Saltar al contenido

Administration

Protecting your team's accounts

The three measures that prevent nearly everything, ordered by effort.

Open it in the platformUpdated on 13/08/2026

What sits inside are contracts, payroll and identity documents belonging to people who are not here to protect them. Three measures cover almost everything that can go wrong, and all three take one afternoon.

1. Two-factor, mandatory

A password on its own leaks: it gets reused, written down, stolen from another service. A second factor means a stolen password is not enough. By some distance it is the best protection per unit of effort.

Important

Make it mandatory for the whole organisation, not optional. Optional means three people turn it on and the other twenty do not.

2. Each person with their own

Making everyone an administrator is convenient until the day someone deletes something. Those who only look, look; those who only sign, sign.

3. Watch who signs in

The log shows who signed in, from where and what they did. Reviewing it monthly catches the account of someone who left six months ago and is still open.

MeasureEffortPrevents
Mandatory two-factorOne afternoonA leaked password opening the door
Tight permissionsHalf an hourAccidental deletions and changes
Monthly reviewTen minutes a monthLive accounts for people who left

Watch out

When someone leaves, remove their access that same day. It is not distrust: it is that their account stays open and nobody is watching it any more.

What if someone loses their two-factor phone?

An administrator restores access after checking who they are. Which is why you want two administrators.

Can people sign in with their work account?

Yes, if you have corporate sign-in. It is the easiest option once you are many.

Am I warned about odd sign-ins?

Sign-ins are logged with their location and device.

A real case

The situation

A sixty-person company makes two-factor mandatory.

What you do

  1. Warns everyone a week ahead
  2. Switches it on a Monday
  3. Keeps two administrators able to restore access

What you get

Four people need help on day one and none after that.

The situation

Somebody uses the same password as elsewhere.

What you do

  1. Turns on the second factor for everyone

What you get

A leaked password stops being enough.

The situation

The second factor is switched on unannounced and everyone locks out.

What you do

  1. Gives a week's notice and leaves a recovery route

What you get

The change happens without stopping work.

The situation

Nobody knows who has the second factor active.

What you do

  1. Checks the status per person

What you get

The gaps become visible.

The situation

Somebody loses a phone with the session open.

What you do

  1. Closes their sessions from administration

What you get

Access is cut within minutes.

The situation

An account is shared to get past a problem.

What you do

  1. Creates that person their own account

What you get

The log keeps saying who did what.

This article answers

  • enable two-factor authentication
  • require 2fa for the whole team
  • how do i protect my company account
  • someone accessed an account