Saltar al contenido

Administration

Securing your organisation's account

Second factor, devices, single sign-on and what to check when something feels off.

Open it in the platformUpdated on 13/08/2026

In an account holding signed contracts and evidence with probative value, security is not an optional setting you look at in year two. Three things are worth settling in the first month, and one is worth knowing how to check when a doubt arises.

Two-factor authentication

It is the measure that removes the most risk for the least effort. A password leaked somewhere else stops being enough to get in. For accounts with administration rights it is not negotiable: those are the ones that can change the whole organisation's configuration.

Passkeys

They replace the password with the device's fingerprint or face. There is nothing to remember and nothing to leak, and they cannot be phished with a fake email because they are bound to the real domain. If your team uses modern phones or laptops, it is the most convenient and the most secure route at once.

Single sign-on

If your company already runs a corporate identity system, connecting the platform to it avoids the classic problem: someone leaves, their email is removed and this account is forgotten. With single sign-on, there is only one offboarding to do.

Watch out

Before enabling single sign-on, make sure at least one administrator keeps direct access. If the connection fails and nobody can get in another way, recovering access is a great deal slower.

When something feels off

  1. 1

    Check the devices with an open session

    One you do not recognise can be signed out from there, changing nothing else.

  2. 2

    Review the audit log

    Who logged in, from where and what changed. That is what turns a suspicion into a fact.

  3. 3

    Change the password and enable two-factor

    In that order: changing it without a second factor leaves the door just as open.

Frequently asked questions

Can I require two-factor for the whole team?

Yes, it can be enforced by organisation policy. For administration accounts it should always be mandatory.

What if someone loses the phone with their second factor?

An administrator can reset it for them. Which is why it matters that more than one person holds that permission.

Does an external participant need two-factor?

They have no account, so it does not apply. Their access is a personal link, and on advanced signatures they are verified with the SMS code.

Can I enforce a minimum password length?

Yes, there is a password policy configurable per organisation.

A real case

The situation

An administrator gets a sign-in alert from a country where they have nobody.

What you do

  1. Opens the device list and signs out the session she does not recognise
  2. Reviews the log for what that session did
  3. Requires two-factor on every account with administration rights

What you get

She knows exactly what was touched and closes the door the same day, instead of wondering for a week.

The situation

There is one administrator and they are on holiday.

What you do

  1. Names two administrators from the start

What you get

The account does not depend on one person.

The situation

Nobody has reviewed who has access in years.

What you do

  1. Schedules a periodic review

What you get

Access reflects today's organisation.

The situation

The second factor is switched off.

What you do

  1. Turns it on with advance notice

What you get

The account is protected without blocking anyone.

The situation

A security notice arrives and nobody reads it.

What you do

  1. Addresses notices to more than one person

What you get

The notice reaches somebody who can act.

The situation

An account is shared between several people.

What you do

  1. Gives each one their own account

What you get

The log says who did what.

This article answers

  • enable two-factor authentication
  • securing my organisation's account
  • set up single sign-on SSO
  • sign out of a lost device
  • company password policy