Appearance
Account & Security
How you get into Tenbi, how to protect your account with two-factor authentication, what to do when a password is lost, and which emails Tenbi sends you.
Getting in
Tenbi is in an invite-only alpha. Accounts are created from an invite; if you don't have one yet, join the waitlist below.
Accepting an invite
You'll receive an email with the subject You're invited to Tenbi and an Accept invite button. The link opens a page that has already validated your invite and shows You're invited as your email address — or, if a teammate invited you to their existing workspace, You're joining their workspace as your email address:
- Your Email is fixed — it's the address the invite was sent to.
- Choose a Password (at least 8 characters) and repeat it under Confirm password.
- Click Create account. Your account and workspace are created and you're signed in immediately, landing on First Steps so you can start setting up. (Joining an existing workspace? You land in that workspace instead — its lanes, modules, and skills are already there.)
Invite links work once and expire — the email tells you when. If the page shows "This invite link is invalid, expired, or already used," ask whoever invited you for a fresh invite.
The Terms of Service gate
Before you can use anything, a Before you continue screen asks you to agree to the Terms of Service and Privacy Policy (both linked from the screen, along with how connected credentials are stored). Click Accept & continue to record your acceptance and enter the app, or Sign out if you'd rather not proceed.
You may see this screen again. Your acceptance is recorded against a specific version of the terms. If the terms are ever updated, you'll be asked to accept the new version at your next visit before continuing.
No invite? Join the waitlist
On the sign-in page, click Sign up. While Tenbi is in invite-only alpha the sign-up page is a waitlist — no password is collected:
- Optionally enter a Workspace name (optional) (leave it blank if you're solo) and your Email.
- Click Join the waitlist.
- Answer a short survey — one question per screen, every step skippable via Skip (use Back to revisit).
You'll see "You're on the list" and receive a confirmation email (You're on the Tenbi waitlist). Invites go out in waves — when yours is ready, you'll get the invite email described above and can create your account from it. There's nothing else to do in the meantime.
Bring a Claude credential. Tenbi runs on Anthropic's Claude models — you'll need an Anthropic API key or Claude subscription during onboarding. See First Steps.
Members and roles
Workspaces can hold more than one person. Every member carries a workspace role:
- Owner — the person who created the workspace. Owners can do everything below, and they're the only ones who can change other members' roles. The owner can't be deactivated or demoted.
- Admin — can invite, deactivate, and reactivate members, but can't change roles.
- Member — full access to the product: lanes, modules, credentials, skills, runs, and analytics. Members don't manage other members.
There's nothing to configure for a solo workspace — you're its owner, and you'll only meet these roles if you invite someone.
Inviting a teammate
As an owner or admin, open Workspace → Members in the sidebar:
- Enter your teammate's email under Invite by email and click Invite.
- The invite link is shown once — copy it and send it to them yourself. If the platform mailer is configured they also get the invite email directly. Need it again later? The invite row's menu has Copy invite link — it generates a fresh link and invalidates the old one.
- Your teammate accepts the invite as described above; they join your workspace as a Member.
The page shows current seat usage (for example 2 of 5 seats). If every seat is taken — counting pending invites — the invite is refused; free a seat or revoke a pending invite first. Outstanding invites appear in the People table with an Invited badge (expired ones show Expired); each row's menu lets you copy a fresh link, re-invite after expiry, or revoke. Re-inviting the same email always replaces the earlier link.
Deactivating and reactivating
Deactivate signs the member out everywhere immediately and frees their seat; their work (lanes, run history, audit trail) stays in the workspace. Reactivate restores access — it takes a seat back, so it's refused when the workspace is full. You can't deactivate yourself, and nobody can deactivate the owner.
Attributing tickets to people
Under Ticket attribution on the same pane, you can map tracker identities to people so Analytics shows runs and spend per person:
- Enter the person's name, pick the identity kind — GitHub username, Jira account id, Shortcut member id, or Email — and its value, then click Add.
- Optionally Link member to connect the mapping to a Tenbi account. A mapped person doesn't need an account — mapping is for attribution, not access.
When a run finishes, Tenbi looks at the ticket's assignees: if they match exactly one mapped person, the run is theirs; no match or an ambiguous match counts as Unattributed. Attribution is recorded at that moment — adding a mapping later affects future runs only.
Email auto-matching — no setup for the common case. You don't always need to add a mapping first: when a ticket assignee's email matches a member's Tenbi account email, the run is attributed to them automatically — Analytics credits them, and the run's git commits are authored in their name. Auto-matching is credit only: it never decides who pays or clears the require-attribution run gate — both still want an explicit mapping (or the sole-member rule), so an inferred email match can't quietly bill someone's key or let a gated ticket run. Add an explicit mapping when the tracker email differs from the account, or to attribute a teammate who has no seat.
Teams and visibility
On the Workspace → Teams page (owners and admins of Team and Enterprise workspaces), you can group your workspace into teams:
- Create teams and assign members to them from the Members pane (one team per person). Lanes, modules, and credentials each belong to a team — or to Workspace (shared), the default, which everyone can edit.
- New lanes, modules, and credentials created by a team member belong to their team automatically; owners and admins can reassign anything between teams under Resource assignment.
- Team members can edit shared resources and their own team's; other teams' setups are read-only to them.
- Cross-team visibility controls what members see: Open (recommended) lets everyone view every team's setup — useful for avoiding two teams watching the same tickets — while Opaque hides other teams' lanes, modules, and credentials from members. Owners and admins always see everything.
A team can only be deleted once it has no members or resources. Analytics gains a per-team view of runs and spend once teams exist.
Your AI credential
Under Settings → Credentials you can store a personal AI credential. Pick the agent it belongs to — Claude (an Anthropic API key, or a Claude subscription token, which requires acknowledging an Anthropic Terms-of-Service risk that lands on your own account) or, when your workspace allows it, Codex (Beta) (an OpenAI Platform API key). You hold one personal credential at a time: saving under a different agent replaces it. It is stored encrypted and shown only as its last four characters. Removing it also removes any stored acknowledgment.
A Codex personal key is stored but not yet used for runs — it activates when per-run agent selection ships. Which agents are offered is an owner/admin setting (Workspace → Settings → Personal key agents).
Whether it's used depends on your workspace's payment policy (set by an owner or admin on Workspace → Settings): under workspace pays it sits idle; under personal preferred or personal required, runs on your tickets bill your credential — see Whose key pays? for the full rules. Owners and admins can see who has a credential stored (a small key icon on the Members page) — never the credential itself.
Two-factor authentication
Two-factor authentication (2FA) adds an authenticator-app code to your sign-in, on top of your password. It's optional but recommended — your account holds credentials that can reach your repos.
You manage it from your account card at the bottom of the sidebar: click it, choose Account settings, then open the Security pane. The Two-factor authentication section shows a status chip — On or Off.
Turning it on
You'll need any TOTP authenticator app — Google Authenticator, 1Password, Authy, and the like all work.
- Click Enable two-factor.
- Confirm your Password and click Continue.
- Scan the QR code with your authenticator app. Can't scan? Copy the setup key shown next to it (Copy key) and enter it in your app manually.
- Enter the 6-digit code your app now shows and click Verify & turn on.
Privacy note: the QR code is generated locally in your browser from your setup key — it is never sent to a third-party QR service.
Recovery codes — save them now
Immediately after enrolling, Tenbi shows your recovery codes. Each one signs you in once if you lose your authenticator device. They will not be shown again — store them before clicking Done:
- Copy puts them on your clipboard.
- Download saves them as
tenbi-recovery-codes.txt.
Put them somewhere safe that isn't the device running your authenticator app — a password manager is ideal.
Signing in with 2FA on
Sign-in becomes two steps: enter your email and password as usual, then enter the code under Authentication code and click Verify. The prompt accepts either:
- the current 6-digit code from your authenticator app, or
- one of your recovery codes (each works once).
You can type the code with the gap your app displays ("123 456") — spaces are ignored. The challenge is short-lived: it expires after about 5 minutes and allows a handful of attempts, after which you're returned to the password step to start over (Back to sign in takes you there any time).
Regenerating recovery codes
Running low on unused codes, or unsure where they ended up? In Account settings → Security, click Regenerate recovery codes. Confirm with your Password and a current code (or a recovery code) under Authentication or recovery code, then click Regenerate codes. A fresh set is shown once — save it the same way as before.
Regenerating replaces every existing code. Old codes stop working immediately, including unused ones.
Turning it off
In the same section, click Turn off, confirm with your Password and a current code (or a recovery code), and click Turn off two-factor. Your sign-in goes back to password only, and your recovery codes are no longer needed.
Locked out?
- Lost your authenticator device: sign in with one of your recovery codes, then either re-enroll with a new device or turn 2FA off and on again.
- Lost your recovery codes too: contact the operator who invited you. An admin can clear 2FA from your account so you can sign in with your password and enroll again.
Passwords
Forgot your password
On the sign-in page, click Forgot password?, enter your Email, and click Send reset link.
You'll see the same confirmation regardless of what you typed — "If an account exists for that email, a reset link is on its way" — so the form can't be used to probe which emails have accounts. The request is rate-limited; if you see "Too many requests," wait a while and try again.
If your address has an account (and the platform's mailer is configured), an email with the subject Reset your Tenbi password arrives with a Set a new password button. The link works once and expires in 24 hours. It opens a page showing which account it's for:
- Enter a New password (at least 8 characters) and Confirm new password.
- Click Set new password. You're signed in right away, and every previous session is signed out.
Admin-issued reset links
If the email never arrives — no mailer configured, or a delivery problem — the operator can issue you a reset link directly. It opens the same reset page and behaves the same way (works once, shows the account it's for). If a reset page says "This reset link is invalid, expired, or already used," ask for a new one.
Changing your password while signed in
In Account settings → Security, under Change password: enter your Current password, a New password (at least 8 characters), Confirm new password, and click Change password.
Changing your password signs out every other session — only the browser you changed it in stays signed in. That makes it the right first move if you suspect someone else has your password.
Active sessions
Also under Security, the Active sessions list shows everywhere your account is signed in — browser, platform, sign-in time, and IP, with your current one tagged This session. Click Sign out on any single session to end it, or Sign out other sessions to end everything except the browser you're in.
Email notifications
Tenbi can email you about run events. Open Settings in the sidebar, then the Notifications pane (Email notifications). These are your personal preferences, sent to your account email — but they cover runs across your whole workspace, not just runs you started:
- Run failed — a run ended in FAILED; the email includes the reason and a link to the record. On by default.
- Pull request opened — a run finished and its PRs are ready for review. Off by default — this can be chatty on busy Lanes.
Toggles save as you flip them. Emails only actually send when the platform mailer is configured — your preferences are saved either way.
Silent-mode Lanes stay silent everywhere. A Lane with silent mode on suppresses these notification emails too, exactly like it suppresses channel messages — email notifications go through the same gate as the Messaging modules.
These per-user emails are separate from channel notifications: Discord/Slack messages about a Lane's runs are configured per-Lane via Messaging modules, and reach a channel rather than your inbox.