Login & security policy
Choose which sign-in methods your members may use and who is admitted automatically — your organisation's login policy.
Every organisation on WAQAF decides for itself how its members sign in. The login policy lets you choose which sign-in methods appear on your organisation's sign-in page — email and password, magic link, Google, or Apple — and which new sign-ups are admitted automatically by their email domain. You'd set this when you're tightening security (for example, allowing only one sign-in method) or when you want everyone from your own staff email domain to join without a manual review each time.
Who can do this. You need to be an Owner or Org Admin of the organisation. The login policy lives in organisation settings, which only those roles can open; the server also checks this when you save. If you don't see the Login policy page, your role doesn't allow it — see Roles & permissions reference.
Where to find it. Settings → Login policy. It sits alongside your other organisation settings.
What the login policy controls
The policy has two parts, both on the same page:
- Allowed sign-in methods — a list of toggles, one per sign-in method, that decides what members see on the sign-in screen.
- Auto-approve email domains — a list of email domains whose new sign-ups are admitted automatically as members, with no manual approval.
The login policy is about how people get in, not about your own account's security. Passkeys and two-step verification are set up per person on each member's own account, not here. To turn those on for yourself, see Password, passkeys & 2-step verification.
Choosing allowed sign-in methods
The Allowed sign-in methods list lets you turn each method on or off for your organisation. There are four:
- Email & password — the usual email-and-password sign-in.
- Magic link — a single-use link emailed to the member, with no password.
- Google — continue with a Google account.
- Apple — continue with an Apple account.
Turning a method off here removes it from your organisation's sign-in page, so members never see it as an option.
Open the Login policy page
Go to Settings → Login policy. You'll see the Allowed sign-in methods list at the top and the Auto-approve email domains box below it.
Switch methods on or off
Use the switch beside each method to allow it or remove it. Leave on only the methods you want your members to use. The methods you keep are what your sign-in page will offer.
Save the policy
Select Save policy. WAQAF stores your choice, and the change takes effect on the sign-in page straight away.
You must keep at least one method on. If you switch every method off, the Save policy button is disabled and the page shows "At least one method must stay enabled." — this is a deliberate guard so an organisation can never lock all of its members out.
Allowing a method here can't switch one on platform-wide. Your organisation's sign-in page shows a method only when both WAQAF offers it and your policy allows it. So if magic link or social sign-in isn't available across WAQAF, you won't see it on your sign-in page even after you allow it here — your policy can only ever narrow what's offered, never add to it.
Auto-approving members by email domain
Normally, when someone asks to join your organisation, an Owner or Org Admin reviews and approves the request (see Join requests). The Auto-approve email domains box lets you skip that review for people whose verified email is on a domain you trust — typically your own staff email domain.
Add your trusted domains
In the Auto-approve email domains box, type one domain per line — for example
yourcharity.org. Enter the bare domain only, without the @ and without a
person's name in front of it.
Save the policy
Select Save policy. From now on, a new sign-up whose verified email ends in one of these domains is admitted automatically as a member. Anyone whose email isn't on the list still goes through the usual join-request review.
The match is exact — yourcharity.org admits name@yourcharity.org but
not name@team.yourcharity.org. List each domain you want to trust on its own
line. Add a domain only if you're confident everyone with an address on it should
be a member of your organisation, since they'll join without anyone reviewing
them first.
How the policy reaches your members
Members don't see the policy itself — they see its effect. A member whose organisation allows only email and password, for instance, sees just those fields on the sign-in page, with no magic-link tab or social buttons. This is why two colleagues in different organisations can see different sign-in pages, and why a method you expected might simply not be there. For the member's view of this, see Signing in.
See also
Signing in
The everyday ways members get into the dashboard, and why sign-in pages differ.
Password, passkeys & 2-step verification
Set up passkeys and two-step verification on your own account.
Join requests
Review and approve people asking to join your organisation.
Roles & permissions reference
Which roles can open organisation settings and change the policy.
