STAFF AREA
/manage/login

Sign in to the admin area

This is the way in for staff and partner organisations. It is completely separate from the player sign-in: different address, different session, different password policy, and two-factor authentication is required.

Staff area. Every sign-in attempt — successful or not — is written to the access log with the time, IP address and device. That log cannot be deleted, and it is checked whenever access to sensitive data is reviewed.

Step 1 · Your work account

At least 12 characters, no reuse of an old password, and no "save password" option on shared computers.

Forgot password

How staff accounts work

  • There is no sign-up. Staff accounts are created by a system admin. Nobody can register themselves — if they could, the whole access model would mean nothing.
  • You do not pick your role. Your role comes from your account once you have authenticated. There is no role selector on this screen.
  • No shared accounts, no demo logins. One person, one account, so the audit trail always points at a real individual.

Error messages are always neutral. A wrong email, a wrong password, or a revoked account all return the same line: "Those sign-in details are not correct." We do not say whether an email exists or whether an account is locked. For a product about gambling behaviour, confirming that someone has an account here is already a leak. After five failed attempts in a row the account is locked for 15 minutes and the owner gets an email alert.

Permissions are not disclosed before sign-in

After authentication, the server loads the role and authorised start page already attached to the account. This screen offers no role selector, staff directory or internal route map, and a user cannot change their own access here.