Rutba
Start free

Blog · How we build

One sign-in for the whole suite, and an organisation that stays chosen

Since 24 September, Rutba’s workspaces no longer ask for a password of their own. You sign in once, the organisation you chose stays chosen until you switch, nothing about it travels in a link, and signing out anywhere signs you out everywhere.

· 5 min read

Share this

Until this week, “one account” at Rutba stopped at a door. The sites and the consoles shared one sign-in, but the workspaces where the actual work happens — the shop, the books, Drive, Sign — each kept a password form of their own. Open one and you signed in again; open it as a different company and you picked from a list; follow a colleague’s link and it might carry a company name in the address and open somewhere you did not mean to be.

The models worth copying had already solved this, and the ones we copied are the ones people use every day: one place that knows who you are, a switcher in the corner of every screen, and apps that never show their own password box. Since 24 September that is how the whole suite works.

You sign in once

Rutba’s own sign-in now checks every password — for the sites, the consoles and every workspace. A workspace does not show a password form on the normal path: it asks the sign-in, quietly, and opens. If you have not signed in, it sends you there and brings you back.

Quietly means a small hidden check, not a page. Every app asks when it loads, when you come back to its tab, and every five minutes while it is open. That is how a workspace knows you signed out in another tab, or switched organisation in another app — and why it follows rather than going on showing the old one.

An organisation that stays chosen

A person acting for one organisation is a profile: your own, a client you do the books for, a demo you are trying things in. Whichever one you chose stays chosen, in every app, until you switch — and the switcher is in the header of every app, one click, no second password.

  • Nothing goes in the link. Which organisation you are in is kept by the sign-in, not in the address. A link a colleague sends opens in the profile you are in; if what it points at belongs to another one, the app says so rather than quietly moving you.
  • A demo looks like a demo. A demo or test workspace carries a mark that stays on screen, so the practice company always looks like the practice company.
  • Switching is the only way to change it. No app, and no link, can pick your organisation for you.

The context is never in the address. A link opens where you are; if it belongs somewhere else, the app says so.

Sign out once, everywhere

Signing out at Rutba ends the session and tells every app that trusted it, so each one forgets you — not just the tab you pressed it in. A shared computer at the counter is exactly where that matters: the next person does not inherit a workspace that was still open in the other window.

A workspace’s own password, asked at most once

Most workspaces already had people with passwords of their own, and nobody should be locked out because we changed the door. So the first time you open a workspace after signing in, it works like this:

  • Already linked to your Rutba account: it opens. The link is the proof, whatever password the workspace holds.
  • Not linked yet, same password: right after you sign in, the workspace is asked — once, in the background — whether the password you just used is also yours there. The password is sent for that one check and never stored, and the answer is a yes or a no. Yes: it links your account and never asks.
  • Not linked yet, different password: the workspace asks you for its own password once. After that it never asks again.

That is the only place a password is ever asked outside Rutba’s sign-in. And when you change your Rutba password, the default is to change it everywhere you are linked, and the page lists where that is — or, if you choose “only here”, it says in plain words that the others keep their old password and will ask for it once.

Invitations that do not go missing

Inviting somebody from the console now reaches the organisation’s workspace and keeps reaching it until the workspace acknowledges — a dropped request is retried rather than leaving a member half-invited. What the new member may open inside the workspace is still granted there, by whoever runs it.

What had to be true before it shipped

  • The quiet check answers only the suite’s own apps, named one by one — never a pattern, and never a storefront where a merchant’s own code runs. Why that distinction mattered is the next part of this series.
  • A workspace can still be reached without us at a break-glass address, for its operators and for a workspace that is not connected — and every use of it is logged as such.
  • The sign-in service holds nothing of its own that could drift from the records it serves; it keeps no records at all.

Where a sign-in leaves you

The hub: what you have, organisation by organisation, and what you could add.

Read how the hub works

Read next

Platform services

A launch morning waits ten minutes. A looping script is paused

Rutba Relay now counts the deliveries each organization started in the last hour. Just over its ceiling, a publish is told to wait ten minutes. Four times over is not a person, and that organization’s publishing is paused until somebody looks.

4 min read

Business Suite

A page of zeroes is a worse claim than nothing at all

The promoter’s page on the storefront is deliberately thin: it says where you stand, and nothing else. A dashboard of zero earnings would tell an approved promoter they have earned nothing — a different and much worse statement than "this does not exist yet".

3 min read

Share this

One family

The rest of Rutba

One account across all of it. Sign in once and the products know each other.

PORTAL-BLOG-DETAIL · 41818a7