SimpleScrumTools

Start here

Getting started

Create an account, confirm your email address, sign in, and find your way around the first screen.

Create an account with email and password

You need no account to open the create-account page. The product creates your organization together with your account, so your first screen is never empty.

  1. On the home page, click Create a free account.
  2. Type your name in Your name.
  3. Type your address in Email.
  4. Type a password of at least 8 characters, with a number and a special character, in Password.
  5. Click Create account.
  6. Read the card Check your email.
  7. Open the email Verify your SimpleScrumTools email address.

The card says If that address can be used, a confirmation link is on its way to {your address}. It also says The link is good for 24 hours. The card has the link Back to sign in.

  • Your name is 1 to 80 characters. A blank name blocks the form with Too small: expected string to have >=1 characters. A longer name blocks with Too big: expected string to have <=80 characters.
  • Email must be a valid address of at most 254 characters. A malformed address blocks the form with Enter a valid email address. A longer address blocks with Too big: expected string to have <=254 characters.
  • The product stores the address in lower case. Capitalization never matters when you sign in.
  • The card is the same whether or not the address already has an account. When it does, the product sends You already have a SimpleScrumTools account to that address and creates no second account.
  • The product accepts five submissions of this form per hour, whether or not each one creates an account. The sixth blocks with Too many requests. See how the product counts the limits.
  • Under the form, Already have an account? Sign in opens the sign-in page.

The password rules

The hint under the field says At least 8 characters, with a number and a special character. The browser checks four rules before it sends anything, and shows only the first rule that fails.

  • At least 8 characters. A shorter password blocks with Password must be at least 8 characters.
  • At least one digit. A password with no digit blocks with Password must contain at least one number.
  • At least one character that is not a letter A to Z or a digit 0 to 9. A space counts. A password with no such character blocks with Password must contain at least one special character.
  • At most 72 bytes. A longer password blocks with Password must be at most 72 bytes.

The same rules apply on the create-account page and on the reset page. The product does not check the rules when you sign in, so an older password still works.

How the product counts the limits

The product refuses a burst of requests with Too many requests. Before you sign in, the product counts a burst against your network address. Everybody at one address shares one count, for example an office, a company network or a mobile network. The product gives no signed-out person a count of their own. Each count clears itself.

On some sites the product can read no address at all. Every signed-out person then shares one count, and each number below is the total for the whole site.

  • Five create-account submissions per hour.
  • Ten sign-in attempts per 15 minutes. A click on a provider button and the return from the provider each spend one, so ten of them buy five provider sign-ins.
  • Twenty link redemptions per hour. Confirmation links, reset links and invitation links share the twenty.
  • Five outbound emails per hour. Reset links and new confirmation links share the five.

After you sign in, the product counts against your account instead, and two other counts apply. The product accepts 300 reads each minute and 60 changes each minute. Every screen you open counts against the reads, and every change anywhere in the product counts against the changes. Over either count, the screen shows Too many requests.

Create an account or sign in with a sign-in provider

A button such as Continue with Google or Continue with Microsoft appears only when the administrator of the site configured that provider. A provider that is not configured is absent, not disabled. The same buttons are on the home page, above the form on the create-account page, and below the form on the sign-in page.

  1. Click the provider button.
  2. Choose an account at the provider.
  3. In the address bar, add /app to the end of the site address.

The provider always asks which account. After step 2 the product returns you to the home page, signed in. The home page does not show that you are signed in, and its header still offers Sign in. That form starts a second session and does not say that you are already signed in. The create-account page does the same while you are signed in. The home page offers no other way into the product, so step 3 is the only one.

  • The product asks the provider only for your name, your address and your sign-in. It never reads your files or your mail.
  • When no account has the address, the product creates an account and its organization, as with email. The product sends no confirmation email on this path, so the address stays unconfirmed unless the provider confirms it. To confirm the address later, use a reset link. See Forgot your password.
  • When an account already has the address and the provider confirms the address, the product links the provider to that account and signs you in.
  • When an account already has the address and the provider does not confirm the address, the product blocks the sign-in.
  • Google confirms the address when the Google account says it is confirmed. A Microsoft work or school account confirms the address only when Microsoft proves that the directory of the account owns the address. Many directories send no such proof, and the address then stays unconfirmed. A personal Microsoft account, such as outlook.com, hotmail.com or live.com, does not confirm the address today.
  • When the administrator of the site restricted Microsoft sign-in to one directory, the product refuses an account outside it.
  • A provider confirms the address only on the sign-in that links it to the account. A later sign-in through the same provider never confirms an address that is still unconfirmed.
  • An account created through a provider has no password. The email and password form blocks it with Invalid email or password. To add a password, see Forgot your password.
  • Finish at the provider within 10 minutes. After that the sign-in fails.
  • A cancel at the provider, and every refusal above, end on the sign-in page with no message.
  • A click on a provider button spends the sign-in count, and the return from the provider spends it again. Over the count, the button opens a plain text page that contains Too many requests. See how the product counts the limits.
  • The provider buttons carry no return path. If an invitation sent you to the sign-in page, a provider sign-in lands on the home page. Open the invitation link again.
  • A provider button can open a plain text page that contains That sign-in provider is not available. Then the administrator of the site configured that provider only in part.
  • A development instance can also offer Continue with the development provider. It signs in one fixed account, Dev Stub User, not your own. A production instance can still show the button, and there the button opens the plain text page above.

Confirm your email address

  1. Open the link in the email Verify your SimpleScrumTools email address.
  2. Wait while the page shows Confirming your address….
  3. On Email confirmed, click Sign in.

The card Email confirmed says Your account is ready. Sign in to get started. above the link. The link does not sign you in. It opens the sign-in page.

  • The link is good for 24 hours and works once. A newer link replaces an older one.
  • A used, replaced or old link shows That link did not work with This link is invalid, expired, or has already been used. Under it the card says Links expire after 24 hours and can be used once. Sign in to request another.
  • A link without its token shows That link is incomplete with The confirmation link is missing its token. and Sign in to request another.
  • When the account behind the link is gone, the same heading shows That account no longer exists.
  • Confirmation links, reset links and invitation links share one count of twenty per hour. Over it, a good link shows That link did not work with Too many requests.
  • Three other actions also confirm the address: a reset link, an accepted invitation, and the first sign-in through a provider that confirms the address.

What you cannot do until you confirm

The product blocks one action. A member with Manage the organization and an unconfirmed address cannot start a checkout on the Billing screen. The screen shows Verify your email address before adding a payment method. Receipts and billing notices go there. Everything else works before you confirm. See Plans and billing.

Get a new confirmation link

NeedsManage the organization org_manage

The only control is on the Billing screen, the last link in the left rail. It appears only after the product refuses a checkout for an unconfirmed address. That needs a Free organization on a site where the administrator configured payments.

A Pro or Enterprise organization has no upgrade button, so it never shows that refusal. Without payments the screen says Upgrading is not available yet. In both states nobody can get a new link this way. See Plans and billing.

  1. Open the Billing screen of the organization.
  2. Click Upgrade to Pro or Upgrade to Enterprise.
  3. Click Resend verification email.
  4. Open the new email.
  5. Follow its link.
  6. Sign out.
  7. Sign in again.

After step 2 the screen shows the message above and the button Resend verification email. After step 3 the screen replaces the button with Verification email sent to {your address}. Come back once it is confirmed. The new link replaces any older one and is good for 24 hours.

Sign in

  1. On the home page, click Sign in.
  2. Type your address in Email.
  3. Type your password in Password.
  4. Click Sign in.
  • Capitalization in the address does not matter.
  • You can sign in before you confirm the address.
  • A wrong password, an unknown address, or an account created through a provider and still without a password blocks with Invalid email or password. The message is the same for all three.
  • An empty field or a malformed address blocks with Invalid request body.
  • Over ten attempts per 15 minutes, or twenty on one address, the form blocks with Too many requests. See how the product counts the limits.
  • Under the form, New here? Create an account opens the create-account page.

After you sign in, the product opens your first organization. When the invitation page sent you to sign in, this form returns you to the invitation instead. A provider button does not. See Invitations.

Forgot your password

  1. On the sign-in page, click Forgot your password?.
  2. Type your address in Email.
  3. Click Send reset link.
  4. Open the email Reset your SimpleScrumTools password.
  5. Within one hour, follow its link.
  6. Type a password of at least 8 characters, with a number and a special character, in New password.
  7. Click Set new password.
  8. On Password changed, click Sign in.
  9. Sign in with the new password.

After step 3 the card Check your email says If {your address} has an account, a reset link is on its way. It is good for one hour and can be used once. The card is the same whether or not the address has an account. It has the link Back to sign in.

After step 7 the page says Every other session has been signed out. Use your new password to sign in.

  • An empty field or a malformed address blocks with Invalid request body. The browser does not check this form before it sends.
  • The link is good for one hour and works once. A newer link replaces an older one at once.
  • A used, replaced or old link blocks with This link is invalid, expired, or has already been used.
  • A link without its token shows That link is incomplete and the link Request a reset link.
  • Over twenty link redemptions in one hour, a good link blocks with Too many requests.
  • The reset ends every session of the account. Every browser and device signs out at once, and the next page each one opens is the sign-in page.
  • A reset link works for an account created through a provider. It gives the account a password, so the email and password form then accepts it too.

Where you land after you sign in

The product opens the first organization in your list, ordered by name. It is not the organization you used last. When you belong to two or more, a select beside the organization name moves you to another one. A screen reader reads its label, Organization, and the screen does not show it. With one organization, only its name shows.

Every organization screen has the same top bar: the SimpleScrumTools wordmark, the organization name, your name, Help, the theme button and Sign out. The wordmark opens your first organization. Hold the pointer on your name to see your address. The Members screen shows it too. Help opens the help site in a new tab, so your work stays where it was.

Below the top bar, the left rail lists the screens your roles cover. Overview, Members, Roles and Teams need View. Overrides, Activity, Settings and Billing need Manage the organization. A link you lack the bundle for is absent, not disabled. See Organizations and Roles and permissions.

Overview is the first screen. Its heading is Projects: every portfolio in the organization, in order, with its project cards. With Manage the organization you also see New portfolio and New project. See Portfolios and Projects.

With Manage the organization on a Free organization, a line above the first portfolio names the plan and the projects you use, for example Free plan and 0 of 1 project. The line ends with the link Billing. At the cap it adds no more projects on this plan, and where paid plans are on sale the link reads Upgrade. Pro and Enterprise show no such line. See Plans and billing.

On a Free organization where the administrator of the site configured ads, an ad panel closes the screen. Before you answer, and after you decline, the panel holds a sentence about the Free plan in place of an ad. A bar at the foot of the window asks about cookies. It has no close button, and it stays on every screen with a panel until you click Accept or Decline. See Ads and cookie choices.

When you are in no organization

Every account starts in one organization, so this state means you were removed from your last one, or it was deleted. The product shows a card headed You are not in any organization. It lists what you can do: ask an administrator of an organization to invite you, ask through the Contact page for a deleted organization to be restored within 30 days, or delete your account on the Your account page.

Below the list, the card says Signed in as {your address}. It has no top bar and no theme button, but it has its own Sign out and the link Back to the home page. See Invitations.

Light, dark and system

The theme button is in the top bar of every organization screen. The home page, the sign-in and create-account pages, and the password, confirmation and invitation pages have it too. So does every other public page: help, the Scrum primer, the demo, pricing, about, contact, privacy and the EULA. Its label is System, Light or Dark. Click the button to move it one step: System to Light to Dark, then back to System.

  • System follows the light or dark setting of the operating system, and follows a change to it at once.
  • Light or Dark replaces the operating system setting, whether that setting is light or dark.
  • The product stores the choice in this browser only. It is not an account setting, and it does not follow you to another browser or device. Other open tabs of the product follow the change at once.
  • In a private window, the browser forgets the choice when you close the window. If the browser blocks storage, the button changes nothing.

Sign out

Needsmembership of the organization, nothing more

Sign out is in the top bar of every organization screen. The product does not ask you to confirm, and opens the sign-in page.

  • Sign out ends the session in this browser only. Another tab of this browser stops working at once. Its next page is the sign-in page, and a control on it answers Authentication required. Other browsers and devices stay signed in.
  • To end every session at once, use a reset link. Every other browser and device signs out at once. See Forgot your password.
  • The page You are not in any organization and the page Your account have no top bar. Each has its own Sign out button.

The shape of the product

An organization holds its members, roles, Scrum Teams, portfolios and projects. It has a plan: Free, Pro or Enterprise.

A portfolio groups projects. Every project sits in exactly one portfolio, and every organization starts with a portfolio named Unsorted.

A project is one Product Backlog with a key, a Product Goal and a Product Owner. It also holds phases, item types, epics, a Definition of Done and its sprints.

A Scrum Team is a group of members with a timezone. You assign a team to projects. A sprint needs exactly one Scrum Team before it can start, and can exist without one until then.

A role is a named set of capability bundles. Your organization roles apply everywhere, and a team role applies only to the work of that team.