Skip to content

Sign in for the first time

There’s no separate InPolicy password to remember. You sign in through your work identity provider — Google Workspace or Microsoft Entra — or you accept an emailed invitation from your admin and set a password on the way in.

InPolicy may be in invite-only or open mode depending on where your organisation is in its rollout.

A valid invite code is required to create an account. If you have one:

  1. Open https://app.inpolicy.ai/register?code=YOUR_CODE — invite emails pre-fill this link — or enter the code manually on the registration page.
  2. Complete the sign-up form and verify your email.

If you don’t have a code, or your code is expired or fully used, you’ll be placed on the waitlist automatically and receive a confirmation email. You’ll be notified when a spot opens.

Anyone can sign up without a code:

  • Work email (e.g. you@acme.com): the first person from your company gets in immediately and a shared workspace is created for your domain. Colleagues from the same domain go on the waitlist until your workspace admin invites them directly.
  • Personal / free email (e.g. Gmail, Outlook.com): you get your own individual workspace, separate from any company account.

A valid invite code always overrides these rules and grants immediate access regardless of mode.

If InPolicy is in invite-only mode and you try to sign up via Sign in with Google or Sign in with Microsoft without a valid code, you’ll land on an access-code screen after the OAuth redirect. Enter your code there to complete sign-up, or join the waitlist if you don’t have one. Existing users are never affected — the gate applies only on first sign-in.

Option 1: SSO (Google Workspace or Microsoft Entra)

Section titled “Option 1: SSO (Google Workspace or Microsoft Entra)”

Your admin has connected your organization’s identity provider. Sign-in is a redirect:

  1. Go to your tenant URL — usually https://app.inpolicy.ai or a subdomain your admin provided.
  2. Click Sign in with Google or Sign in with Microsoft.
  3. Approve the OAuth consent prompt the first time (your admin already approved the app for the organization; your personal consent covers profile and email scopes).
  4. You’ll be redirected back to InPolicy, signed in.

Your name, email, and avatar come from your identity provider. If you change any of those at the provider level, InPolicy will pick up the change the next time your admin runs a directory import (see Directory sync).

If your admin invited you by email, you’ll receive a message with a link that looks like:

https://app.inpolicy.ai/auth/accept-invitation?token=…
  1. Click the link. No sign-in is required to open it.
  2. Set a password on the acceptance screen.
  3. You’re in.

Invitation tokens expire after 7 days. If the link says “invitation expired”, ask your admin to resend the invitation.

You reached the signup gate without a valid code, or your company’s workspace is already active and your admin hasn’t invited you yet. Check your email for a waitlist confirmation. To skip the wait, ask a colleague already on InPolicy to have an admin invite you directly via the Users page.

Your company already has an InPolicy workspace.

Section titled “Your company already has an InPolicy workspace.”

Someone at your domain is already on InPolicy. Ask your workspace admin to invite you — you don’t need to sign up separately.

You aren’t in the directory yet. Ask your admin to invite you directly, or — if SSO directory sync is enabled — wait for the next sync.

Your email domain isn’t on the tenant’s allowlist. This is controlled by an admin from the Users page → Add usersImport tab, where Google Workspace / Microsoft Entra is connected and the domain allowlist is set. See SSO for the full flow.

Tokens expire after 7 days. Ask your admin to re-send — there’s no way to extend an already-issued token.

Invitation tokens are single-use. If you clicked the link, accepted, and then tried again from the same email, that’s expected. Go to https://app.inpolicy.ai and sign in normally instead.

I signed in, but I can’t see any policies.

Section titled “I signed in, but I can’t see any policies.”

You’re probably on the default Viewer role, which only sees published policies. If your team hasn’t published anything yet, there’s genuinely nothing to show. The empty state is the empty state.

  • Install the browser extension if your team uses it.
  • If you’re an admin, head to users and roles next.
  • Otherwise, you’re done — browse published policies from the Policies menu.