Passwordless Sign-In: Simpler and Safer

Quick PIT lets your team sign in two ways: a one-time link sent to their email, or a single tap with an account they already have — Google, Apple, or Microsoft. Both approaches do away with app-specific passwords entirely. For you as a CoC admin, that means one of the most common and time-consuming support tasks — resetting forgotten passwords — simply goes away.

This page explains how each method works and why it’s both easier for your volunteers and more secure for the sensitive data your count collects.

Request a free demo

Quick PIT lets your team sign in two ways: a one-time link sent to their email, or a single tap with an account they already have — Google, Apple, or Microsoft. Both approaches do away with app-specific passwords entirely. For you as a CoC admin, that means one of the most common and time-consuming support tasks — resetting forgotten passwords — simply goes away.

This page explains how each method works and why it’s both easier for your volunteers and more secure for the sensitive data your count collects.

How each method works

Passwordless email link

A volunteer enters their email address. Quick PIT emails them a secure, single-use link that expires after a short time. Tapping the link on the same device signs them in — no password to create, remember, or type on a phone keyboard in the field. The link proves they control the inbox, which is the same thing a password reset email proves anyway, just without the extra password step in the middle.

Social sign-in (Google, Apple, Microsoft)

A volunteer taps “Continue with Google,” “Continue with Apple,” or “Continue with Microsoft” and authenticates with an account they already use every day. Quick PIT never sees or stores their password — the identity provider verifies who they are and confirms it back to us. Many of your staff and volunteers already have one of these accounts, so there’s nothing new to set up.

Why this matters for CoC admins

You never reset a password again

Because Quick PIT has no passwords of its own, there is no “forgot password” ticket to handle, no temporary password to issue, and no risk of you being on the hook for someone’s credentials. A volunteer who can get into their email or their Google/Apple/Microsoft account can get into Quick PIT. During a count — often early morning, often with seasonal volunteers you’ve never met — that removes a real bottleneck at exactly the moment you can least afford one.

Account recovery becomes someone else’s job (in a good way)

Password recovery, suspicious-login detection, and multi-factor authentication are handled by the email or identity provider — organizations like Google, Apple, and Microsoft that invest heavily in securing accounts. Your CoC inherits that protection for free instead of trying to replicate it.

Faster onboarding for volunteers

New volunteers can be counting in under a minute. There’s no account creation form, no password rules to satisfy, and no credential to forget between training day and count day. Fewer steps means fewer people stuck at the sign-in screen needing your help.

The security benefits

  • No password reuse risk. People reuse the same password across many sites. A breach somewhere else can’t expose a Quick PIT password, because Quick PIT doesn’t have one.
  • Phishing has a much smaller target. There’s no Quick PIT password for an attacker to trick a volunteer into revealing.
  • Stronger protection without extra effort. If a volunteer’s Google, Apple, or Microsoft account has two-factor authentication turned on, that protection automatically extends to their Quick PIT access.
  • Cleaner offboarding. When someone leaves, you remove their access in the Quick PIT dashboard. You’re never left wondering whether an old password is still floating around in a notebook or a shared spreadsheet.
  • Right-sized access to sensitive data. PIT survey responses contain real names, dates of birth, and partial SSNs. Keeping passwords out of the picture removes one of the easiest ways that kind of access leaks.

App Lock: Protection for an unattended device

Sign-in confirms who someone is when they open Quick PIT. App Lock protects what happens next — specifically, the risk of a volunteer setting their phone down mid-count and walking away while still signed in. It’s an optional safeguard you control as a CoC admin.

When you turn it on (Dashboard → Settings → App Lock), members have to re-authenticate to reopen the field app. It applies to everyone in your CoC starting at their next launch, and you set how forgiving it is:

  • Require unlock on reopen turns the feature on for the CoC.
  • Re-lock after (minutes in background) decides how long the app can sit minimized before it locks again. The default is 5 minutes; set it to 0 to lock every single time the app leaves the screen. The app also always locks on a full relaunch.

How a member unlocks depends on their device:

  • On phones and tablets (Android/iOS): Face ID, Touch ID, fingerprint, or the device passcode — the same strong protection that guards the rest of their phone.
  • On the web (or a device with no passcode set): the member creates a short app PIN the first time they sign in. Quick PIT stores only a scrambled (hashed) version of the PIN, never the PIN itself, and after five wrong tries the member is signed out and has to sign in again.

A couple of things worth knowing: protected count data never flashes on screen before the app is unlocked, and the web PIN is best thought of as a deterrent for a shared browser rather than the hardware-grade lock you get on a phone. For the most common field scenario — a volunteer’s phone left face-up on a table — App Lock means a passerby can’t browse names, dates of birth, or partial SSNs without the volunteer’s face, fingerprint, or passcode.

At a glance

Traditional password
Passwordless & social sign-in
Resetting passwords
Frequent admin task, especially on count day
Never — there are no passwords
Volunteer setup
Create account, choose & confirm a password
One tap or one email link
Forgotten credential
Common, and blocks the volunteer
Nothing to forget
Breach exposure
A stored password list can be stolen
No password stored to steal
Two-factor protection
Optional, rarely configured
Inherited from the provider

Common questions

What if a volunteer doesn’t have a Google, Apple, or Microsoft account?
They can use the email link option with any email address. The two methods work side by side, so no one is locked out.

Is the email link safe if someone sees the email?
The link is single-use and expires quickly, so an old or already-used link can’t be reused to get in. It works the same way the password reset emails you already trust do.

Can we still control who has access?
Yes. Access and roles are managed by CoC admins in the Quick PIT dashboard. Sign-in just verifies who someone is; your dashboard settings decide what they can do and for which CoC.

The bottom line

Passwordless email links and social sign-in make signing in faster and less frustrating for volunteers while removing whole categories of security risk and support work for you. No passwords to reset, no credentials to leak, and stronger account protection — all backed by providers your team already relies on.

Request a free demo

More Articles

Get In Touch

Are you interested in using the Quick PIT app for your community or have a question or concern? Send us a message and we will get back to you within 2 business days.