Microfinance sign in
The institution service is invitation only. Sign in happens at the managed identity provider, which sets your credential and your second factor; this page never asks for a password and never shows a success screen of its own. After the provider verifies you, the server checks your invitation and your current membership before any institution data is shown.
Access
Service status: not configured
The institution service is not configured for this site. Nobody can sign in from this page until a reviewed deployment exists. What is required before this button is enabled:
- A reviewed managed identity provider (Auth0 B2B Organizations is the preferred evaluation, WorkOS the comparison): plan, region, subprocessors and data processing agreement approved; no provider is activated today.
- A reviewed service deployment on an https origin with the OIDC adapter configured, a persistent database and a named audit anchor.
- An invitation created by provisioning for the named owner address, accepted by the verified identity (issuer and subject) after enrolling MFA at the provider.
- The synthetic identity, session and scope tests, then the provider invitation, MFA, recovery and revocation checks within the approved scope; until then every acceptance case OD01 to OD14 is NOT RUN.
The service is configured. The button opens the provider's sign in on the service origin; you will be asked for your credential and your second factor there.
Sign in through the identity provider Open the service workspace
The service workspace shows institution data only to a signed in session; without one it shows the same sign in gate.
Service origin:
Provider and MFA policy
- Invitation only. There is no sign up, no email domain rule and no automatic membership: a successful provider login proves identity only. The server's membership record decides institution, roles and branches for every request and every export.
- MFA is mandatory for every user, including administrators. A session whose assurance the provider does not assert is refused on every institution route until a second factor is presented.
- Identity key is the provider issuer plus subject. Email is the invitation target, never a role or an institution grant.
- Recovery (lost second factor, forgotten password) is the provider's flow; the service has no recovery, reset or signup route. Sign out revokes the server session immediately.
- What reaches the provider: your email, the opaque subject, authentication factors and login metadata. Borrower records, notes, balances and source credentials never do.
What the demonstration workspace is
A dedicated synthetic institution with its own branches, personas, seeded portfolio snapshot, review queue, action register, report draft, calendar, notes, working sessions, support access records, country pack and languages. It is not a customer institution and the owner's roles apply to this workspace only.
Real CBS/MIS calls, production uploads, borrower records, external messages and calendar invitations, regulatory filing, local AI activation, live payments and customer permission grants stay disabled. Every module carries an honest status label inside the workspace.
Labels follow the language selector; the service policy, the country pack and every figure are the same in every language. Nepali and Hindi texts on this page are drafts pending native review.