by an administrator. Please contact your administrator to assign access to this application.
- Select account does not exist and cannot access the application. The account needs to be added as an external user in the tenant first.