Account and access
Two populations sign in to two different places, and half the questions on this
page come from mixing them up. Your team signs in to the Cockpit at
app.revenexx.com through the revenexx identity provider. Your customers'
buyers sign in to your storefront with accounts that live in the Customers
app. Nothing you change for one affects the other.
I cannot sign in to the Cockpit. What do I check first?
There is no separate Cockpit password; opening the Cockpit hands you to the identity provider and back. If a colleague who has never signed in gets the failure page, their account is not provisioned, so check they appear under Settings › Team and re-invite if not. If someone who signed in yesterday gets it today, sign out fully, clear the site's cookies and try a private window. If everyone gets it at once, do not re-invite anybody; raise it with support. See Single sign-on.
My colleague never received the invitation email.
Open their entry in Settings › Team; it will read Invited. Check the address for a typo first, because the mail goes to exactly what was typed, then ask them to look in spam, then use Resend invitation. If several invitations are disappearing at once, it is a mail-delivery problem rather than a Cockpit one. See Invite your team.
How do I give a colleague read-only access to orders?
Today you cannot. Access in the Cockpit is governed by roles held in the identity provider, and there is no role column in Settings › Team and no permission editor. Every colleague you invite gets the same access, and a role change is a request to your revenexx contact. Plan around it: fine for a five-person admin team; a working student who should only read orders needs a separation that does not exist yet. See Users, roles and permissions.
A colleague has left. Do I suspend or remove them?
Suspend, on the day they leave. Suspend blocks sign-in and keeps the account, so the audit trail of what they changed stays readable, and Reactivate reverses it. Remove from organisation deletes their identity-provider record permanently and they would have to be invited again from scratch. Then check the Sessions tab, because suspending an account does not end a session that is already open. See Users, roles and permissions.
Can we sign in with our Active Directory or Entra ID?
In principle yes, the identity provider speaks the standard protocols, but it is not something you configure yourself: there is no SSO settings screen and no domain verification flow in the Cockpit. Raise it with your revenexx contact as a project, bring the directory you use and the protocol your IT prefers, and say whether you also want members provisioned and deprovisioned automatically. See Single sign-on.
Where do I set password rules and session length for my team?
Nowhere, yet. The policy fields under Settings › Auth & Security (password history, session length, sessions per user, blocking common passwords) apply to your customers' buyers signing in to your storefront, not to your colleagues. Setting a 30-minute session there does nothing to your Innendienst and everything to your customers. For your team the control you have is the monthly review of Settings › Team › Sessions. See Security and data protection.
How do I turn on two-factor authentication?
Each person enrols their own factors under Settings › Profile › Security: a passkey, an authenticator app, an SMS code or an email code. Passkeys are the best of the four and take under a minute. One limit to know: the Cockpit cannot yet list or remove a registered passkey, so a lost security key is a support request, and terminating the person's sessions is the stop-gap. See Security and data protection.
Why can a customer's buyer not sign in to the shop?
Open the person in CRM › Contacts and read three fields in order:
registration_status (pending means nobody has decided their application,
rejected means someone said no), the contact's own status (invited or
blocked), and the company's status (blocked on the organization disables
sign-in for everyone at it). If all three are clean, it is the password or the
email address they are typing. See
When a customer cannot order.
Why do I see a Billing tab and my colleague does not?
Settings › Billing is visible to administrators and billing administrators only. Those are roles in the identity provider, and since roles are not yet assignable from the Cockpit, changing who holds them is a request to your revenexx contact. See Subscription and billing.
Is there an audit log of what my colleagues changed?
Not a tenant-wide one. Settings › Profile › Activity shows your own account's recent activity, roughly the last hundred entries, with no export and no date filter. It is a self-check, not a compliance-grade log; if an auditor asks for one, raise the requirement with revenexx rather than pointing them there. For orders specifically, the History tab on each order records every action with the actor. See Security and data protection.
Why does my Cockpit have menu entries a colleague's does not?
Because the sidebar is assembled from the apps installed in each tenant. A menu entry someone else has and you do not is an app you have not installed. Permissions have nothing to do with it. If you are both on the same tenant and see different things, the difference is the identity-provider role. See Apps and the Marketplace.
A session looks suspicious. How do I end it?
Settings › Team › Sessions lists every active sign-in across your organisation with the device, the browser, the factors used and when it was last active. Terminate Session ends one. Do that for anything nobody can account for, and have the account it belongs to change its password afterwards. Reading that list once a month is the cheapest security control you have. See Users, roles and permissions.