Getting started

Sign in and find your way around

There is no password to remember: you enter your email address and Conterminal emails you a six-digit sign-in code. Where you land afterwards, and what the left rail shows, are derived from your workspace type rather than from anything you can configure. This covers both, plus the handful of places the behavior is genuinely surprising.

9 minute read · Updated July 26, 2026

What sign-in looks like

Go to /auth/login. The page heading reads Sign in to Conterminal, and the card reads Welcome back above Enter your email to receive a sign-in code.

  1. Enter your work email. The field is labeled Email address with the placeholder you@company.com. Capitalization and surrounding spaces do not matter — the address is trimmed and lowercased before it is looked up.
  2. Select Send sign-in code. The button reads Sending... while the request is in flight, then the card switches to Check your email and repeats the address it used.
  3. Type the six digits. Enter the code in the Sign-in code field and select Sign in. The field accepts digits only, stops at six characters, and the button reads Verifying... while it checks. A short entry is rejected before anything is sent, with Enter the 6-digit code from your email.
  4. Mistyped the address? Select Use a different email to clear the form and start over. Nothing is remembered from the failed attempt.

Sign-in links still work too. If your message carries a link rather than digits — invitation mail and older notification mail often do — opening it verifies the token and drops you straight into the product without ever showing the code field.

An unrecognized address still says “Check your email.”

The login page will not create an account, and it deliberately does not tell an anonymous visitor whether an address exists. If your address has no user record, you get the same Check your email screen and no message ever arrives. Waiting longer will not help. Check the spelling, then check whether you were added under a different address.

Use password instead
A second button below the submit control. It swaps the form to an email-and-password pair for the few accounts that have a password set, and the toggle then reads “Use a sign-in code” to switch back. A bad pair returns “Unable to sign in with those credentials.”
Sign in with passkey
Appears above the email form only when passkeys are turned on for the deployment and your browser supports them. If you do not see the button, passkeys are not available to you and the emailed code is the way in.

Your first sign-in

There is no self-serve signup for a workspace. Someone has to add your address first — an admin on your own organization, or a partner who sent you a collaboration invite. Two things are different about that first sign-in.

You came in through a collaboration invite

An invite link carries a token, so after you authenticate Conterminal sends you to the invite screen instead of your workspace. Signed out, you see Review Collaboration Invite with the recipient email and a supporting delivery-order count, and a Continue with Magic Link button. Signed in, you see Accept Collaboration Invite with a required Full name field. Accepting also pins that organization as your active workspace, which matters if you belong to more than one.

If you are already signed in as someone the invite was not addressed to, the screen reads Sign In With The Intended Account and shows both addresses side by side, with a Sign Out And Switch Account button. An invite token always outranks any other destination in the URL.

Your memberships are reconciled at the door

Every sign-in re-reads the organization memberships attached to your email address and syncs your role assignments before deciding where to send you. That is why a membership an admin added five minutes ago works on your next sign-in with nothing else to do, and why a removed membership takes effect the moment you sign in again.

When passkeys are enabled, the first page after an email sign-in may show a dialog titled Add a passkey? offering Face ID, Touch ID, Windows Hello, a device PIN, or a security key. Selecting No thanks is recorded on your account so it stops asking; you can enroll later from Settings → Security.

Where you land, and why it differs

Your landing page is derived from your workspace type. You cannot set it, and it is not necessarily the page you get by typing /protected into the address bar — those are two different pieces of routing that do not always agree. Here is what each workspace type gets immediately after a successful sign-in.

Carrier (trucking)
/protected/operations/home — the operations overview reached by the Home block at the top of the left rail.
Forwarder / broker
/protected/operations/home — the same operations overview, with a forwarder rail beside it.
Importer (BCO)
/protected/operations — the shipment list, not the overview.
Warehouse
/protected/operations/dashboard — the Container Dashboard.
Personal tracking
/protected/my-tracking. No left rail, and no operations surfaces at all.
Platform admin
/protected/platform, with platform navigation in the header instead of a workspace rail.

Typing /protected takes a different road

/protected is not a page. It redirects to /protected/home, which re-decides your destination on its own rules: carriers are sent to Document Review at /protected/inbox, platform admins to the platform console, and importer, forwarder, and warehouse workspaces to the landing pages listed above. A carrier therefore has two "home" pages depending on which door was used — the operations overview after signing in, Document Review after typing the bare URL. That is expected, not a fault in your account.

Personal-tracking accounts that open /protected see Access Denied.

The dispatcher behind /protected only recognizes carrier, importer, forwarder, warehouse, and platform workspaces. Personal tracking is not on that list, so it falls through to the Access Denied page even though you are signed in and /protected/my-tracking works normally. Go to the tracking URL directly. The same dead end catches any membership whose workspace type was never set, which is worth reporting rather than working around.

Reading the left rail, by workspace type

The rail on the left (labeled Workspace navigation for screen readers) is not shown to everyone. Carrier workspaces get it, and importer, forwarder, and warehouse workspaces get it when they have operations access. Personal-tracking accounts and platform admins get no rail — their navigation sits in the header. The rail is desktop-only in every case; below tablet width, everything moves into the menu button in the header.

Carrier rail

Five groups, top to bottom: a Home block with a house icon; Document Review on its own with no group heading; Tracking (Container Dashboard, Vessel Tracking); Operations (Scheduling, Dispatch); and Back Office (Timecards, Companies, Reporting, Directory, plus Quotes for admins and managers, Drivers for admins, and Billing when you have billing access). Tracking and Operations start expanded; Back Office starts collapsed. Reporting is greyed out on purpose — hover it and the tooltip reads Reports library — coming with the reporting engine.

Forwarder and importer rail

Two groups, neither with a clickable heading, so nothing here collapses. Operations holds Home, then Document Review, Vessel Tracking, and — for forwarders only — Container Dashboard. Importer workspaces additionally get Delivery Appointments for responding to and booking delivery times. System holds Companies, Directory, and Billing when your workspace has billing access.

Warehouse rail

One group, Tracking, holding Container Dashboard, Vessel Tracking, and a greyed-out Scheduling entry whose tooltip reads Scheduling — coming soon. The warehouse rail is deliberately narrower than the forwarder rail even though both are external operations workspaces — Companies and Directory are reachable by URL and from search, just not from the rail.

On any Document Review screen the Document Review entry becomes a toggle that opens a sub-rail of status filters underneath it, with a badge counting what is waiting. Collapsing that sub-rail sticks for the rest of your visit to Document Review and reopens the next time you enter it. The Document Review and Container Dashboard entries also return you to the last list view you had open in that browser tab, filters included, rather than to a bare default.

Why a group you collapsed is open again

Only groups with a visible heading can be collapsed — on the carrier rail that is Tracking, Operations, and Back Office. Their state is deliberately never saved. Clicking a heading applies to the page you are on and is discarded the moment you navigate, at which point the defaults reassert: Tracking and Operations expanded, Back Office collapsed. On top of that, whichever group contains the page you are currently viewing is forced open regardless of anything you clicked. If you keep collapsing Tracking and keep finding it open, nothing is broken and there is no preference to change.

Belonging to more than one workspace

One email address can be a member of several organizations. There is no workspace switcher anywhere in the interface. Conterminal picks one workspace for you and uses it for everything — landing page, rail, permissions, and every list you see.

The preference is held in a browser cookie named pt-active-org-id. Exactly one action writes it: accepting a collaboration invite, which pins the inviting organization. The cookie is server-side only, so you cannot read, set, or clear it from the browser console — and because it carries no expiry, it disappears when you fully quit the browser. When it is absent or names an organization you are no longer a member of, the selection is computed fresh on every request:

  1. Organizations that are inactive, or that were merged into another organization, are dropped first. They are never selectable.
  2. Workspace type decides next: a carrier workspace outranks a forwarder workspace, which outranks importer and warehouse workspaces, and personal tracking ranks below all of them.
  3. Among equals, the membership you have held longest wins.
  4. If two are still tied, the higher role wins — admin over manager over user over collaborator.

The practical consequence: if you dispatch for a trucking company and are also a collaborator on an importer's workspace, you will always land in the trucking workspace and the importer data will simply not appear. That is the selection rule working as designed, not a permissions failure, and nothing in the UI will tell you it happened. Ask support to move your active workspace, or use a separate address for the second organization.

You can always read which one you are in: the user menu at the bottom of the left rail shows your name with the organization name underneath it. Platform sessions show Platform Workspace there instead.

Signing out

  1. Open the user menu — the block showing your name and organization at the bottom of the left rail. On a phone or narrow window, open the menu button in the header instead.
  2. Select Sign out at the bottom of the menu. It ends the session and returns you to the login page.
  3. On the Access Denied page, use that page's own Sign out button — the rail is not always reachable from there.

Platform and personal-tracking sessions have no left rail, and the header menu that holds Sign out only appears at phone and small-tablet widths. On a full-size desktop window those sessions have no visible sign-out control at all. Go to /auth/logout directly — it signs you out and returns you to the login page — or narrow the window until the menu button appears.

Signing out ends your session, but nothing in the sign-out path clears the active-workspace cookie. On a shared or kiosk browser the next person's sign-in can inherit the same preferred organization. On shared machines, sign out and then close the browser completely or clear the site's cookies.

Troubleshooting

“Your magic link has expired. Please request a new one.”

Sign-in codes and links are single-use and short-lived. Select Try again, request a new code, and use the newest email — an older message in the same thread will fail the same way. The wording still says “magic link” even when you asked for a code; it is the same credential either way.

“Invalid or expired link. Please request a new magic link.”

Usually a link that was already used, or one rewritten by a mail client or corporate link scanner. Request a new code and type the six digits into the login page instead of clicking through the email.

“Invalid or missing verification token”

The sign-in URL reached Conterminal without its token, typically because only part of the link was copied or the message was forwarded as plain text. Go back to the login page and request a fresh code.

“Access denied. You are not authorized to access this application.”

You authenticated, but no usable organization membership was found for your address, so Conterminal signed you back out immediately. Either you were never added, the organization was deactivated or merged, or you were invited under a different address. An admin on that organization has to add you — support cannot infer the membership for you.

The code screen appeared but no email arrived

The login page shows Check your email even for an address it does not recognize. Confirm the spelling, check spam and quarantine, then confirm with your admin which address your membership was actually created under.

“Unable to send a sign-in code right now.”

The send itself failed, rather than your address being wrong. Wait a minute and retry; if it repeats, send support the address and roughly when you tried.

“Session verification is temporarily unavailable. Refresh to retry.”

A transient failure verifying your existing session, returned as a plain-text page. Refresh after a few seconds — you should not need to sign in again.

You landed on Access Denied instead of your workspace

On a personal-tracking account, /protected is not a valid destination — go to /protected/my-tracking. Otherwise the page needs a workspace type or role you do not have, and Return to workspace takes you back to your own landing page.

A rail group you collapsed keeps reopening

Working as designed. Group state is never saved, it resets on every navigation, and the group containing your current page is always forced open. There is no setting for this and nothing to report.

You are in the wrong company's workspace

Only accepting a collaboration invite changes your active workspace, and there is no switcher. Closing the browser completely clears the pinned choice and returns you to the automatic ranking. If the ranking itself is putting you in the wrong place, send support your email address and the organization you need.