Account protection
Security & sign-in
Two-factor required — all roles
Signing in
Two ways to start a session: email magic link or email + password. Magic-link is the recommended path — we email you a one-tap link, valid for 15 minutes and single-use. Password sign-in is available once you set one in Settings → Password.
After your first factor verifies, you will be prompted for your six-digit authenticator code. Codes refresh every 30 seconds, and we accept codes from up to 90 seconds either side of now to tolerate phone clock drift — so you rarely need to wait for a fresh one.
Two-factor authentication (within 14 days)
Every account must enrol an authenticator app (Google Authenticator, 1Password, Authy, Bitwarden, etc.) within 14 days of sign-up. During the grace period a banner at the top of every page reminds you and counts down the days remaining. After 14 days, sign-in will be blocked until enrolment is complete.
- Open Settings → Two-factor authentication.
- Scan the QR code with your authenticator app, or copy the secret manually if scanning is not possible.
- Enter the 6-digit code from the app to verify enrolment.
- Save the ten recovery codes — they are shown only once. Store them in a password manager or print them.
Recovery codes
- Ten codes per enrolment. Each one is single-use.
- Shown once at enrolment and once after regeneration.
- If you lose access to your authenticator, use a recovery code from the sign-in challenge page.
- Regenerate from Settings → Two-factor authentication if codes run low. The old set stops working immediately.
Lost authenticator AND recovery codes
Contact support. We will verify your identity out-of-band (a callback to a known number, recovery email, or another trusted channel) before resetting your two-factor settings. After the reset, you will be required to enrol a fresh authenticator on your next sign-in. You will also receive an email recording who reset your 2FA and when — if you did not request the reset, contact support immediately.
Disabling two-factor
Two-factor is mandatory for every account — you cannot turn it off and keep using the CRM. The Disable button on the settings page exists only so you can switch authenticator apps: disable, then immediately re-enrol with the new app.
Sessions, sudo, and time display
- Sessions are valid for 14 days of activity. Idle sessions expire automatically.
- Sensitive actions (changing your password, changing your email, disabling 2FA) require a fresh sign-in within the last 10 minutes. You may be asked to re-authenticate.
- All timestamps in the app are shown in UK local time and follow British Summer Time automatically.
- Use Force sign out in your settings to revoke every other device immediately if you suspect a session is compromised.