Firstbase is updating how user emails work. The previous primary email and secondary email labels are being replaced with identity email and company email. Each address can be used to sign in, and you manage them separately in the People section.
This guide explains what each email type means, how users sign in with either one, what changed in the admin experience, and how notification preferences work.
This update is being rolled out to organizations in phases. If your organization has not been migrated yet, you will continue to see the primary and secondary email labels until the update is enabled for your account.
Understanding identity email and company email
Firstbase now uses two distinct email types for each person. They replace the previous primary and secondary email labels.
Identity email (formerly primary email)
- Personal login tied to a person across organizations
- One identity email links to one account
- A user can sign in with it to access every organization they belong to under that identity
Company email (formerly secondary email)
- Organization-specific corporate address for your company
- Has its own login and routes the user directly to your organization when they sign in with it
Key points
- A person can have an identity email, a company email, or both (at least one is required when adding someone)
- When both are present, each has its own login. Users can sign in with either address
- The same person across multiple organizations typically shares one identity email but may have different company emails in each organization
- Admins can update identity and company email on a person record, as long as both values stay unique and valid
Working across multiple organizations
If a user belongs to more than one organization under the same identity, Firstbase provides two ways to choose which organization they are working in:
- Company picker: After signing in with identity email, users who belong to multiple organizations see a Choose a company screen where they select which organization to enter.
- Company switcher: While signed in, users can scroll to the bottom of the left navigation sidebar, click My Company, and under Switch Company select another organization without signing in again.
Signing in with company email always routes directly to that organization, so the company picker does not appear on that login path.
How users sign in with identity email or company email
Users can sign in with either email when both exist. Which one they use determines what happens after login.
Sign in with company email
- User signs in with their company email.
- They go directly to your organization.
- They land in the app with permissions for that organization.
Sign in with identity email (one organization)
- User signs in with their identity email.
- They go straight into the app.
Sign in with identity email (multiple organizations)
- User signs in with their identity email.
- They see the Choose a company screen (see above).
- They select an organization and continue into the app.
Already signed in?
Users who belong to multiple organizations can switch without signing in again:
- In the left navigation sidebar, scroll to the bottom of the menu.
- Click My Company (the row that shows the current organization name).
- In the panel that opens, under Switch Company, select the organization they want to work in.
This works regardless of which email they used to sign in.
Adding and managing people
When you add or edit a person in People, you work with Identity email and Company email as separate fields (replacing the old primary and secondary labels).
Adding a new person
You can provide an identity email, a company email, or both. At least one is required.
Identity email only
- Creates a new identity, or links to an existing one if that identity email is already in use
- The person signs in with their identity email
Company email only
- Creates a company email login for your organization
- The person signs in with their company email for your organization
Both emails
- Each address has its own login
- The person can sign in with either email
- Set their notification preference (Identity, Company, or Both)
Adding someone with an identity email that is already in use
If the identity email you enter is already tied to an existing identity in Firstbase, the person is added to your organization as Invited. They must sign in with their identity email and select Join for your organization on the Choose a company screen before they have access.
Editing email addresses
You can update identity and company email on an existing person record. Both addresses must remain unique and different from each other.
Once an email has been saved on a person record, it cannot be removed. You can change it to a different valid address, or add the other email type later if it was not set at creation.
Company email already in use
Firstbase blocks adding or updating a person if the company email is already assigned to another active user, including across organizations. Use a different company email, or add the person with identity email only if they should join through an existing identity.
Setting notification preferences
When a person has an identity email, a company email, or both, you can choose where operational notifications are sent. This is separate from which email they use to sign in.
Options
| Preference | Notifications go to |
|---|---|
| Identity | Identity email only |
| Company | Company email only |
| Both | Both addresses (as separate emails) |
When it applies
Notification preference controls operational emails such as orders, replacements, returns, and offboarding updates.
When adding or editing a person
- Options are only available when the corresponding email is set. For example, Company is disabled if there is no company email.
- The default is Both when both emails can be provided.
Activation and invitation emails (separate from notification preference)
- New person, identity email only: Activation email to identity email (if you choose to send an invite when adding them)
- New person, company email only: Activation email to company email
- New person, both emails: Activation to each new login (identity and company, when they are different addresses)
- Existing identity, added to a new organization: Organization invitation email (no new activation link)
- Both emails, existing activated identity: Activation to company email if that login is new; organization invitation to identity email
Resend activation
Each email has its own Actions menu on the person profile. To resend activation for a specific login, open Actions next to that email (identity or company) and select Resend activation email. This only applies to the email you chose and is not affected by notification preference.
What's new in the People profile
The person profile in People has been updated to reflect the new email model.
Updated email fields
- Primary email and Secondary email are now Identity email and Company email
- Each email appears in its own section under Emails
- Notification preference appears as a separate field below the email sections
Status badges
Each email can show status badges that help you understand the person's login setup:
- Activation status — whether that email's login is activated, pending activation, or not yet provisioned
- Login type — whether the person signs in through SSO or a Firstbase login for that email
Actions per email
When viewing someone else's profile, each email has its own Actions menu. From there you can:
- Send or resend an activation email for that specific login
- Reset the password for that login (when eligible)
Actions apply to the email you selected. Identity and company email are managed independently.
Pending email changes
If an identity email change is in progress, the profile may show a Pending email change indicator with the destination address. The current email remains visible until the change is complete.
FAQs
What's the difference between identity email and company email?
Identity email is a personal login tied to a person across organizations. One identity email links to one account, and a user can sign in with it to access every organization they belong to under that identity.
Company email is an organization-specific corporate address. It has its own login and routes the user directly to your organization when they sign in with it.
A person can have one or both. When both are present, each has its own login and the user can sign in with either address.
Which email should my users sign in with?
Either works when both are set. The difference is where they land after sign-in.
Company email — best when someone only needs access to your organization. They go straight into your org with no company picker.
Identity email — used for personal email addresses, including during onboarding when someone does not yet have access to their company email. It is also the right choice when someone belongs to multiple organizations under the same identity. In that case, they may see the Choose a company screen after sign-in if they belong to more than one organization.
Users who belong to multiple organizations can also switch companies from My Company in the left navigation without signing in again.
When does a user see the company picker?
The Choose a company screen appears after sign-in when the user signed in with their identity email and they belong to two or more organizations under that identity.
It does not appear when the user signed in with their company email, or when they signed in with identity email but belong to only one organization.
Users who belong to multiple organizations can also switch companies at any time from My Company at the bottom of the left navigation sidebar, under Switch Company.
What happens when I add someone with an identity email that's already in use?
If the identity email you enter is already tied to an existing identity in Firstbase, Firstbase does not create a duplicate account. The person is added to your organization as Invited.
The person shows as Invited in your organization until they complete the join step. They receive an email about the new organization invitation. You can still add a company email for your organization if needed.
To get access, the user signs in with their identity email, finds your organization under Invitations on the Choose a company screen, and selects Join (they can also Decline). Until they join, they do not have access to your organization.
You do not need to know whether the email is used elsewhere before adding the person. Firstbase handles this automatically when the identity email matches an existing identity.
What happens if I try to add a company email that's already in use?
Firstbase blocks the action. A company email cannot be assigned to more than one active user, even across organizations.
If the company email belongs to someone else, use a different company email or add the person with identity email only if they should access your organization through an existing identity.
You cannot use the same address for both identity and company email on one person, or use someone else's identity email as a company email for a different person.
The same person can belong to multiple organizations through their identity email, not by reusing the same company email across different people.
Can I remove an identity or company email after it has been added?
No. Once an identity or company email is saved on a person record, it cannot be deleted or cleared.
You can change either email to a different valid address, or add the other email type later if it was not set when the person was created. Each saved email may be tied to a login account.
How do notification preferences work?
Notification preference controls where operational emails are sent (orders, replacements, returns, offboarding updates, and similar). It does not control which email someone uses to sign in.
Choose Identity, Company, or Both. Options are only available when the corresponding email is set. The default is Both when both emails can be provided.
Activation and invitation emails follow separate rules and are not controlled by notification preference.
How do I resend an activation email?
Each email has its own Actions menu on the person profile. Open Actions next to the email that still needs activation and select Resend activation email. This only resends activation for that specific login.
How do admins reset a user's password?
Open the person's profile in People, click Actions next to the identity or company email, and select Reset password. Firstbase sends a password reset email to that specific address.
Reset is available when the person is Active or Offboarding and that email's login has been activated.
Identity email uses a Firstbase login. Company email depends on your organization's setup: if your organization uses SSO for company email login, password reset is not available for company email. If your organization uses Firstbase login for company email, password reset is available when eligible.
How does this affect users who sign in with SSO?
If your organization uses SSO, users continue signing in with their company email through your SSO provider. SSO configuration remains per organization.
Identity email is a separate Firstbase login and is not backed by your organization's SSO, even if SSO is enabled. The same person can belong to other organizations through their identity email, separate from the SSO login path for your organization.
If SSO users have login issues, work with your IT team or identity provider to verify SSO configuration and IdP settings. SSO authentication is managed outside Firstbase.
What happened to email swapping?
With the updated email model, email swapping is no longer used for organizations on multi-tenancy.
Previously, users could only sign in with their primary email. Admins used email swapping to change which email was primary, or automations could swap personal and work emails based on employment status.
Now, identity email and company email are separate, and each can have its own login. Users can sign in with either address directly. Set identity and company email correctly when adding or editing a person, and choose notification preference for operational emails. For integrations, personal and work emails map directly to identity and company email without automatic swapping.
You can still update either email address on a person record. What changed is the old swap workflow used to change which email controlled sign-in.
What changed about the Actions menu on a person's profile?
The old ellipsis (...) menu at the top of a person's profile has been replaced with a labeled Actions dropdown.
Actions at the top of the profile
Use the Actions button next to the person's name for person-level workflows, such as:
- Begin offboarding
- Reactivate person
- Assign equipment
- Place order for person
- Initiate return
- Initiate replacement
- Delete person (when available)
Actions next to each email
Email-specific actions now live in their own Actions menu next to Identity email or Company email on the Profile tab. Use these for actions tied to a specific login, such as:
- Send or resend activation email
- Reset password
- Resend offboarding email
This makes it clear which email each action applies to, especially when a person has both identity and company email.
Edit profile
To update a person's details (including identity or company email), use the Edit profile button on the Profile tab. That is separate from both Actions menus.
[Screenshot: Actions dropdown at the top of a person's profile]
Is this available for my organization?
This update is being rolled out to organizations in phases. Not every organization has it yet.
How to tell if your organization has been migrated:
- Person records show Identity email and Company email instead of primary and secondary email
- Users who belong to multiple organizations see My Company with a Switch Company option in the left navigation
- The Choose a company screen appears after sign-in for users with identity email access to multiple organizations
If you still see primary and secondary email labels, your organization has not been migrated yet. If you are unsure whether your organization is included in the rollout, contact your Firstbase account team.
Comments
0 comments
Please sign in to leave a comment.