Most issues in ISO Mate come down to a permission, an active filter, or a connection that needs refreshing. Use the sections below to fix the most common problems with signing in, permissions, subscription access, account limits, file uploads, email and calendar sync, rate limits, and missing data. Where a topic has a dedicated guide, follow the link for the full walkthrough.
Signing in
I forgot my password
On the login page, select Forgot password? and enter your email address. We send a reset link to your inbox that expires after a short time, so use it promptly. The password rules that apply when you set a new one are explained in Password Security and Breach Detection.
My account is temporarily locked
After several failed sign-in attempts, ISO Mate locks the account for a short period to protect it. The message tells you how long to wait. Once the lockout clears, sign in with the correct password, or reset it if you are unsure. If you still cannot get in after the wait, your account may be disabled, in which case contact support.
I cannot log in because my email is not verified
New accounts must confirm their email address before the first sign-in. Open the verification link we emailed when you registered.
If that email never arrived, or the link has expired, enter your email and password on the login page as usual. Rather than signing you in, ISO Mate takes you to the verification page with your address already filled in, where Resend sends a fresh link. You can request a link once a minute, and up to three times an hour. Reaching that limit is expected rather than a fault, so wait a while and try again.
Resetting your password does not lift this block, so use Resend rather than Forgot password?.
If your ISO Mate address is also a Google address, signing in with Google confirms it straight away, because Google has already verified the address on its side. One consequence is worth knowing before you choose that route: it clears any password on the account and signs out existing sessions and API tokens, because that password was set before anyone had proven the address belonged to them. You keep access through Google, and you can set a new password afterwards from your security settings.
Google Sign-In is not working
Google sign-in requires your Google account to be linked to your ISO Mate profile. Open Security Settings from the profile menu, find the Google Account card, and use Link Google Account to complete the authorization.
If you are told this is not the Google account linked to your profile, you are signing in from a different Google account than the one on record. Only the linked account can reach your profile, even when the other one uses the same email address. Choose the linked account in Google’s account chooser, or sign in with your email and password instead.
If Google worked until you changed your email address, that is expected rather than a fault. Completing an address change removes a Google link that belonged to the address you left behind, and signs you out of your other sessions. Sign in with your password, then link Google again from Security Settings. See Changing Your Email Address.
To move the link to a different Google account, unlink the current one first and then link the new one. The full linking rules are in Setting Up Two-Factor Authentication.
I am not receiving my two-factor code
Two-factor codes are sent by SMS to the mobile number on your profile. Confirm the number is correct, wait a moment for the message, and use the resend option if it does not arrive. If you cannot receive SMS, sign in with one of the recovery codes you saved when you enabled two-factor authentication.
Permission errors
I see “Access Denied” or cannot open a page
Your role may not include the permission that page needs. Ask an administrator to review your role under Roles & Permissions in the Settings menu (the gear icon). Access is granted per organization, so also confirm you are working in the right one.
I cannot create or edit items
Creating and editing require the matching permission for that resource. For example, creating issues needs the create permission for issues, and editing them needs the update permission. An administrator can add these to your role.
A role change was refused
Some role changes are refused on purpose, and the message explains which rule applied. These are the ones people meet most often:
- The role grants more than you have: you can only hand out access you hold yourself. Somebody who already has those permissions, usually the account owner or an administrator, needs to make the change.
- This is the only administrator: an organization must always keep one. Give the Admin role to somebody else first, then remove it from the original holder.
- You are the only administrator: you cannot give up your own Admin role while you are the last one. Once another administrator exists you can, and they can grant it back to you if you change your mind.
See Managing Users and Roles for the full rules.
I cannot remove or delete a user
A user who owns an organization cannot be removed from it or deleted, because an organization must always have an owner. The current owner needs to transfer ownership to somebody else first, which only they can do. You also cannot remove yourself from an organization.
Subscription and access
My organization has lost access to its data
If a free trial has run out, or a subscription has been cancelled and its paid period has finished, ISO Mate stops serving that organization’s records until billing is sorted out. Nothing is deleted. Your issues, tests, documents, and history are all still there, and they come back the moment the subscription is active again.
The parts of ISO Mate you need in order to fix it stay open. You can still sign in, open the billing pages and subscribe, switch to another organization you belong to, accept an invitation, edit your own profile, export your data, and delete the account if that is what you want.
A payment that has failed but is still being retried does not lock anybody out. Your organization keeps working normally while the retries run, so update the card on file before the retries are exhausted. See Managing Your Subscription.
Account limits
I cannot add another user
An organization has a ceiling on how many people it can hold, counting current members plus any invitations that have been sent and not yet answered. While the organization is subscribed the ceiling is high enough that no real team reaches it. Before then, on a trial or an organization that has never subscribed, it is ten.
Reaching it only blocks new additions. Everybody already in the organization carries on as normal and no data is touched. To make room, withdraw an invitation nobody has answered, remove a member who no longer needs access, or subscribe to lift the ceiling. The Add User dialog shows the current usage so you can see how much room is left. See Managing Users and Roles.
I cannot create another organization
One person can own up to ten organizations. Organizations you belong to but do not own do not count towards that, so joining somebody else’s team never uses up a slot of yours. If you have reached the limit, delete an organization you no longer need, or transfer its ownership to somebody else.
Creating several in quick succession is also paced, so if you are setting up a few at once you may be asked to wait briefly between them.
I cannot add another calendar
There is a ceiling on how many personal calendars one person can hold in an organization. If you have reached it, delete a personal calendar you no longer need and you can add a new one straight away. Calendars you connect from Google do not count towards it. See Calendar Sources and Settings.
File uploads
My file was rejected when I tried to attach it
Two limits apply. The first is size, which depends on where you are attaching:
- 50MB: issue attachments and compliance evidence.
- 25MB: email attachments.
- 10MB: help desk ticket replies and internal notes, chat messages, test execution attachments, files on a custom object entry, and images placed in a rich text editor.
- 2MB: an organization logo.
The second is file type. Web pages and scripts, such as HTML, JavaScript, and CSS files, are refused wherever ISO Mate keeps a file against a record, because a browser could execute them. That covers issue attachments, help desk ticket replies and internal notes, chat messages, compliance evidence, test execution attachments, and images in a rich text editor.
Email attachments are the deliberate exception. Outbound mail legitimately carries any kind of file, so the composer accepts them rather than narrowing what you can send from ISO Mate compared with any other mail client. Anything attached there is only ever handed back to you as a download, never opened in the browser.
ISO Mate inspects the contents of the file rather than trusting its name, so renaming one to .txt does not get it past the check. Where a type is refused, put the file inside a ZIP archive first, which is accepted.
Everyday formats are unaffected. Images, PDFs, Word, Excel, and PowerPoint documents, plain text, CSV, Markdown, JSON, XML, and archives all attach as normal. The full list for issue attachments is in Creating and Managing Issues.
An attachment downloads instead of opening
Only images and PDFs open in the browser. Every other file type downloads so you can open it in the application that handles it, which is expected behaviour rather than a fault.
Email sync issues
My emails are not syncing
- Credentials: confirm the mailbox username and password are correct.
- Google connection: for Gmail, the Google connection can expire. Reconnect the mailbox if it has.
- IMAP access: make sure your provider allows IMAP, since some require you to enable it first.
- Ports: check the IMAP port (often 993) and the SMTP port (often 587 or 465).
Sent emails are not appearing
Check your SMTP settings. Some mail servers require a specific authentication method or encryption setting before they will send. See The Email Activity Panel for how mailbox messages connect to the rest of your workspace.
API and MCP token issues
My token stopped being able to do something it could before
A token can never do more than the person who created it is currently allowed to do. If one of their roles was changed or removed, every token they created loses that access straight away, even though the token itself is still valid. Restore the role, or create a new token under somebody who holds the permissions the tool needs. See Connecting via the MCP Server.
My integration can read but no longer write
An active subscription is required to change anything through the API or an MCP client. If the trial has ended or the subscription has lapsed, tools can still list what is available and read records, but anything that would create, update, or delete is refused with a payment required error. Restoring the subscription restores writing straight away, with no change needed on the integration.
I cannot create another API token
There is a ceiling on how many API tokens one organization can hold at once, generous while the organization is subscribed and tighter before then. Revoking a token you no longer use frees a slot immediately. It is worth doing anyway, since an unused token is a credential nobody is watching.
Rate limits
I see a “Too many requests” message
ISO Mate limits how many requests can be made in a minute, so that no single user or tool can crowd everybody else out. The message tells you how long to wait, and anything you had already saved is unaffected.
Reading has a generous allowance that ordinary work never approaches. Changing things has a tighter one, because creating, editing, and deleting are the requests that accumulate data. The two are counted separately, so reaching the limit on changes never stops you reading your lists and records while you wait.
These are the usual explanations:
- A bulk action over a lot of records: most bulk actions are a single request, but some are applied to each record in turn, so a large selection becomes a lot of requests. A full page is comfortably within the allowance, while several full pages one straight after another can reach it. The message tells you how many records were processed and how many were left, so wait a moment and run it again for the remainder.
- A script or integration of your own: check whether it is retrying in a tight loop, and have it wait for the period given in the response before trying again.
- Creating many records in quick succession: a few areas apply a tighter limit of their own, including creating calendars and calendar events. Wait a moment and carry on.
- An AI assistant or tool connected through MCP: each API token has its own allowance, and all of an organization’s tokens together share a second, wider one. So a single busy tool can reach its own limit while your console session is unaffected, and several tools running at once can reach the shared ceiling even when none of them has exhausted its individual allowance. MCP is metered by those token allowances rather than by the limits described above. See Connecting via the MCP Server.
Your own use of the console and the mobile app is counted per signed-in user rather than per office or network, so a colleague working normally is never slowed down by somebody else’s activity. Two allowances are shared across an organization: the combined one for API tokens described above, and a wider ceiling on changes that all of its members draw on together. Both are deliberate, so that one runaway integration or one script cannot consume the capacity the rest of the team depends on. If a legitimate workload needs more headroom than the limits allow, contact support.
Google Calendar sync issues
My calendar events are not syncing
- Connection: confirm your Google account is connected in the calendar settings.
- Calendar toggle: check that the specific calendar is switched on in the calendar sidebar.
- Permissions: make sure you granted the requested access during the Google authorization.
- Reconnect: disconnect and reconnect the calendar to refresh the sync.
Performance
Pages are loading slowly
- Connection: check your internet connection.
- Cache: clear your browser cache and reload the page.
- Browser: try a different browser to rule out a browser specific issue.
- Still slow: contact support with the name of the page that is slow.
Missing data
I created an item but it does not appear in the list
- Filters: an active filter may hide it, and your filters are remembered between visits. Select Clear Filters to reset and show everything. On notes, tasks, and contacts, check the Created by filter in particular, since it narrows the list to one person’s records.
- Organization: confirm you are viewing the correct organization from the account name in the top toolbar.
- Permission: some views only show records you have permission to see.
- Refresh: reload the page to load the latest data.
Formatting or an embed disappeared from a note or description
Rich text fields, such as note content, issue and ticket descriptions, risk descriptions, and policy content, are kept to a safe set of formatting. Anything that could run code in the browser of the next person to open the record is removed when the record is saved. That covers embedded frames and videos from other sites, scripts, style blocks, and embedded objects.
This applies however the content arrives, whether you typed it, pasted it from another document, or a workflow automation wrote it. If an automation of yours populates a rich text field, keep it to ordinary formatting rather than embed markup.
Everyday formatting is unaffected. Headings, bold and italic, lists, tables, quotes, code blocks, links, and images all behave as normal. Links that open in a new tab are given standard protective attributes automatically, which changes nothing about how they work for you.
An SVG image is also cleaned when it is stored, which removes any script and any link inside it. Ordinary artwork is unaffected, so your logos and diagrams look exactly as they did.
Want to explore ISO Mate without the friction? Start your free 14-day trial.