RPD001-Employer Account Setup and Admin Invitation

Rupid · Employer Portal

What this is

Before an employer can upload anything, they need somewhere to log in. Rupid’s team creates the company’s account first with just the company name and one contact person. That person gets an invitation on their work email, with a temporary password, must be changed at the first login, verifies their phone, and lands on a checklist that walks them through the rest. There is no public sign-up — every employer account starts with Rupid.

Why it matters

A secure login exists before a single document changes hands, strangers cannot open accounts, and the employer’s first screen tells them exactly what to do next instead of leaving them staring at an empty portal.

Before it can be used

  • A signed NDA, commercial understanding with the employer exists.
  • Rupid’s team has the contact person’s name, work email address and mobile number.

What this covers

  • Account creation by Rupid’s team with the bare minimum details
  • A one-time invitation that lapses in 72 hours, with resend and cancel
  • First login: password, phone verification, and a second login factor
  • Handing the main admin role to a different person later
  • A record of every step with who did it and when

Who uses it

Rupid’s operations team (creates and invites) · The employer’s first admin (activates) · Later admins (through handover)

What the system must do

  1. Let Rupid’s team create the company account with the registered name and one contact — nothing more is needed at this stage.
  2. Accept only a company-domain email address for the admin. Free personal addresses (gmail, yahoo and the like) are refused, because portal access carries authority over salary data and money files. Where a company genuinely has no domain, Rupid’s team records the reason and approves the exception by hand if needed.
  3. Send the invitation to that work email, with an SMS to the mobile telling them to check it. The link works once and lapses after 72 hours.
  4. At first login: set a password (at least 8 characters mixing upper, lower, number and symbol/special character), verify the mobile by OTP, and set up a second factor.
  5. Open the portal on the onboarding checklist, never on an empty dashboard.
  6. Allow the invitation to be resent — which Revokes the earlier link — or Revoked, keeping a record of each.
  7. Allow the main admin role to be handed over: the current admin or Rupid starts it, the new person completes their own activation, and the old temporary pw credentials stop working at that moment. Create new Admin instead
  8. Record creation, invitation, activation, resend and handover with the person, time and device. Audit Logs.

How it works

  1. The account exists before the employer logs in. The portal’s opening state is the checklist, not a blank page.
  2. An invitation link works exactly once and only alongside the OTP on the registered mobile, so a forwarded email alone does not grant access.
  3. Everything except the checklist stays visibly locked until the steps ahead of it are done.

Screens

Create Company Account (Rupid’s side)

Where Rupid’s team opens a new employer account. Deliberately short — this is a two-minute job, not a data-entry exercise.

What’s on it:

  • A single-column form: registered company name, everyday/brand name, contact person’s name and designation, work email, mobile
  • A live duplicate warning if the company name closely matches an existing account
  • A note field for the account manager

What you can do:

  • Create the account
  • Send the invitation straight away or save it for later

Invitation Manager (Rupid’s side) : A User Role

One list showing every invitation and where it stands, so the team can see at a glance who has activated and who has not

What’s on it:

  • A table: company, contact person, email, sent date, status (Sent / Opened / Activated / Lapsed / Cancelled), hours left before it lapses
  • A filter for status and a search by company

What you can do:

  • Resend an invitation (the old link dies immediately)
  • Revoke an invitation
  • Correct the contact person details and reissue

Activation (employer’s side)

The employer’s first-ever screen. Three short steps on one page with a progress strip, so it never feels like a form marathon.

What’s on it:

  • Step 1: set a password, with the rules shown as tick-marks that turn green as they are met
  • Step 2: the mobile number partly masked, an OTP box, and a resend timer
  • Step 3: choose a second factor — an Google authenticator app (with a QR code)
  • The company’s name shown throughout, so the person knows they are in the right place

What you can do:

  • Set the password
  • Enter the OTP, or ask for a resend
  • Set up the second factor and finish

Onboarding Checklist

The employer’s home screen until the programme goes live. It answers one question at a glance: what do I do next?

What’s on it:

  • A vertical list of stages — company verification (KYB), agreements, working week and holidays, pay cycles, eligibility, employee list, invitations to Employees about the product through email, SMS, WA, go-live
  • Each stage with a status chip: Done, In progress, Waiting on Rupid, or Locked
  • Locked stages showing the plain reason they are locked (‘opens after verification is approved’)
  • One highlighted ’next step’ card at the top with a single button
  • A quiet progress bar across the top

What you can do:

  • Open any unlocked stage (Design: to reach the blocked stage/step use Menu instead of Wizard)
  • See what Rupid is currently doing on stages waiting on them
  • Contact the account manager

Admin Handover (Don’t implement it)

Used rarely but needed badly when the HR head changes. Kept as one simple form to avoid support tickets.

What’s on it:

  • Current admin’s details shown read-only
  • Fields for the successor’s name, work email and mobile
  • A warning that the current admin’s access ends once the successor activates

What you can do:

  • Start the handover
  • Cancel a handover that is still pending

Tricky cases and how they’re handled

Case Handling
The 72 hours pass with nobody activating The link stops working. A fresh invitation goes out — automatically after a day, or by Rupid’s team — and the record shows both.
The contact person quits before activating Rupid’s team replaces the contact and reissues; the earlier link stops working from that moment.
Someone forwards the invitation to a colleague The link still demands the OTP on the original mobile, so a forwarded email alone does not grant access.
The company genuinely has no email domain Rupid’s team records the reason and approves a personal address by exception — visible on the account so an auditor can see it was deliberate.
The admin loses access to their second factor Rupid’s team resets it after verifying identity on a call, and the reset is on record.

Walkthroughs

From nothing to a working login

Detail
Who Rupid’s team, then the employer’s admin
Starting point Commercials agreed
Steps Rupid creates the account with the company name and the HR head’s work email and mobile → invitation lands in her inbox → she opens it, sets a password, enters the OTP, adds a second factor → the checklist appears with ‘Company verification’ as the first open step.
Result A protected login exists and the employer knows exactly what comes next

Handing over to a new HR head

Detail
Who The outgoing admin
Starting point She is leaving the company
Steps Settings → Handover → enter the successor’s name, work email and mobile → the successor activates like a first login → her own access closes automatically.
Result A clean handover, both sides on record, no shared passwords

Who can do what

Role View Create Update Delete Approve
Rupid Ops
Owner Admin
HR Admin
Finance

Fields

Field What it is Type and allowed input Length / range Required Example
Company Name The registered name of the company Letters, numbers, & . , - ( ) 3–128 Yes One97 Communications Ltd
Everyday Name A shorter name used on screens Letters, numbers, spaces 0–64 No Paytm
Contact Name The first admin’s full name Letters, space, dot, apostrophe, hyphen 3–100 Yes K. Lakshmi Prasanna
Designation Their role at the company Letters, space, & , - 0–50 No Head – HR
Work Email Where the invitation goes; becomes the login A company-domain email; personal domains refused up to 254 Yes lakshmi.p@paytm.com
Mobile For the OTP at activation and login 10 digits, starting 6–9 10 Yes 9876543210
Password Set by the admin at activation Upper, lower, number and symbol 8–64 Yes (hidden)
Second Factor The extra check at login Authenticator app or SMS code Yes Authenticator app

Checks the system runs

  • The email domain is checked against the list of public email providers and refused if it matches, unless Rupid records an exception.
  • The same email cannot belong to two employer accounts.
  • A company name close to an existing account raises a duplicate warning before creation.
  • The activation link is tied to its invitation and cannot be reused, edited or shared.

Error messages

When it happens Message shown
Personal email used Please use your company email address. Portal access carries authority over salary data, so we can’t set it up on a personal address.
Lapsed link This activation link has expired. Ask for a fresh invitation and we’ll send one right away.
Used link This link has already been used. If that wasn’t you, contact Rupid support immediately.
Weak password The password needs at least 8 characters with an uppercase letter, a lowercase letter, a number and a symbol.
Three wrong OTPs Too many incorrect codes. Please try again after 15 minutes.

Alerts and messages sent

Channel Message
Email You’ve been invited to set up {company} on Rupid. The link works for 72 hours: {link}
SMS Rupid: your activation link for {company} has been sent to {email}.
Email Your Rupid access for {company} is active. Next on your checklist: company verification.

Points to decide

  • Should a reminder go out automatically at 24 and 48 hours, or is one at 48 enough?