Most sign-in and access problems have a short explanation and a fix you can apply yourself or with one message to an org admin. Find the page or message you are seeing below. Error messages in Trace.Space end with a code in brackets, for example (code: 3012); the code helps support find the cause, so include it when you write to us.
"Sorry, your magic link is invalid or has expired"
A magic link is a one-time sign-in link sent to your email. This page, with a Back to Sign in button, appears when the link cannot be used. The line above the button tells you why:
The link you're trying to access has expired. A magic link works for 30 minutes after you request it. Click Back to Sign in and request a new one.
The link you're trying to access has already been used. Each link signs you in once. Request a new one.
The link you're trying to access was requested from a different browser. The link only works in the browser that asked for it. If you requested it on your laptop, open it there, not on your phone. If your email client opens links in a different browser than the one you used, copy the link and paste it into the original browser.
The link you're trying to access couldn't be found. The link is malformed, usually because an email client wrapped or shortened it. Request a new one and click it directly in the email.
If no email arrives, check your spam folder and click Resend on the sign-in page. See Email authentication using Magic Link.
"User is suspended"
An org admin has suspended your account. Suspended members cannot sign in, but everything they created stays in place, and the admin can unsuspend them from Organization settings > Members. Contact an org admin to be reinstated. See Managing users.
A related message, User is not part of Organization. You may have been removed or suspended from the Organization which you are trying to access!, means the same thing for one specific organization.
"Sorry, you no longer have access to this organization"
This page appears when you sign in but Trace.Space finds no organization you can open, or the organization in your link no longer includes you. It says Contact the company admin if you think this was a mistake and offers a Switch organization button. Click it to pick another organization you belong to, or ask an org admin of the missing organization to invite you again. See Switching Organizations.
SSO sign-in fails
If Log in with SSO sends you to your identity provider but you do not land back in Trace.Space, the SSO configuration is usually the cause: a callback URL that does not match, an issuer URL that is not HTTPS, missing email or profile claims, or a domain claimed by another organization. Only an org admin can check these. Send them the exact error text and point them to the troubleshooting list in Single Sign-On (SSO).
If your email domain is not configured for SSO, use the Google, Microsoft or GitHub buttons or a magic link instead.
"Your session has expired. Please log in again."
Sessions last 30 days, and a user can keep at most five browsers signed in at once; the oldest is signed out when a sixth signs in. Sign in again. If it happens constantly, sign out of browsers you no longer use.
"Access denied" when opening a page
The page shows Access denied with the text You do not have permission to access this content. Please contact an administrator to request access. and a View org admins button. Click the button to see the names and email addresses of the organization's admins; each entry opens an email to that admin.
You see this when your user groups do not grant read access to the item, baseline, or settings page you opened. Reviews show a variant: You need to be a participant to access this review, with the email of the review's creator, who can add you as a participant. See Reviews.
No items visible
If the Items tree is empty although colleagues see content, your user groups grant no read access at the top of the tree. Access is inherited downwards: an item takes the nearest explicit setting above it, and if the Root is set to Deny or has no setting at all, nothing below it is visible. An org admin fixes this by giving one of your user groups at least View only at Root, or on the specific items you should see, under Organization settings > Members > User groups. The How permissions work explanation on that page walks through the inheritance rules. See User groups and access control.
"Cannot suspend last admin"
An organization must always have at least one org admin, so you cannot suspend the only one. Use Set as Org admin on another member first, then suspend the account. See Managing users.
"Insufficient permissions"
The action you tried (editing, creating a trace, deleting, changing settings) needs a higher access level than your user groups give you on that item. Members with read access can still create and manage ordinary traces, but parent-child moves need write access. Ask an org admin to raise your access, or to do the change for you.
Still stuck?
Click Help at the bottom of the left sidebar to open the support chat, or email [email protected] with the message, its code, and the address of the page. See Getting help.
