What your IT team needs to know about Knowhand.
Knowhand runs in the browser and needs no installation and no access to mailboxes, calendars or your directory. People sign in with a link sent to their work email or with the company Google account. This page lists what you may need to allow.
- No passwords, no installation
- Data in Frankfurt (EU)
- No access to mailboxes or calendars
"What do we need to approve for Knowhand?"
Last updated 25 September 2026
Two ways to sign in, no password.
Knowhand has no passwords. People sign in with a link sent to their work email or with an existing company Google account.
Link by email
Knowhand sends a sign-in link to the work email address. The same email contains a code that can be entered on the sign-in page instead. This works with any work address, including Microsoft 365 mailboxes.
Sign-in link and code- valid for 60 minutes
- works once
- 8-digit code
Sign in with Google
With your company's Google account, for example from Google Workspace. The person signs in at Google, and multi-factor authentication and access rules of your account stay in effect.
Requested permissionsopenidemailprofile
- Sign-in with Microsoft is not available yet. For Microsoft 365, use the link by email.
- From Google, Knowhand receives the name, email address, the Google account ID and, if available, the address of the profile picture.
- A board is created with a work email address. Knowhand rejects personal email domains such as gmail.com, gmx.at or outlook.com at that step ("Please use a work address").
- People with the same company domain join the board automatically unless the admin turns this off. Everyone else joins with an invite link.
Who creates the board and how IT becomes admin.
Knowhand has two roles: admin and member.
- There is one board per company domain. Whoever signs in first with an address from your domain creates it and is admin.
- An admin appoints further admins under Admin › Members with "Make admin". That is also how IT becomes admin: the person who created the board appoints you.
- An admin turns off automatic joining via the company domain under Admin › Members. Then only people with an invite link get in.
- Admins manage members, categories, templates, brand, subscription and export. They can delete requests in case of misuse but cannot mark any as solved. Admins don't see values per person either.
- The last admin can't be removed or demoted.
Allow email from board@knowhand.com.
Sign-in links and notifications come from the same address. Allow it in your spam filter, ideally with a passed DKIM check for knowhand.com.
| Sender address | board@knowhand.com |
|---|---|
| Sender name | "Knowhand" for sign-in links, "Board name via Knowhand" for notifications |
| Technical sender domain | send.knowhand.com (Return-Path) |
| Sending | Resend, from the EU (Ireland) |
| Signature | DKIM for knowhand.com, SPF via send.knowhand.com; both align with the sender domain, so the emails pass DMARC |
| Sign-in links and codes | Valid for 60 minutes, work once |
| Measurement | No open or click tracking |
The addresses Knowhand uses.
For firewall, proxy and filter rules.
| Address | Used for |
|---|---|
knowhand.comwww.knowhand.com | Website, app and sign-in links from emails |
lbtyszczqsjdkzgziefy.supabase.co | Sign-in, data and files (Supabase, Frankfurt) |
challenges.cloudflare.com | Bot protection of the sign-in form (Cloudflare Turnstile); without this address no sign-in link can be requested by email |
accounts.google.com | Only for "Sign in with Google" |
board@knowhand.comsend.knowhand.com | Sender and technical sender domain of emails |
checkout.stripe.combilling.stripe.com | Payment and customer portal, only for admins who manage the subscription |
Where your data lives
- Hosting, database and files: Frankfurt (EU). Email: EU. Payment: Stripe (EU).
- AI assistant: off by default. When on, the entered request text and the board category names go to Google Vertex AI in Frankfurt or to your own endpoint.
- All sub-processors are listed in the data processing agreement.
How Knowhand protects your data.
The measures as implemented in the application. In detail in chapter 4 of the review pack.
- Tenant isolation in the database: Row Level Security on every table, reads only within your own board, including images and attachments.
- Column-level write permissions: plan, status, counters, email address and board membership are changed by the server only.
- Every action checks membership and role on the server. The database service key never reaches the browser.
- Files only through short-lived signed links. Uploads only through the server, with checks for type, size and storage quota.
- Security headers on every page: HSTS, Content Security Policy, protection against embedding, nosniff, Referrer-Policy and Permissions-Policy.
- Encrypted transport (TLS) and encrypted storage at the database provider. Your own keys for the AI assistant are stored encrypted (AES-256-GCM).
- Payment and email callbacks are only processed with a valid signature.
- All operator accounts for hosting, database, code, payment and email sending are protected with two-factor sign-in. Daily backups, kept for 7 days.
When someone leaves, remove them in Knowhand.
Knowhand is not connected to your directory. If you block an account in Microsoft Entra ID or Google Workspace, the person stays a member in Knowhand. Remove them in the board as well.
- 1
Open Admin
In the board under Admin › Members.
- 2
Remove the person
Choose "Remove" next to the person.
What happens
- The profile is pseudonymised, the person's requests stay as "Former member".
- Open offers to help and the person's invite links are withdrawn.
- The person can't come back on their own, neither through the company domain nor through an invite link.
- The last admin can't be removed. Appoint another one first.
SSO with SAML
SAML is not built in; on request we look into it, without a commitment. There is no SCIM. Today you sign in with a link to your work email or with the company Google account.
Write to hallo@knowhand.comExport, deletion and operations.
Export and deletion
- Every member exports their data as JSON in the profile and deletes their account themselves; the profile is pseudonymised.
- Admins export the whole board as JSON and the requests as CSV. The export shows who posted which request or offered help, with the time. Attachments are listed only with name, type and size.
- Deletion by the admin: final 14 days after confirmation, with all attachments. After cancellation the board stays readable for 60 days, then it is deleted.
- Email delivery logs: 90 days. Backups: 7 days.
Operations and contact
- Availability: 99.5% monthly average targeted, excluding announced maintenance and outages at subcontractors (terms).
- Support by email at hallo@knowhand.com, reply within one working day. There is no phone hotline.
- Knowhand is run by Paul Krügel in Vienna (sole proprietorship). You can export your data as JSON and CSV at any time.
Common questions from IT
Can I sign in to Knowhand with Microsoft?
Not yet. The link by email works with any work address, including Microsoft 365 mailboxes. Allow board@knowhand.com in your spam filter and follow the note on link scanners.
Which permissions does Knowhand request when signing in with Google?
Three: openid, email and profile. Knowhand receives the name, email address, the Google account ID and, if available, the address of the profile picture. Knowhand doesn't request access to mailboxes, calendars, files or the directory.
Which address does Knowhand send email from?
From board@knowhand.com, through the email service Resend from the EU. Sign-in links use the sender name "Knowhand", notifications "Board name via Knowhand". Opens and clicks are not tracked.
Who creates the board for our domain, and how does IT become admin?
Whoever signs in first with an address from your domain creates the board and is admin. That person appoints further admins under Admin › Members, including people from IT. Automatic joining via the domain can also be turned off there.
Does Knowhand remove people automatically when we block their work account?
No. Knowhand is not connected to your directory. An admin removes the person in the board under Admin › Members, which pseudonymises the profile.
Does Knowhand support SAML or SCIM?
SAML is not built in; on request we look into it, without a commitment. There is no SCIM. Today you sign in with a link to your work email or with the company Google account.
Where does Knowhand store our data?
Hosting, database and files are in Frankfurt (EU). Email goes through a sending service in the EU, payments through Stripe (EU). Vercel, Supabase, Resend and Cloudflare (bot protection of the sign-in form) are headquartered in the USA; any transfer is covered by EU Standard Contractual Clauses. All sub-processors are listed with location and basis in the data processing agreement.
Does our IT team have to install anything for Knowhand?
No. Knowhand runs in the browser, on the computer and on the phone. There is no app or client to roll out.
Still open?An IT question that isn't answered here?
Write to us. Paul answers support emails personally, within one working day.