INTERNAL AREA
Manage · internal

Staff sign in

This is the separate entrance for /manage/*. A player account will not work here, and a staff account will not work in the player app.

Internal area. Every sign-in, and every read and write inside Manage, is logged with the account, the time and the IP address. The log cannot be deleted.

Required on every staff account. Two-factor cannot be switched off for an internal role, so you will not be able to sign in until a device is paired.

Sign in

There is no self-service sign-up. Staff accounts are created by the system administrator, and granting a role needs a second person to approve it. If you do not have an account, nothing on this page will create one for you.

Why staff sign in separately

The player app has its own sign-in, with registration and an 18+ gate. Internal roles use different authentication, a different session policy and a different level of logging, so they do not share that entrance.

Before you start

  • Have your two-factor device with you
  • Use your work email, not a personal address
  • Your role and its permissions load after you sign in

If you were sent here from a link, you will be taken back to that page once you are signed in — provided your role covers it.

Wrong password or code

The error message is the same either way — it never says whether an email address exists. Five failed attempts in a row lock the account for 15 minutes, counted by account and by IP address.

Switch account

⇄ Switch account

Access loads after authentication

No role hints here

This screen does not list internal roles, people or routes. The server reads the role already attached to a successful account.

Least privilege

Only the authorised start page and permitted records become available after sign-in. A blocked request is logged and returns a neutral access page.

Sessions

This internal session ends after 8 hours without activity. Staff accounts do not offer a "remember me" option.

Nothing on the signed-out screen confirms that an email address has an account or reveals what permissions it would have.