Accessing the Platform
Accessing the Billing Platform
Section titled “Accessing the Billing Platform”Access the SAFE billing platform online using any modern web browser.
Accessing the Platform for the First Time
Section titled “Accessing the Platform for the First Time”You’ll receive a welcome email with access instructions when we create your user account.
To set up your password:
- Click the link in your welcome email
- Click “Request a new password”
- Enter your email address (shown in the email)
- Check your email for a password setup link
Password requirements:
- Minimum 12 characters
- The system checks passwords against known compromised passwords at have i been pwned
- We strongly recommend using password management software to create and store your password
- See our list of recommended password managers
After setting your password, you’ll get a password reset code. Store this code safely - you’ll need it if you forget your password.
Once you’ve set your password:
- Return to the login page
- Agree to our privacy policy
- Log in with your new password
You’ll automatically receive a 6-digit code by email to complete your first login. See the Two-Factor Authentication section below for details.
Changing Your Password
Section titled “Changing Your Password”You can change your password at any time. We suggest changing it if you think someone else might know it.
To change your password:
- Go to Main Menu > Change Password
- Enter your current password
- Enter your new password
- Enter your 2FA code (if you use 2FA)
Your new password works immediately.
Sometimes we’ll ask you to change your password:
- When passwords expire
- When we update security requirements
You must change your password before using the platform when we ask. Required steps like this one, along with email verification and setting up an authenticator, appear on their own page with the rest of the platform unavailable until you have finished. The page keeps your platform branding, the environment name and a Logout option, and offers a Continue action once the step is done.
Changing Your Email Address
Section titled “Changing Your Email Address”Your email address is where password resets and access instructions are sent, so changing it takes a few steps to make sure the new address reaches you and that nobody else can change it on your behalf.
- Enter your current password.
- Enter the code sent to your existing email address.
- Enter the code sent to the proposed address.
Each code lasts ten minutes and allows five attempts. The new address is not saved until both codes are returned, so a mistyped address cannot leave you unable to receive platform email.
Asking for another code repeatedly is held for a minute between sends. Five incorrect passwords block the form for fifteen minutes, and starting the change again does not lift the block. You are emailed when a wrong password is entered and again if the block is triggered, so an attempt by someone else on your session does not go unnoticed.
If you cannot enter your password, or cannot read either inbox, use Request Admin Assistance and someone with the right access can help. See Account Access Assistance.
Resetting Your Password
Section titled “Resetting Your Password”If you forget your password:
- Click “Request a new password” on the login page
- Enter your email address
- Check your email for a reset link
To prove your identity, you’ll need one of these:
- Your password reset code (from when you last set a password)
- Your 2FA code
- A backup code
Don’t have any of these? Contact your data protection officer for a fallback reset code.
Two-Factor Authentication
Section titled “Two-Factor Authentication”The platform requires two-factor authentication (2FA) to secure your account and protect customer data.
Two Types of 2FA:
-
Email-Based 2FA (automatic for all users)
- When you log in, we send a 6-digit code to your email address
- Enter the code to complete your login
- Code expires after 10 minutes
- You can tick “Remember this browser” to skip 2FA for 7 days on that device
-
Authenticator App 2FA (recommended for enhanced security)
- Uses an authenticator app (Google Authenticator, Authy, etc.)
- Generates codes offline - works without email access
- Can remember your browser for 30 days
- More secure than email codes
- Required to access user management and sensitive customer data
Setting up Authenticator App 2FA:
- Go to Main Menu > Setup 2FA
- Install an authenticator app (see recommended apps)
- Scan the QR code with your authenticator
- Enter the 6-digit code shown in your app
- Save your backup codes safely
Once you set up app-based 2FA, the platform automatically stops sending email codes.
Important:
- Authenticator app 2FA is required to access user management and sensitive customer data
- Keep your backup codes safe - you’ll need them if you lose your authenticator
Remembered browsers:
A remembered browser records which kind of verification it completed, and only an authenticator satisfies the functions that require one. So a browser remembered while you were on email codes does not carry that trust over when you set up an authenticator: you complete two-factor authentication once more on it, and it is then remembered for the longer period. Recovery access is not authenticator verification either, so Elevated functions stay unavailable until a new authenticator is set up and verified.
When your platform is updated to a release that adds this, every remembered browser completes two-factor authentication once again.
Removing Two-Factor Authentication
Section titled “Removing Two-Factor Authentication”To remove 2FA (for example, when switching devices):
- Go to Main Menu > Remove 2FA
- Enter your 6-digit authenticator code
Lost your authenticator? Use a backup code instead.
No backup codes left? Ask your data protection officer to send you a recovery code. After you log in with the recovery code, you have 30 minutes to remove your 2FA device without entering a second code. Once you’ve removed it, set up 2FA again from a new device.
Resetting Your Backup Codes
Section titled “Resetting Your Backup Codes”Lost your backup codes? Get new ones:
- Go to Main Menu > Reset Backup Codes
- Enter your password
- Enter your 2FA code (if using 2FA)
- Save your new codes safely
Note: This invalidates your old backup codes.
No 2FA access? Contact your data protection officer for a fallback reset code.
Logging In
Section titled “Logging In”To log in you need:
- Your email address (check your welcome email or ask your data protection officer)
- Your password (reset it if forgotten)
- Your 2FA code (the platform always uses 2FA)
Using 2FA?
- Authenticator app: Enter the 6-digit code from your app
- Email code: Check your email for a 6-digit code and enter it
You can tick “Remember this browser” to skip 2FA on that device: 7 days where you verified by email code, 30 days where you used an authenticator.
Warning: Don’t use “Remember this browser” on shared or public computers.
Notification Emails
Section titled “Notification Emails”We send security alerts when someone logs in from a new location.
Got an alert you didn’t expect? Someone else might be using your account. Take action immediately:
- Change your password
- Update your 2FA (if enabled)
- Contact your data protection officer
Logging Out
Section titled “Logging Out”Always log out when you finish:
- Go to Main Menu > Logout
- This is essential on shared or public computers
The CRM Workspace
Section titled “The CRM Workspace”The CRM workspace is a separate interface, reached from the CRM Workspace link in the backend menu. Access to it is granted separately: Login (Backend) and Login (CRM) are independent, so an administrator can create CRM-only staff, backend-only staff, or people who use both.
CRM-only users have their own Account Security area for password changes, two-factor setup, backup codes and API keys, so a login challenge never sends them to an interface they cannot use. Where a sign-in method is not available to you, the page says why rather than simply failing.
If you use both interfaces, the switch in the top bar moves you between them and keeps your place: open a customer in one and you land on the same customer in the other.