Part 3 · Using the app
Sign in and your team
Sign in with Google, name your company, and invite the people who work on the claim.
Sign in with Google
Sredify uses your Google account. The first time you sign in, you name your company and become its Admin.
We keep your Google name, email and photo so your team can see who is who. We never see your Google password.
You can belong to more than one company, for example if you are an accountant working on several claims. Switch between them with the company name at the top left of the board. Each company has its own board and Account. Create a company is at the bottom of the same menu.
Changes save on their own. The top bar shows Saving... and then Saved. If someone else changed the same thing a moment before you, your change is not saved and a note tells you who changed it, so nobody overwrites anyone by accident.
Saved to your company
Projects, Account details, assessments, reports and claims are saved to your company, so everyone in it sees the same work on any computer. Only the tutorial's sample project stays in your own browser.
Roles
Everyone in a company has one role:
- Admin. Everything, plus inviting people, changing roles, connecting GitHub and Jira, approving outside apps and creating API keys.
- Editor. Can edit projects, run assessments, and edit claims and evidence. Cannot manage people or connections.
- View only. Can see everything and change nothing. Good for an accountant or an auditor.
View only members see a View only pill in the top bar. Buttons and fields that would change something are greyed out and say View only when you hover them. Opening projects, assessments and claim packages, and downloading PDFs, still work.
A company always keeps at least one Admin. To step down, make someone else Admin first.
Members is not the same list as People. People are the staff on your claim (salaries, SR&ED time). Members are the people who can open the app.
Invite someone
Admins open Account, then Members, enter an email, pick a role and press Create link. Copy the link and send it yourself by email, Slack or text.
- The link works once, only for that email's Google account, for 7 days.
- The link is shown only when you create it. Lost it? Press New link under Waiting to join. The old link stops working.
- Cancel stops a link before it is used.
If someone opens the link while signed in to a different Google account, the page tells them which email it was sent to and lets them switch account.
Connected apps
Outside apps (a timesheet tool, a browser extension) can ask to connect. They send you to a Sredify screen that says what the app wants, for example see projects and record time. Only a company's Admins can approve.
- Unverified app means Sredify hasn't checked who is behind it yet. Only approve apps you know and trust.
- Pay is marked sensitive. An app only sees pay or salary amounts if you approve Pay, and only while the approving Admin is still an Admin.
- An app acts with the approving Admin's current role. If that Admin becomes View only, the app can still read but can't add anything. If they leave, the app stops.
- Everything an app adds is labelled with its name, for example "Acme Timer · approved by Ann", and follows the same rules as time added in the app.
- Account, Apps and API, Connected apps lists every app, who approved it and when it was last used. Revoke stops it at once. Tick Also remove everything it added to stop counting its time, notes and links (they stay in history).
Developers: the full API docs, with a browser extension sample, are at /developers/docs. Register an app at /developers.
API keys
Account, Apps and API lets an Admin create API keys so your own tools and scripts can read the company's data, or add recorded time, notes and links (for example from a timesheet app).
- Pick only the permissions a key needs. Pay is marked sensitive: without it, a key never sees pay or salary amounts.
- The key is shown once. Store it like a password. Lost it? Revoke it and create a new one.
- A key acts with its creator's current role. If that person becomes View only, the key can still read but can't add anything. If they leave the company, the key stops working.
- A key can only change or remove items it added itself. Removed items stay in history, with the reason.
- Time added by a key follows the same rules as time added in the app, and shows as "Timesheet sync (API key) · approved by" its creator.
- Revoke stops a key on its very next request. Editors and View only members can see the list but can't create or revoke keys.
This guide helps you prepare. It is not tax advice. Have your SR&ED preparer review your claim before you file.