> For the complete documentation index, see [llms.txt](https://codifi-fdm.gitbook.io/codifi-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://codifi-fdm.gitbook.io/codifi-docs/frequently-asked-questions/administrators.md).

# FAQ for Administrators

Tenant- and organization-level questions. Skim or use search.

> Looking for something not here? See the [**main FAQ**](/codifi-docs/frequently-asked-questions/faq.md) or [**Known Issues**](/codifi-docs/known-issues-and-edge-cases/known-issues.md).

***

### How do I invite a new user to my organization?

**Short answer:** From the admin area, **Invite User** by email. They'll receive an activation email and choose a password.

**See:** [Inviting Users to Codifi](/codifi-docs/getting-started/inviting-users-to-codifi.md)

***

### What's the difference between a Sandbox tenant and a Projects tenant?

**Short answer:** A **Sandbox** tenant is for building and testing Compositions, training new staff, and demoing work. A **Projects** tenant is the production environment where real client work lives. Most orgs have both; user accounts can belong to multiple tenants and switch between them from the avatar menu.

***

### How do I move a user between tenants?

**Short answer:** Users aren't moved — they're **invited to additional tenants** from each tenant's admin area. Their account stays the same; the tenants are added to their access list.

***

### How are permissions controlled?

**Short answer:** Through **Roles-Based Access Controls (RBAC)**. Roles bundle permissions; users get one or more roles per Project (and an organization-level role for tenant-wide settings).

**See:** [Roles-Based Access Controls](/codifi-docs/cross-platform-features/roles-based-access-controls-rbac.md)

***

### A user is reporting they can't log in.

**Short answer:** Common causes in order: (1) account deactivated, (2) password expired, (3) they're on the wrong tenant, (4) they're stuck on the multi-factor step. Check the user's status in the admin area first.

**Since v3.3** sign-in starts with the email address and Codifi works out the method from there, so "which login button do I press" is no longer a cause. If they're stuck at the code screen, see the MFA questions below.

**See:** [How to Access Codifi](/codifi-docs/getting-started/how-to-access-codifi.md)

***

### How long do login sessions stay alive?

**Short answer:** Tokens expire after a period of inactivity. We recommend field crews **log in the night before a field day** so their session is fresh when they arrive on site without service.

***

### Can I see who did what across the org?

**Short answer:** Per-Project, use **Project History**. For tenant-wide auditing, contact Codifi support — additional audit data is available on request.

***

## New in v3.3

### How do we turn on multi-factor authentication for our organization?

**Short answer:** Talk to Codifi. MFA is switched on for your organization at the identity layer, and there is **no toggle for it in the web app's admin settings**, not on the tenant and not per user.

**What to expect once it's on:** the next time each user signs in, they're walked through enrollment with a QR code before they can continue. There's no skip and no "remind me later," so plan the switch-on date around your field schedule rather than dropping it on a crew the morning of a survey.

**See:** [How to Access Codifi](/codifi-docs/getting-started/how-to-access-codifi.md)

***

### A user lost the phone with their authenticator on it. What do I do?

**Short answer:** Nothing. They can do it themselves, and there's no admin screen for it. On the code entry screen there's a **"Lost your device? Reset MFA"** link. They enter their email, get a reset link, confirm it, and re-enroll with a fresh QR code on their next sign-in.

**One catch worth knowing:** that link only appears **after** they've entered their email and password successfully. If they've lost the phone *and* forgotten the password, have them reset the password first, then the MFA reset link becomes reachable.

**See:** [How to Access Codifi](/codifi-docs/getting-started/how-to-access-codifi.md)

***

### Can I reset another user's MFA on their behalf?

**Short answer:** No. There's no admin action for it, by design: the reset link goes to the user's own mailbox, which is what makes it safe to expose without a support ticket.

***

### What does the ten Project device limit mean for us?

**Short answer:** Only that a field device carries up to ten Projects at a time. **Project membership is unlimited** and nothing about your assignments or permissions changes. Crew members choose which ten are downloaded and swap them as work moves.

**On upgrade day:** anyone with more than ten Projects on their iPad is asked once to pick which to keep. The rest are offloaded, not deleted, and they stay members of all of them.

**See:** [Managing Projects on Your Device](/codifi-docs/mobile-app/getting-in-the-field/managing-projects-on-your-device.md)

***

### Does Nearby Sync send our data anywhere new?

**Short answer:** No. Nearby Sync moves data **directly between devices** that are already members of the same Project, over their own Wi-Fi and Bluetooth radios. It doesn't route through a third party, and it doesn't give anyone access to a Project they weren't already on.

**See:** [Nearby Sync](/codifi-docs/mobile-app/getting-in-the-field/nearby-sync.md)
