Sign-in has three parts, and each has its own route back in.
The email address
The account is the email address it was invited to. Where someone has more than one, the invitation went to one of them specifically.
An address that has changed does not carry the account with it. Updating it is done from account while signed in.
The password
Resetting it sends a link to the address on the account. The link lasts 72 hours, which is deliberately long: owners check email in the evening or over a weekend, and a link that dies overnight sends people back to the start for no security gain.
An expired link is not a dead end. Opening one within 30 days of its expiry offers to send a replacement to the same address, shown partly masked so you can confirm which mailbox to look in. Holding the old link already proves you received the first email, so nothing new is disclosed. After 30 days, start a fresh reset.
The message arrives from the platform's sending address, and is worth looking for in spam where it does not appear.
Passwords expire after 90 days. That is not a failure: signing in with an expired password takes you straight to choosing a new one rather than refusing you.
Too many attempts, and locked out
These are two different things with two different remedies, and the messages are easy to confuse.
"Too many login attempts. Please try again later." is a temporary slowdown after repeated failures. It is counted both per network address and per account, so somebody guessing at your address cannot be masked by coming from many machines. Nothing is wrong with the account. Waiting is the whole of the fix.
"Your account has been locked." happens after five failed attempts and does not lift on its own. Support has to unlock it — see getting help. The counter resets to zero on any successful sign-in, so four bad attempts followed by a good one leaves nothing behind.
If you are not sure which you are seeing, the difference is whether the message mentions waiting or mentions support.
The second factor
Where two-factor sign-in is enabled, a code from the authenticator application is required after the password.
Codes are time-based, so the clock on the phone matters. A device whose time has drifted produces codes that are rejected, and setting the clock to update automatically resolves it.
Recovery codes issued at setup are the route in when the device is unavailable, which is the reason for storing them somewhere other than the phone.
A new device
Signing in from an unfamiliar device may require confirmation by email. This is expected rather than a restriction on the account.
Signed out while still working
Sessions end after a period of inactivity, with a warning shortly before. Signing back in returns you to where you were.
Inactivity means no interaction with the page — reading a long report without clicking counts as idle. This is deliberate: the platform holds financial detail, and an unattended session on a shared or site machine is the most ordinary way that gets seen by somebody it should not.
Signed in, but something is not available
That is a role rather than a sign-in question — see roles and permissions and I cannot see something I expect to.
If none of these apply
Support can confirm which address holds the account and reissue an invitation — see getting help.
