Skip to Content
Policies and PasskeysTroubleshooting

Troubleshooting

The cases on this page have one thing in common: the system works as designed, but the message is not enough to understand what is missing.

What looks like a problem but is not

  • It asks you to sign with your passkey on every operation
    That is by design. People always sign
  • The operation is “pending approval”
    That is the expected response, not an error. It completes when the signatures come in
  • The same operation works through the API but not in the dashboard
    API users do not sign; people do
  • You do not see a button or a screen
    Your role does not include it. Koywe hides what you cannot use
  • You are a Super Admin user and cannot approve someone else’s passkey
    Being a Super Admin user is not enough: only the root user can do that

Everything is denied, even creating a rule

What is missing: that user never got the rule that lets them edit the approval policy. It happens in organizations created a while ago, or when a Koywe user did the initial setup instead of the customer.

What to do: ask Koywe to assign them the Super Admin role again. That creates the missing rule, and from there the customer builds the rest on their own.

The rules point to someone who is not on my team

What is missing: if the organization was set up through the API or with an internal tool, the rules were tied to whoever did that setup. The actual Super Admin user inherits an approval policy that allows them nothing.

What to do: the same as above, then rewrite the rules so they point to real people. On day one, check that the initiator of your rules is someone on your team.

I added a bank account and it disappeared

What is missing: a rule that allows changing destination accounts. The account was never created — it did not disappear, it never existed. And since the denial is easy to miss, the person thinks it worked.

It often comes with a confusing detail: a teammate can create accounts. That is because they have the rule and the other person does not.

What to do: add the destination account changes rule for that person, or have the teammate who already can do it. It is the most often forgotten permission.

I cannot edit the approval policy

What is missing: someone deleted the last rule that allowed editing it. No other rule covers it, so the organization is locked out of its own approval policy.

What to do: only Koywe can restore it. To keep it from happening again: if you want to change who manages the approval policy, add the new rule first and check that it works, then delete the old one.

I am a Super Admin user and cannot approve passkeys for my team

What is missing: one of two things.

  • You are not the root user. Only the user who registered the organization approves the others.
  • You are the root user but sign with an email code. The code does not work for approving passkeys.

What to do: find out who did the company’s onboarding: that is the root user. If that person cannot get a passkey to work on their device, that is the first thing to fix.

I created my passkey but signing says it is invalid

What to check, in this order:

  1. Which device was it created on, and which one is being used to sign? This is by far the most common cause. A phone passkey only works on a computer if the provider syncs it or if the QR code is scanned.
  2. Is it approved? A pending registration cannot sign.
  3. Was there a recovery before? The old passkey is revoked permanently.
  4. Is it for this organization? Someone who works in two organizations needs one in each.
  5. Is the browser picking a different credential? Ask them to choose it manually in the dialog.

Recommend storing the passkey in a synced password manager (iCloud Keychain, Google Password Manager, 1Password), not tied to a single machine.

I cannot sign from Windows or Android

What is happening: certain Windows and Android combinations over QR code drop right at signing. It is not a permissions problem, which is why resetting the passkey usually does not help.

What to do:

  1. Try another browser and, if available, another device.
  2. If they need to keep operating, ask Koywe for the email code as an alternative. Important: it works for approving, not for signing crypto operations from the wallet.
  3. Send support the device, operating system, and browser. That combination is the useful information, not the error text.

It says “You already have a passkey” or “the user already exists”

What is happening: there is already a credential for that person in the organization, often a revoked one from an earlier attempt.

What to do: run a recovery, not a new registration. The root user starts it, the person receives a code by email and creates a new passkey.

If the person locked out is the root user, they cannot recover on their own: they have to email Koywe from the organization’s registered email address.

I cannot choose someone as an approver

What is happening: three different rules.

  • Nobody approves their own operation, so the rule’s initiator does not appear as an approver.
  • The approver needs permission to approve (a Treasury Manager, Admin, or Super Admin user).
  • The approver needs to be able to sign. Without an approved passkey, they appear in the list but can never act.

What to do: choose a second person with an approving role and a passkey ready. If the rule requires several approvals, have at least three candidates.

I added a stricter rule and it does nothing

What is happening: new rules are added at the end, and an earlier, more permissive rule applies first. Especially if that rule has no minimum amount: it takes everything.

What to do: move your new rule above the permissive one. Within the same operation type, order from highest amount to lowest. Then confirm in the audit log which rule actually applied.

I do not see anything about passkeys or the approval policy

What is happening: the organization is exempt from the approval policy, from an earlier onboarding.

What to do: ask Koywe to remove the exemption — but write the rules first. The day it is removed, without rules nothing can be operated.

A pending operation disappeared

What is happening: pending items expire after 24 hours, including passkey registrations. It was not left half done: it simply never ran.

What to do: start it again and get the signature right away. If your approvers are in another country, keep that in mind when you decide which operations require approval.

The approvers already signed and my order is still waiting

What is missing: almost always the signature of the person who started it. When a rule requires approval, both sides sign. The screen shows it as “Pending requester signature”.

What to do: the person who created the operation goes to their pending items and signs. Nobody can sign for them.

How to ask for help

Some things only Koywe can do:

  • Write to support, not through side channels. A request that does not reach support is not logged.
  • Passkey or Super Admin changes need a written request from the organization, because they change who controls the money. This is on purpose.
  • Always include: organization ID, company ID if applicable, the user’s email, what they were trying to do, and the exact error.

Next steps

  • First steps — set it up right from the start, in order.
  • User roles — what each role can do and which screens it sees.
  • If none of this solves it: How to ask for help, with the details worth including.
Last updated on