Accepting your invitation and setting your password
How to use your invitation email, set your first password, and what to do if the link no longer works.
How to use your invitation email, set your first password, and what to do if the link no longer works.
You cannot create your own account in Recruit. An administrator invites you, and the invitation email contains a link to a page where you choose your password. This guide covers that first sign-in, what happens straight afterwards, and how to fix the usual problems.
The invitation email
The email is titled "You've been invited to" followed by your organisation's name. It greets you by first name and contains a link to set your password. It goes to the address the administrator entered when they invited you, so check that inbox (and your junk folder) first. That address is also your sign-in name.
The email says the link expires in 48 hours. A link can be used once: after you have set a password, the same link stops working.
Setting your password
- Open the link in the invitation email. A page titled Set your password opens.
- Type a password in the Password field. A strength indicator (Weak, Fair, Good or Strong) and a Password requirements checklist update as you type.
- Type the same password in Confirm password.
- Select Set password.
- You are taken to the sign-in page with a "Password set" message. Sign in with your email address and your new password.
If you were already signed in to Recruit on that device when you opened the link, the page warns you that completing the form signs you out on this device. That is expected.
Password rules
- At least 12 characters and no more than 100.
- At least one uppercase letter (A-Z) and one lowercase letter (a-z).
- At least one number (0-9).
- At least one special character, for example ! @ # $ %.
- The password and confirmation must match, otherwise you see "Passwords do not match".
Your organisation can set stricter rules than these, such as a longer minimum. If your password is refused you see "Password does not meet security requirements." Choose a different one. The link stays valid, so you can try again.
If your account already has two-factor authentication
If two-factor authentication is already switched on for your account, a Verify your identity step appears after you select Set password. Enter the 6-digit code from your authenticator app in the Authentication code field. If you cannot get to your app, select Use a recovery code and enter one of your recovery codes instead. The password is saved only once the code is accepted. A wrong code lets you try again.
What happens next
Your account becomes active as soon as the password is saved, and your status in Settings, Users changes from Invited to Active.
Administrators, HR users and group administrators must have two-factor authentication before they can use Recruit. When you first sign in with one of those roles, you are sent to a Set up two-factor authentication page that says your organisation requires it.
- Select Enable two-factor authentication.
- If your organisation allows more than one method, choose Authenticator app or Email. For the authenticator app, scan the QR code with an app such as Google Authenticator or Authy (or enter the manual code if you cannot scan), type the 6-digit code and select Verify and enable. For email, we send a 6-digit code to your work address; enter it and select Verify and enable. Send a new code resends it.
- Save your recovery codes. Each one works once. Use Copy all or Download codes, tick I have saved my recovery codes, then select Continue to app.
You cannot reach the rest of Recruit until this is done. Other roles are not forced through this page, but can switch two-factor authentication on themselves from their profile.
From then on, signing in means your email and password, followed by a verification code if two-factor authentication is on.
Expired passwords and changing your password
Passwords do not expire unless your organisation has set a maximum password age. If it has, and your password is older than that, Recruit takes you to a Your password has expired page that says "For security, please set a new password to continue." You cannot use anything else until you change it.
You can also change your password whenever you like from your profile, under Change Password. The fields are the same on both screens:
- Enter your Current password.
- Enter a New password that meets the rules above, then repeat it in Confirm new password.
- Select Change password.
Recruit signs you out and shows "Password changed successfully. Please log in again." Sign in with the new password. These messages can appear along the way:
- Current password is incorrect: retype your existing password.
- New password must be different from your current password: pick something new.
- Passwords do not match: the new password and confirmation differ.
If you have forgotten your password, use Forgot your password? on the sign-in page. It emails a reset link to your address.
Problems with the link
The link has expired or has already been used
You see Reset link no longer valid, with the text "This password reset link has expired or has already been used." Ask your administrator to send a new invitation. Only an Administrator or an HR user can do this, and HR users can only do it for people with the Member role.
They open Settings, then Users, find your row (its status reads Invited) and select Resend. You receive a fresh email with a new link. Use the newest email.
Resend is offered only while you have not yet set a password. If your row shows Invite pending or Invite failed, the invitation email itself did not go out. The administrator uses Retry invite on that row instead, or Cancel invite to remove it and start again.
You cannot sign in afterwards
"No account found for this email address. Please contact your administrator." means the address you typed is not the one that was invited. Use the exact address the invitation was sent to. If the invitation went to the wrong address, ask your administrator to sort it out.
"Account locked. Please contact your administrator." means the account has been locked after too many failed attempts. An administrator can unlock it from Settings, Users.
Your organisation uses single sign-on
If your organisation requires single sign-on you see "You must sign in with single sign-on". Use the Microsoft or Google button on the sign-in page instead of a password.
Old bookmarked links
Invitation links from before the current sign-in process open the sign-in page instead of a password page. Use the link in your most recent invitation email, or ask an administrator to resend it.