Account and organization security

Protect sign-in, two-factor authentication, invitations, integrations, and organization credentials.

Security has two layers: the user account at /account and the organization settings available from the organization profile. Protect both layers when administrators, volunteers, or service providers change.

Protect the account

From /account, review the profile and security controls:

  • Keep the email address current because it is used for account-related confirmation.
  • Set or change the password through the account security controls.
  • Review linked social accounts and keep only accounts that should remain connected.
  • Enable two-factor authentication with an authenticator application.
  • Keep the generated backup codes in a secure location.

Enabling two-factor authentication requires the current password. The setup then shows a QR code and asks for a six-digit authenticator code. Disabling two-factor authentication and regenerating backup codes also require the password.

Do not store a QR code or backup codes in a public document. If backup codes may have been exposed, regenerate them immediately and confirm that the new set is stored securely.

Protect organization access

In the organization profile:

  1. Invite only named users who need access.
  2. Assign the smallest role that supports the person’s work.
  3. Remove former members and cancel unused invitations.
  4. Review the activity view when available to administrators.
  5. Rotate API tokens and managed keys after staff or vendor changes.

Do not share one administrator login. Individual accounts make invitations, role changes, and removal auditable.

Protect integrations

Organization integrations may contain Telegram credentials, Firebase service-account data, WhatsApp device connections, notification topics, API keys, and MCP access. Treat each as a secret or privileged connection:

  • Paste credentials only into the intended settings field.
  • Do not place secrets in page content, custom code, screenshots, or video recordings.
  • Restrict third-party keys at the provider where possible.
  • Test notifications with a private destination first.
  • Disconnect or rotate a provider connection when it is no longer trusted.

Deletion and recovery

Account deletion and organization deletion are destructive administrative actions. Before confirming either action, export records that the organization must retain and verify that no active team member or integration still depends on it. Follow the confirmation text shown by the application; do not treat deletion as a reversible test.

If access is lost

Use the account recovery flow for a lost password or email verification issue. If a member can sign in but cannot see a feature, check role, organization selection, verification state, plan state, and feature access before changing credentials.