Account settings

How candidates and employers change their password or email, set a password on a passwordless account, and delete their own account from your board.

Signed-in candidates and employers manage their own account from Settings on your board. The page is the same for both roles: email notifications, then sign-in and security (email, then password), then a danger zone for account deletion. Labels on that page are editable in the website builder.

Password, email, and account deletion are always available. They are not behind a feature toggle, because they are the person's own account rights.

Prerequisites

Candidate accounts or employer accounts (or both) must be enabled under Settings → Features. The person must be signed in and have verified their email.

Change or set a password

Accounts that already have a password see a Change password card. They enter the current password and a new password (at least eight characters). The current session stays signed in. Every other session for that account ends.

Magic-link and Google or LinkedIn accounts often have no password. Those people see Set password instead. That action sends the existing password-reset email to the address on the account. They set the password from the link in that email. There is no in-session "plant a password" form.

The logged-out forgot-password flow is unchanged and still works for both password and passwordless accounts.

Change email

Email change is verify-then-switch:

  1. From Settings, the person enters the new address.
  2. Cavuno checks that the address is not already used on this board and emails a confirmation link to the new address. The link expires after 24 hours.
  3. The account email switches only after they open that link. The new address is marked verified.
  4. A security notice is sent to the old address so a hijack is visible.

The person stays signed in. They do not need to re-enter a password to start the change, so passwordless accounts can use the same flow. The new inbox is the gate.

Delete the account

The danger zone on Settings lets the person delete their own account. They confirm by typing a confirmation word. There is no email code step.

Deletion is immediate and irreversible. It removes the login and the personal data attached to it (candidate profile, collections, saved jobs, alerts, avatar, resume). Companies always survive. Memberships are removed. If the deleted person was an admin, the earliest remaining approved member of that company is promoted to admin so the company is never left without one.

Employers who delete their account do not delete their companies or live jobs. To remove a company from the board, a company admin uses employer company deletion when you have that toggle on.

A candidate who only wants to leave the talent pool can set profile visibility to Hidden instead of deleting the account. See Candidate profiles.

After deletion, Cavuno emails a confirmation to the address that was on the account.

Availability

  • Plan: All paid plans. Account settings are part of candidate and employer accounts, which are available on every paid plan.
  • Setting: None for password, email, or account deletion. Those controls appear whenever the matching account type is on. Candidate accounts use Settings, then Features, then "Candidate profiles." Employer accounts use Settings, then Features, then "Employer accounts."
  • Setup required: None.

Limitations

  • Passwordless accounts cannot set a password inside the Settings form. They use the password-reset email.
  • An email change does not complete until the new address is confirmed. The old address keeps working until then.
  • Account deletion cannot be undone. You can still manage any companies left on the board from Companies in your dashboard.

Customize the emails

These Settings actions send board-branded mail you can edit in the Email editor:

  • Email change confirmation (board-email-change): the link sent to the new address
  • Email changed notice (board-email-changed-notice): the security notice sent to the old address
  • Account deleted (board-account-deleted): the confirmation sent after deletion

Set password uses the existing Password reset template.

Verify account settings

Sign in as a test candidate and as a test employer. Confirm Settings shows Email, then Password, then the danger zone. Change a password on an email-and-password account and confirm other sessions end. On a magic-link account, request Set password and complete the reset email. Request an email change, confirm from the new inbox, and check that the old inbox received the notice. Delete a throwaway account and confirm the person is signed out, the confirmation email arrives, and any company they managed is still in your Companies list.

Example

A recruiter who signed up with Google opens Settings, requests a password so they can also sign in with email, then later changes their work address. They confirm the new inbox, keep working in the same session, and their old address gets the security notice.

Next steps

For how job seekers sign in, see Sign-in and accounts. For employer teammates, see Employer team access. For removing a company (not just a login), see Employer company deletion.

Frequently asked questions