There are five doors, and which one a person uses depends entirely on who they are. Only staff use a password.
Staff sign-in
Email and password, with a Forgot your password? link on the sign-in page. Reset links last one hour and can be used once; using one signs the account out everywhere.
There is no public sign-up. Staff accounts are created by an administrator, who sets the password directly.
The simplest handoff: create the account, then immediately use Send password reset. The new user receives an email link and chooses their own password — no credentials change hands.
Rostrum does not currently support single sign-on (SAML, OAuth or corporate identity providers), and there is no two-factor authentication. Sessions last 15 minutes and renew silently in the background for up to seven days of activity.
Magic links for speakers and reviewers
From the Faculty tab you can send a participant a magic link — a one-click sign-in that needs no password. It is deliberately narrow:
- It grants access to that one event and nothing else. Even an administrator who clicks one gets an event-scoped session.
- It expires at the end of the event's last day, in venue time.
- It cannot be used to set or change a password.
This makes it safe to send to a speaker who will never sign in again — they click, they upload, they are done.
Codes for participants and delegates
Submitters, authors and reviewers sign in to the hub by entering their email address and receiving a six-digit code. Delegates do the same in the Attendee App. In both cases, an account is created automatically on first use — participants never register, and never have a password to forget.
For the Attendee App you can decide whether anyone with an email address may sign in, or only addresses on a list you upload.