Accounts
Your login belongs to you. Your profile belongs to the organization. How roles, profile, notifications, security, and account deletion work.
Two kinds of accounts
There are two records, and they are not the same thing.
Your Base Assist Auth Account is how you sign in. Your organization profile is who you are inside a company.
One login can open more than one organization. Each organization keeps its own profile for you.
Your Auth Account
The Auth Account belongs to you. It is the email, password, passkeys, and verification methods you use to sign in.
It is not owned by any one organization. If you work with three companies on Base Assist, you still have one Auth Account.
Security settings live on this account. Changing your password or turning on a verification app applies everywhere you sign in.
Your organization profile
The organization profile belongs to the organization. It is your name, photo, title, phone, work hours, and the rest of the directory record for that company.
Admins, Super Admins, and the Owner can edit it. You can also edit the parts of your own profile that the company leaves open to you.
If you leave, that profile stays with the organization. Time, expenses, files, and other work stay on their records too.
One login, many organizations
Sign in once. Switch organizations from the app when you belong to more than one.
Each organization has its own profile, notification settings, and directory record. Security stays on your Auth Account, so a password change covers every organization you can open.
Owner
The Owner is the person the organization belongs to.
They carry the organization: billing, closing it, and who holds the account. An Owner is usually also a Super Admin.
If the Owner wants their Auth Account deleted, they email support@baseassist.com. We have to process the organization out before that login can be removed. Do not use Delete account in Security for this.
Super Admin
Super Admin is full control of the organization.
They can open Governance, manage the directory, assign products, set organization security, and edit organization profiles. They can do everything an Admin can do, plus the organization-wide settings that sit in Governance.
Super Admin is a role on the organization profile, not on the Auth Account. Someone can be a Super Admin at one company and a regular member at another.
Admin
Admin can run the organization day to day.
They can manage people, edit organization profiles, and use admin tools in the apps they are given. They do not own the organization.
Product admin permissions (Time admin, Cabinet admin, and others) can be given without the Admin role. Those only open admin screens for that app.
Who can edit a profile
You can edit some of your own profile. The organization can edit the rest.
From Settings, then My Profile, you can change photo, preferred name, bio, skills, phone, and work hours.
The Owner, Super Admins, and Admins can edit the directory record: legal name, email, title, department, location, employment, products, and account status.
Name and work email on the directory are organization fields. Ask an admin if those need to change.
Open My Profile
Go to Settings, then My Profile. That page is the profile for this organization, not a global profile for every company you belong to.
Switch organizations first if you meant to edit the profile at a different company.
What you can set
These fields live on the profile for this organization.
On My Profile you can set:
Profile photo and banner
Preferred name
Bio
Skills
Phone
Work hours and time zone
Work hours also drive quiet hours on Notifications. Set the hours before you turn quiet hours on.
Organization email is shown on the profile and is not edited there.
What the organization controls
Admins, Super Admins, and the Owner can change the directory record.
That includes first and last name, work email, title, managers, department, location, groups, products, and whether the profile is active.
They can suspend or deactivate a profile without deleting your Auth Account. You would not be able to open that organization until they restore access.
Notifications are per organization
Go to Settings, then Notifications. These choices apply only to the organization you are in now.
A mention at one company does not use the settings from another. Switch organizations to change the other one.
Delivery methods
Turn a method off to stop every notification of that kind in this organization.
Push: alerts on your phone or tablet
Local: in-app alerts and on-device banners
Email: messages to your organization email
Sign-in and password emails are security messages. They are not turned off here.
Quiet hours
Quiet hours pause push outside the work hours on the profile for this organization.
Set work hours on My Profile first. Then turn on Use working hours as quiet hours.
Quiet hours do not stop email or in-app alerts.
Notification types
Each type can use push, local, and email.
The list includes mentions, comments, tasks, projects, approvals, time, expenses, files, chat, calls, and the other types this organization uses.
Turning a method off at the top disables that column for every type.
Security belongs to you
Go to Settings, then Security. These settings are on your Auth Account, not on one organization.
A password change, a new passkey, or a signed-out device applies everywhere you use that login.
Password and sign-in
Reset your password from Security.
Use at least 8 characters, with uppercase, lowercase, a number, and a special character. Other devices are signed out when the password changes.
You can also connect Apple, Google, or GitHub if those options are shown.
Extra verification
Add a second way to prove it is you.
Use a verification code app (Apple Passwords, Google Authenticator, or another TOTP app), email codes, or passkeys.
Use more than one method when you can. If you lose the phone with the app, a passkey or email code is how you get back in.
Devices and sessions
Active Sessions lists every device where you are signed in.
Sign out a device you do not recognize, or sign out of all other devices. Revoke removes that session so the device has to sign in again.
New login alerts
Turn on New login alerts to get an email when someone signs in to your Auth Account.
Those alerts are account security messages. They are not the same as organization notification settings.
How to request deletion
How you delete depends on whether you are the Owner of an organization.
If you are the Owner
Email support@baseassist.com.
Say you are the Owner and you want the account deleted.
We process the organization out. Do not use Delete account in the app for this.
If you are not the Owner
Open Settings, then Security.
Under Danger zone, choose Delete account.
Enter your password, and your verification code if you use one.
Confirm that organization profiles will stay with each company.
Your Auth Account is deleted. You cannot sign in after that.
Ask each organization if you want your information removed from their records. That decision is theirs.
Deleting your login does not remove you from organization records. Read what is deleted and what stays before you continue.
If you are the Owner
The organization is tied to the Owner. Billing, people, files, and the records the company must keep all sit on that account.
Email support@baseassist.com. Tell us you are the Owner and you want the account deleted. We process the organization out. That can mean transferring ownership or closing the organization. We will tell you what we need from you.
Do not use Delete account in Security while you are still the Owner. That request has to go through support.
If you are not the Owner
You can delete your Auth Account from Settings, Security.
That removes your login. It does not delete organization profiles or work records. Those belong to each organization.
Ask each organization to remove your information if that is what you want. A lot of that data has to stay intact for reporting and regulation. The organization decides what they can remove.
If you want access again later, ask that organization to add you back. Deleting the Auth Account does not create a request on their side.
What is deleted
When an Auth Account is deleted, the login is removed. Organization records are not.
This happens when you delete the Auth Account yourself, or when support finishes an Owner request.
We remove:
The Auth Account. Sign-in email, password, and linked sign-in providers.
Verification methods on that login. Authenticator apps, email codes, and passkeys.
Active sessions. Every device is signed out.
The link from your login to each organization profile. The profiles themselves stay with the organizations.
We do not keep that login so you can sign back in later. A new Auth Account is a new login.
What stays with the organization
Organization data belongs to the organization, including user information on the directory.
That includes, and is not limited to:
Your organization profile. Name, photo, title, phone, department, location, skills, and work hours.
Time. Time entries, time reports, and time off.
Money records. Expenses, invoices, payments, and payroll.
Work records. Files, chats, tasks, projects, and approvals.
History. Audit logs and other records the company keeps for reporting.
We do not delete those records when you delete your Auth Account. Organizations keep them as long as they need them for payroll, tax, audit, and other regulation. There is no automatic purge after you leave.
If you want personal details taken off a directory, ask that organization. They may still keep work records that name you.
Getting added back
Deleting your Auth Account does not remove you from an organization, and it does not ask them to add you later.
To come back, reach out to that organization. An Owner, Super Admin, or Admin can add you and send an invite. You will create a new Auth Account, or sign in with a login they attach to your profile.
They decide whether to restore the same profile or start a new one.