# Accounts and organizations

Your **account** is you: your name, your email, and your password. An **organization** is the workspace that owns a portfolio. Every upload, loan, field, and segment belongs to exactly one organization, and the people in it are its **members**, each with one of three roles. Getting in, the roles, and moving between organizations are covered here; the [Account](/account/signing-in-and-sessions/) pages go deeper on sessions, profile settings, and managing a team.

## Creating your account

Sign up with your name, an email address, and a password of at least 8 characters. Any email address works, including a personal one; there is no work-email requirement. Where it is offered, **Continue with Google** signs you up with your Google account instead.

If the email already has an account, the sign-up page says so and offers **Sign in instead**, carrying your email across to the sign-in page.

## Verifying your email

Before you can use the product, Vintage sends a **6-digit code** to the address you signed up with, and you type it back. The step cannot be skipped.

- The code expires after a short window, and there is a limit on wrong attempts. A wrong or expired code shows a message asking you to try again.
- **Resend code** sends a fresh one. After each send it is disabled for **30 seconds** and counts down.

## Creating or joining an organization

Once your email is verified, one of two things happens.

**If you were invited**, you are added to the organization that invited you, at the role on your invite, and you go straight into the product. If several organizations invited you, you join all of them, and one becomes your active organization.

**Otherwise**, you name and create your own organization and become its **admin**. The name is required, and an admin can change it later in Settings.

Every onboarding step shows the account you are signed in as, with a **Use a different account** control that signs you out and returns you to the sign-in page. If you leave partway through, you come back to the step you still owe.

### When an invite reaches an account that already exists

An invite to an email that already has a verified account works through an accept-or-decline choice rather than sign-up:

- If you already belong to an organization, a dismissible **Pending invitations** prompt lists your invites. **Accept** adds you to that organization; **Decline** clears the invite; dismissing the prompt brings it back next time.
- If you have no organization yet, your invites appear as a **Join your team** step before the create-organization step, so you are not pushed into creating an organization of your own when a team is waiting for you.

### Where you land

The first time you arrive after onboarding, a brief **You're all set** confirmation appears once. After that:

- An **admin** or **editor** whose organization has no loans yet lands on the **Uploads** page, ready for a first upload.
- Everyone else lands on **Modeling**. A viewer always lands on Modeling.

While Vintage is setting up a new organization's first portfolio, Modeling, Portfolio, and Fields stay closed. Admins and editors land on Uploads, and viewers land on a page that explains the wait. See [Your first upload](/uploading/your-first-upload/).

## The three roles

Each member of an organization has exactly one role. In decreasing order of access:

**Admin.** Full control. An admin can do everything an editor can, and also manages the team (inviting people, changing roles, removing members), renames the organization, and manages the organization's IP allowlist. The person who creates an organization is its first admin. An organization always keeps at least one admin: Vintage refuses any change that would demote or remove the last one.

**Editor** (shown as "View and update"). Full access to the data: an editor can upload files, map columns, finalize uploads, manage custom fields, and change how the organization's fields are read. An editor cannot manage the team or rename the organization.

**Viewer** (shown as "View only"). Read-only. A viewer can read the portfolio and the Modeling screen but cannot upload or change any data. The **Upload** and **Fields** entries do not appear in a viewer's navigation, and the organization settings and team list are shown read-only.

New invitees start as **viewers**. An admin can choose Editor when sending the invite, or change a member's role afterward. Roles are enforced, not only hidden: a person who reaches a screen their role does not allow sees a page saying they do not have access, and Vintage refuses the action itself. [Roles and permissions](/reference/roles-and-permissions/) has the full matrix.

## Belonging to more than one organization

You can be a member of several organizations, and you work in one at a time: your **active organization**. Everything you see, from the portfolio and uploads to the fields and segments, belongs to it.

The **organization switcher** at the top of the sidebar shows your active organization by name. Its menu lists every organization you belong to, lets you switch to another, lets you create a new organization, and has an **Org Settings** item. Switching changes the whole product over to the newly active organization.

Vintage remembers your active organization across sign-outs and devices, so you return to the one you used most recently. If you are removed from that organization, Vintage moves you to another of your organizations rather than showing you nothing.

**Note:** One organization's data is never shown to someone who is not a current member of it. Removing a member ends their access but keeps their work: their past uploads stay in the organization's history, still showing who uploaded them, and their account is not deleted.

## Sessions and network access, briefly

A session lasts **60 days** and is **rolling**: any use of the product extends it, so you stay signed in while you keep working. See [Signing in and sessions](/account/signing-in-and-sessions/).

An admin can restrict which networks reach the organization by adding IP addresses or ranges to an allowlist under Settings, in the **Security** area. With no rules, the organization is reachable from any network. See [Team and organization settings](/account/team-and-organization-settings/).

## Related

- [Quickstart](/getting-started/quickstart/)
- [Signing in and sessions](/account/signing-in-and-sessions/)
- [Team and organization settings](/account/team-and-organization-settings/)
- [Roles and permissions](/reference/roles-and-permissions/)
- [Your first upload](/uploading/your-first-upload/)
- [Security and data protection](/reference/security-and-data-protection/)