Holarch

Getting Started

Your Account

Create your account from an invitation, sign in, verify your email, reset or change your password, change your email, manage signed-in devices, and delete your account.

How to use it →

On this page
  1. Concepts
  2. How to use it
    1. When and why
    2. Accept an invitation and create your account
    3. Sign in
    4. Reset a forgotten password
    5. Open the Account page
    6. Change your name
    7. Change your password
    8. Change your email address
    9. Sign out a device
    10. Worked example: join the CubeSat EO-1 team
    11. Tips and good practice
    12. Common mistakes
    13. How it connects
  3. The sign-in screens
  4. The Account page
    1. Account menu
  5. Sessions and devices
  6. Passwords
  7. Data restriction
  8. Deleting your account
  9. Messages
  10. Limits
  11. Related

Holarch on the web needs an account. Accounts are by invitation: a project owner or a site administrator sends you a link by email. Your account holds your name, email address, password, signed-in devices, AI keys and organization memberships. Projects belong to their members, not to one account; see Sharing and Working Together.

Concepts

  • Account: your email address, name and password. The email address is the sign-in name and the address invitations are sent to.
  • Invitation: an email with a link. A project invitation adds you to a project with a role; an account invitation from a site administrator lets you create an account. Both links work once and expire after 7 days.
  • Verified email: an address you proved you own by opening a link sent to it. Accounts created from an invitation link are verified by that link.
  • Session: one signed-in browser or device. Each session ends after 14 days without use, and after 90 days in any case.
  • Data restriction: the confirmation that you will not store regulated information in Holarch. You give it when you create your account.
  • Password check: sensitive changes (email, password, account deletion, AI keys, administration) ask for your current password.

How to use it

When and why

You set up your account once, at the start of a project or a course, from the invitation you receive. Afterwards you use the account page to keep your name current for your team, change your password, sign out a lost or shared device, and close the account when you leave.

Accept an invitation and create your account

  1. Open the link in the invitation email ("Open the invitation" or "Create your account").
  2. Holarch shows what you are invited to, for example "Alex invited you to “CubeSat EO-1” as Editor."
  3. Without an account, the Create your account screen appears:
    1. Email is filled in from the invitation and cannot be changed.
    2. Enter Your name (shown to other members, up to 100 characters).
    3. Enter a Password and Repeat the password. Rule: "At least 12 characters; not a common password or your email address."
    4. Read the data restriction and select the box: "Do not store CUI, export-controlled (ITAR/EAR) or classified information in this service." Create Account stays off until it is selected.
    5. Click Create Account. The notice reads "Account created." and the project opens on its Home page.
  4. With an account already, the Join project screen asks for your Password; click Sign In and Accept. When you are already signed in with the invited address, click Accept Invitation. The notice reads "Joined “Project” as Editor."

If you are signed in with a different address, the screen says "This invitation is for address. Sign in with that address to accept it." Click Sign In with Another Account.

Sign in

  1. Open Holarch. Without a session, the Sign in screen appears: "Use the email address your invitation was sent to."
  2. Enter Email and Password, then click Sign In.
  3. Holarch opens the page you asked for, or Manage Projects.

Reset a forgotten password

  1. On the Sign in screen, click Forgot your password?.
  2. On Reset your password, enter your email address and click Send Reset Link. The answer is always "If the address is registered, a message was sent."
  3. Open the link in the email "Reset your Holarch password" within 1 hour.
  4. On Choose a new password, enter New password and Repeat the new password, then click Set Password and Sign In.
  5. You are signed in. The notice reads "Password changed. Other devices were signed out."

Open the Account page

Click your initials at the right of the top bar and choose Account Settings, or press ⌘K and choose Account Settings.

Change your name

  1. Under Profile, edit Name.
  2. Click Save Name. The status reads "Name saved." Other members see the new name in member lists, presence badges and comments.

Change your password

  1. Under Password, enter Current password, New password and Repeat the new password.
  2. Click Change Password. The status reads "Password changed. Your other devices were signed out." You get an email "Your Holarch password was changed".

Change your email address

  1. Under Email, enter New email address and Current password.
  2. Click Change Email. The status reads "Check the new address for a confirmation link." The card then shows "Waiting for confirmation: new address. Open the link sent to that address."
  3. Open the link in "Confirm your new email address" within 24 hours. The screen Email changed reads "Your account email is now address. Other devices were signed out." Click Open Account Settings.

Your old address receives "Your Holarch email address is changing" when you ask for the change and again when it is complete. Until you open the link, you keep signing in with the old address.

Sign out a device

  1. Under Signed-in devices, find the device by browser, address and last activity.
  2. Click Sign Out in its row. The notice reads "Signed out that device."
  3. To end every other session, click Sign Out Other Devices and confirm Sign Out Others. To end all sessions including this one, click Sign Out Everywhere and confirm.

Worked example: join the CubeSat EO-1 team

  1. Your lead shares the CubeSat EO-1 demo project with you as Editor. You receive "Alex shared “CubeSat EO-1” with you".
  2. You open Open the invitation, enter your name "Sam Rivera", choose a 16-character passphrase, select the data restriction box and click Create Account.
  3. The project opens on Home. Sam's initials appear on Alex's screen next to the save status.
  4. A week later you use a lab computer to review the power budget and forget to sign out. From your laptop, open Account Settings → Signed-in devices, find the row "Chrome on Windows" with the lab address, and click Sign Out.
  5. At the end of the semester you transfer the projects you own to your lead (see Sharing and Working Together), then delete your account.

Tips and good practice

  • Use a passphrase of several words. Holarch refuses common passwords and passwords from published leak lists.
  • Sign out on shared computers. Signing out removes your cached projects from that browser.
  • Keep your name recognizable: it is what your team sees on presence badges, comments and the member list.
  • Transfer ownership of shared projects before you delete your account.

Common mistakes

  • "Verify your email address first." Your account was created without an invitation link and is not confirmed. Click Resend the Verification Link on the sign-in screen and open the link within 24 hours.
  • "This link has expired or was already used. Request a new one." Links work once: invitations for 7 days, password resets for 1 hour, email confirmations for 24 hours. Ask for a new invitation or reset.
  • The reset email does not arrive. Check the spam folder. Holarch sends at most 3 messages per address per hour, and says the same thing whether or not the address has an account.
  • "This invitation is for another address." Sign in with the invited address, or ask the owner to invite the address you use.

How it connects

  • Sharing: invitations add you to projects with a role. See Sharing and Working Together.
  • AI: your AI keys and your organizations are on the Account page. See AI.
  • Administration: site administrators manage accounts, can disable them and send password resets. See Administration.

The sign-in screens

All sign-in screens show the Holarch logo and, at the bottom, "Not for CUI, ITAR/EAR or classified information."

ScreenTitleFields and buttons
Sign inSign inEmail, Password, Sign In, Forgot your password?. Under the form: "Accounts are by invitation. Ask a project owner or the site administrator to invite you."
Forgotten passwordReset your passwordEmail, Send Reset Link, Back to sign in.
Reset linkChoose a new passwordNew password, Repeat the new password, Set Password and Sign In, Back to sign in.
Project invitation, new accountCreate your accountEmail (fixed), Your name, Password, Repeat the password, data restriction box, Create Account.
Project invitation, existing accountJoin projectEmail (fixed), Password, data restriction box, Sign In and Accept, Forgot your password?.
Project invitation, signed inJoin projectAccept Invitation, Sign In with Another Account.
Account invitationCreate your accountAs for a project invitation; you start on Manage Projects.
Invalid invitationInvitation not valid"This invitation has expired or was already used. Ask the person who invited you to send a new one." Go to Sign In.
Email verification linkEmail verified / Link not valid"Your email address is confirmed. Sign in to continue." Go to Sign In or Continue.
Email change linkEmail changed / Link not validOpen Account Settings or Go to Sign In.

When the server offers open sign-up, the Sign in screen shows "No account yet? Create an account". The Create an account screen asks for Email, Your name and Password plus the data restriction, and sends a verification link: "Check your email to finish signing up."

The Account page

Title: Account Settings. Sign Out is in the top bar. The page has these cards:

CardContents
Profile"Shown to the members of your projects. Account created date." Name, Save Name.
Email"Signed in as address", a Not verified chip when unverified, a pending change if any. New email address, Current password, Change Email.
Password"At least 12 characters; not a common password or your email address. Changing it signs out your other devices." Current password, New password, Repeat the new password, Change Password.
Signed-in devices"Sessions end after 14 days without use, and after 90 days in any case." Table: Device, Address, Signed in, Last active, Sign Out per row; This device marks the current one. Sign Out Other Devices, Sign Out Everywhere.
AI keysYour AI keys and which key your requests use. See AI.
OrganizationsThe organizations you belong to, their keys, and for org admins members and usage; Create Organization. See Administration.
InvitationsShown when project invitations to your address are pending: project, role, sender and expiry, with Accept and Decline.
AdministrationSite administrators only: Invite People and Open Admin.
Delete accountSee below.

Account menu

Click your initials at the right of the top bar. The menu shows your name and email, then Account Settings, AI Settings…, Admin (site administrators) or Organization Settings (org admins), and Sign Out.

Sessions and devices

  • A session ends after 14 days without use and after 90 days in any case.
  • A new session starts at every sign-in, password change, password reset and email change.
  • Changing or resetting your password, and confirming a new email address, sign out every other device.
  • Sign Out (account menu or the Account page) signs out this browser and removes your cached projects from it. The sign-in screen then reads "Signed out."
  • Sign Out Everywhere signs out every device: "Signed out on every device."
  • When a session ends while you work, the sign-in screen reads "Your session ended. Sign in again to continue; unsaved changes are kept in this browser."

Passwords

RuleMessage
At least 12 characters"The password is too short. Use at least 12 characters." (sign-in screens) or "Use at least 12 characters."
At most 256 characters"Use at most 256 characters."
Not a common or repeated pattern"This password is too common. Choose another one."
Not in published leak lists"This password appears in published lists of leaked passwords. Choose another one."
Not your email address or its name part"Do not use your email address as the password."
Both entries match"The passwords do not match. Type the same password twice."

Data restriction

Holarch on the web is not approved for regulated government information. Do not store or upload any of the following in projects, documents, attachments, comments or AI requests:

  • Controlled Unclassified Information (CUI), including information marked CUI, FOUO or similar.
  • Export-controlled information: technical data under ITAR or the EAR, or marked EXPORT CONTROLLED.
  • Classified information at any level.
  • Other information that a contract or regulation requires to be kept in an authorized environment.

The service runs on commercial cloud infrastructure without a government authorization (such as FedRAMP), and AI requests go to the AI provider of the key in use.

You confirm this restriction when you create your account. Holarch records the date and the version of the text you confirmed. When the text changes, you confirm the new version the next time you accept a project invitation (Confirm the Data Restriction). Without the confirmation, the server answers "Confirm that you will not store CUI, export-controlled (ITAR/EAR) or classified information here."

If regulated data was stored by mistake, delete it and tell your security officer. Model with unrestricted, generic or sanitized data instead. See Data You Must Not Store Here.

Deleting your account

  1. Open Account Settings → Delete account: "Deletes your account and every project where you are the only member. Projects shared with others stay with them; transfer ownership first where you are the only owner. This cannot be undone."
  2. Enter Current password and click Delete Account….
  3. Confirm Delete Account: "Delete the account address and your unshared projects for good?"
  4. The sign-in screen reads "Your account was deleted."

What happens:

  • Projects where you are the only member are deleted at once, together with their versions.
  • Projects with other members stay with them. Where you are the only owner of such a project, deletion is refused: "Transfer ownership of these projects first, or remove their other members." followed by the project names. Transfer ownership or remove the other members, then try again.
  • Your sessions, memberships and pending links end.

Messages

MessageMeaning and fix
"Enter your email and password."A field is empty.
"Email or password is incorrect."Check both. After repeated failures sign-in waits longer each time.
"Too many failed sign-ins for this account. Try again later."More than 10 failed attempts in an hour. Wait, or reset the password.
"This account is disabled. Contact the administrator."A site administrator disabled the account.
"Verify your email address first. Check your inbox for the link, or send it again."Click Resend the Verification Link.
"If the address is registered, a message was sent."Always shown for reset and resend requests, so addresses cannot be probed.
"This link has expired or was already used. Request a new one."Request a new link.
"This link is incomplete. Request a new one."The link was cut off when copied.
"Confirm the data restriction to create the account." / "…to accept the invitation."Select the data restriction box.
"An account with this email address already exists. Sign in, then accept the invitation."Click Sign in instead.
"Sign-up needs an invitation. Ask an administrator or a project owner to invite you."Open sign-up is off.
"The current password is incorrect." / "Enter your current password."The password check failed.
"This is already your email address."Enter a different address.
"This email address now belongs to another account."Someone registered the new address before you confirmed it.
"Enter a valid email address." / "Enter a name of 1 to 100 characters."Fix the field.
"Session not found."The device was already signed out.
"The server is not reachable. Check the connection, then try again."No connection.
"Too many attempts. Try again later."A rate limit (see below). Wait, then try again.

Limits

  • Invitation links: 7 days. Password reset links: 1 hour. Email verification and email change links: 24 hours. Each link works once.
  • Sessions: 14 days idle, 90 days absolute.
  • Sign-in: 5 attempts per account and 10 per network address per minute; after 10 failed attempts in an hour, each further attempt waits longer, up to 15 minutes.
  • Emails (reset, verification, sign-up): 3 per address and 5 per network address per hour.
  • Password checks on the Account page: 10 per hour.
  • Name: 1 to 100 characters. Password: 12 to 256 characters.

Last updated October 7, 2026