Connect & secure

Security & your account

Your account is the key to everything your workspace holds. This page covers what's yours to set — name, language, password, second factor — and what admins can see about how the workspace is being used.

User guide › Security & your account

Where your settings live

Open Settings at the foot of the sidebar, or click your avatar in the top bar. Everything on this page except the audit log sits in the Personal category, which every member can open regardless of role.

PageHolds
ProfileYour display name, email, workspace, your AI usage, and changing your password.
PreferencesInterface language and the daily digest email.
SecurityTwo-factor authentication, recovery codes and passkeys.
IntegrationsAccounts you've connected — see Integrations & API.

Your profile

Display name is what colleagues see next to your comments, on records you own and in mentions. You can change it yourself at any time.

Email is shown but not editable by you — an admin changes it from Members & Permissions. That's deliberate: your email is how you sign in and how a password reset reaches you, so it isn't a field you can quietly alter.

The page also shows which workspace you're in, whether you're an admin, and your AI usage for the month against whatever cap applies to you. See AI in BackOffice.

Preferences

Language sets the interface language. It's stored in the browser you set it in, so if you use BackOffice on a laptop and a phone, set it on each. Field labels your workspace has translated follow the same setting.

Theme — light or dark — is the toggle in the top bar rather than a settings page, because it's a control people flip several times a day. It's remembered per person.

Daily digest email is an opt-in morning summary of what's new for you. Turn it on and pick the hour and your timezone; the page confirms when the next one is due. It relies on the workspace email sender being configured, so if nothing arrives, that's the thing to ask an admin about.

Signing in

The sign-in screen asks for your workspace, then your email or username and your password. The workspace field matters — the same email can belong to more than one workspace, and they're entirely separate.

Depending on what your workspace has enabled, you may also see Continue with Google, Microsoft or LinkedIn, and Sign in with a passkey. Options that aren't set up for your workspace say so rather than failing silently.

Forgot password? sends a reset link to the email on your account. The link is valid for 30 minutes. If it doesn't arrive, check spam before assuming the address is wrong.

Changing your password

Settings → Profile → Change password. You enter your current password, then the new one twice. New passwords must be at least 8 characters.

Changing it doesn't sign other devices out

If you're changing your password because you think someone else has it, that alone isn't enough. Sign out from each device you're still signed in on, and turn on a second factor so a password on its own stops being sufficient.

Two-factor authentication

Two-factor authentication means signing in needs your password and a 6-digit code from an app on your phone. It's the single highest-value thing on this page: it makes a stolen password useless on its own.

Settings → Security shows whether it's on. Turning it on:

  1. Scan the code A QR code appears. Scan it with an authenticator app — Google Authenticator, 1Password, Authy, Microsoft Authenticator and others all work. If you can't scan, copy the manual entry key instead.
  2. Confirm Type the 6-digit code your app is showing. This proves the app is set up correctly before the requirement is switched on.
  3. Save your recovery codes A set of one-time recovery codes is generated at this point. Save them before you close the panel — see below.

After that, sign-in asks for a code after your password. Turning it back off requires a current code, and doing so clears your recovery codes.

Recovery codes

Recovery codes are what get you back in when your authenticator app isn't available — phone lost, replaced, or simply not on you. Each code works exactly once and is entered in place of the 6-digit code at sign-in.

You see them once

They're displayed when they're generated and can't be shown again. Use Copy all or Download .txt and put them somewhere you can reach without your phone — a password manager, or printed and stored offline. Not a note on the phone the authenticator app is on.

The Security page shows how many unused codes you have left. When that number gets low, Regenerate issues a fresh set — you'll need a current 2FA code or an unused recovery code to do it, and the previous batch stops working immediately.

Passkeys and security keys

A passkey signs you in with your fingerprint, face or a physical key instead of typing a password. Touch ID, Windows Hello and hardware keys such as a YubiKey are all supported, on any browser that handles them. It's both faster and harder to phish than a password, because there's no secret to type into the wrong site.

Under Security keys / passkeys, give the key a name — "Work YubiKey", "Laptop" — and choose what kind you're registering:

KindUse when
This deviceYou're registering Touch ID, Windows Hello or the built-in passkey on the machine you're using.
External keyYou're registering a physical key you plug in or tap.
AutoYou're not sure — the browser offers every option and you pick.

Registered keys are listed with when they were added and last used, and some are marked as synced across your devices. Register more than one if you can — a phone and a hardware key, say — so losing one doesn't lock you out. Removing a key warns you that you'll need another way in.

Signing out

Sign out lives in the menu under your avatar. It ends the session on that device only; other devices you're signed in on stay signed in. To be sure you're signed out everywhere, sign out on each one.

The audit log Admin

Settings → Audit log is a timeline of what's been happening in the workspace. Each entry records who did it, what kind of thing it was done to, which action it was, and when.

Actions are named plainly — creates, updates, deletes, sign-ins — and colour-coded so deletions stand out from routine activity. The page shows recent entries and refreshes itself while you have it open.

It's most useful for two questions: "who changed this and when", and "does this account's activity look like the person it belongs to". Neither needs you to read it daily; it needs you to know it's there.

Practical advice

  • Turn on two-factor authentication, and save the recovery codes somewhere you can reach without your phone.
  • Use a unique password. Reused passwords are how most accounts are lost — a breach somewhere else becomes a breach here.
  • Register a passkey as well. It's quicker day to day and gives you a second way in.
  • Sign out on shared or borrowed machines. Closing the tab is not signing out.
  • Tell an admin when someone leaves so their access is removed rather than left dormant. See Permissions & access.
  • Revoke API tokens you no longer use. A token keeps working until someone revokes it — see Integrations & API.
We will never ask for your password

BackOffice asks for your password on the sign-in screen and nowhere else. Nobody from BackOffice, and no colleague or administrator, needs it — not by email, not in chat, not over the phone. Anyone asking is not who they say they are. The same goes for your 6-digit codes and your recovery codes.

If you think your account has been used by someone else, change your password, turn on two-factor authentication, and tell an admin so they can check the audit log.