Help center / Guide 03

security &two-factor

The protections that are on by default, and the ones you control.

Turn on two-factor sign-in

  1. Open My account → Two-Factor and confirm your password.
  2. Scan the QR code with an authenticator app, or type the setup key by hand.
  3. Enter the 6-digit code the app shows to confirm.
  4. Save your recovery codes. Each one works once and lets you sign in if you lose your phone. Store them in a password manager or print them; anyone with them can pass your second factor.

From now on you'll enter a code from the app after your password. Each code can be used only once, so a code someone sees over your shoulder is useless to them.

Lost your phone? At the code prompt, open Lost your device? Use a recovery code, then set two-factor up again and generate new codes. No codes left? Ask a workspace administrator to reset your two-factor.

Require two-factor for everyone

Administrators can switch on Enforce two-factor under Administration → Security Policy. Anyone without it is taken to the setup page after signing in and can't use the apps until it's done. You must have two-factor on yourself before you can enforce it.

Password rules

  • At least 12 characters, with upper- and lower-case letters, a number and a symbol.
  • You can't reuse any of your last 5 passwords.
  • Administrators can make passwords expire after 30–730 days (Security Policy → Password expiry).
  • Passwords are stored with Argon2id hashing; nobody, including us, can read them.

Failed sign-ins and lockouts

After 5 wrong passwords the account is locked for 15 minutes. An administrator can unlock it early from Users. Sign-in attempts are rate-limited per email address and per network address, so guessing at scale doesn't work.

Sessions

  • My account → My Security lists every device where you're signed in. Sign out a single device or all other devices at once.
  • Idle sign-out: administrators choose how long an inactive session stays open (5–720 minutes) under Security Policy.
  • Changing your password signs out your other sessions.

Restrict sign-in to your networks (IP allowlist)

Under Security Policy → IP allowlist, list the addresses or ranges (one per line, e.g. 203.0.113.10 or 198.51.100.0/24) that may use your workspace. Requests from anywhere else are refused. To stop you locking yourself out, the address you're using now must be on the list.

Sensitive employee data

Salary, bank account and national ID numbers are encrypted at rest and masked on screen. Only people with HR sensitive data can reveal them, and every reveal is written to the audit trail with who and when.

The audit trail

Administration → Audit Trail records every important change: who did what, when, from which address, and the before-and-after values. Entries are hash-chained: each one includes a cryptographic fingerprint of the previous one, so editing or deleting any row in the database breaks the chain.

Press Verify chain integrity at any time. A green result means the trail is complete and unaltered; a failure tells you where the chain breaks.

Security events

Administration → Security Events is a live feed of sign-ins, failed attempts, lockouts, two-factor changes and session revocations. Events are kept for 365 days.

Good habits

  • Turn on two-factor for every account, then enforce it.
  • Give each person their own account; never share a login.
  • Review Users and Roles & Access every few months.
  • We will never ask for your password, codes, recovery codes or API tokens.