One Rutba account opens the Relay, and the Relay no longer keeps passwords of its own
The Relay used to run its own sign-up, passwords, second factor and invitations. Now a person signs in once with their Rutba account, and their organisation gives them the Relay the way it gives them anything else.
· 3 min read

Rutba Relay is the publishing service underneath social posting: one post, delivered to every connected network on a schedule, with an API for teams that publish from their own systems. What it does has not changed. How somebody gets into it has.
Until now the Relay kept accounts of its own: a sign-up form, passwords, email confirmation, a second factor, invitations and member roles, all in its own database. For a customer that already used Rutba, that meant a second password for one product — and for us, a second place in the estate collecting passwords, which is a second place to get it wrong.
One account, given the Relay
Now a person has one Rutba account and signs in once, at the same front door every Rutba site uses. They are given the Relay the way they are given anything else in Rutba: by a role on their organisation’s membership — owner, admin, member or viewer — set by their own organisation’s administrators.
- No separate sign-up. An organisation’s administrator gives a person the Relay on their existing Rutba account.
- No second password. The Relay never sees a password at all; it trusts the token Rutba’s sign-in issued.
- No second factor to set up again. Whatever protects the Rutba account protects the Relay.
- Leaving is one change. Removing somebody from the organisation removes their Relay access with everything else.
Every product that keeps its own passwords is one more place a password can leak from.
Why the last point matters most
Access to a social publishing tool is access to a brand’s voice in public. The failure that actually hurts businesses is not a sophisticated attack; it is a contractor who left in March and could still post in June, because their access lived in a separate system nobody remembered to clean up.
When the Relay is just another thing an organisation membership grants, offboarding somebody is one action in one place, and it takes the Relay with it.
Saying clearly when there is nothing to open
One small behaviour is worth describing because it is the kind of thing that makes a product feel broken. An organisation that has a Rutba account but no Relay workspace yet used to be sent round a sign-in loop: signed in, bounced, signed in again. The Relay now answers that case as what it is — not provisioned — so the console can say so in a sentence instead of looping.


