- Help Center
- Account and access
- Sign in, SSO, and launch links
About 5 min read
Sign in, SSO, and launch links
How sign-in works with the control plane, branded workspace URLs, and secure handoff into your tenant runtime.
On this page
Control plane versus workspace
Authentication and billing account management happen on the control plane application. Execution—chat, tasks, agents—happens inside your workspace runtime.
After a successful sign-in, you are handed into the correct workspace with a time-bounded handoff so sessions stay consistent without weakening isolation.
Branded URLs
- When tenant domain mapping is enabled, expect customer-facing links to use your workspace subdomain rather than raw infrastructure hostnames.
- Bookmark the workspace URL your admin communicates; phishing attempts often mimic login pages.
If sign-in fails
- Try an incognito window to rule out stale cookies.
- Confirm your email is the one invited to the workspace.
- Capture the approximate time and any error text before contacting support.
Related articles
- What to do right after you sign up — A short checklist after you create an account: confirm email, pick or wait for your workspace, and open the product for the first time.
- Workspaces explained — How a workspace relates to your company account, why you might have more than one, and where your agents and data live.
- Members, invites, and roles — Inviting colleagues, what new members should expect on first visit, and keeping access aligned with how your team works.
- Billing, plans, and invoices — Where billing is managed, how usage-related charges may appear, and how to get help when something looks wrong on an invoice.
- Create and run your first agent — Creating an agent, choosing a sensible starting model, and verifying health before you rely on it for real work.
- Help Center home