---
id: KB-AD-001
url: https://app.codecontract.io/help/administration/account-security
idioma: en
categoria: administracion
audiencia: administrador
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-ET-002, KB-TZ-001, KB-ET-001, KB-AD-005, KB-AD-018]
citadoPor: [KB-CD-002, KB-AD-012, KB-AD-013, KB-AD-002]
enLaApp: https://app.codecontract.io/settings/security
---

# Securing your organisation's account

_Second factor, devices, single sign-on and what to check when something feels off._

**Responde a:** enable two-factor authentication · securing my organisation's account · set up single sign-on SSO · sign out of a lost device · company password policy

In an account holding signed contracts and evidence with probative value, security is not an optional setting you look at in year two. Three things are worth settling in the first month, and one is worth knowing how to check when a doubt arises.

**En corto**

- Two-factor is mandatory for administrators and advisable for everyone.
- Passkeys are both more convenient and more secure than a password.
- Single sign-on centralises joiners and leavers in the system you already use.
- The audit log is what answers "who logged in and what did they do".

## Two-factor authentication

It is the measure that removes the most risk for the least effort. A password leaked somewhere else stops being enough to get in. For accounts with administration rights it is not negotiable: those are the ones that can change the whole organisation's configuration.

## Passkeys

They replace the password with the device's fingerprint or face. There is nothing to remember and nothing to leak, and they cannot be phished with a fake email because they are bound to the real domain. If your team uses modern phones or laptops, it is the most convenient and the most secure route at once.

## Single sign-on

If your company already runs a corporate identity system, connecting the platform to it avoids the classic problem: someone leaves, their email is removed and this account is forgotten. With single sign-on, there is only one offboarding to do.

> [!WARNING]
> Before enabling single sign-on, make sure at least one administrator keeps direct access. If the connection fails and nobody can get in another way, recovering access is a great deal slower.

## When something feels off

1. **Check the devices with an open session** — One you do not recognise can be signed out from there, changing nothing else.
2. **Review the audit log** — Who logged in, from where and what changed. That is what turns a suspicion into a fact.
3. **Change the password and enable two-factor** — In that order: changing it without a second factor leaves the door just as open.

## Frequently asked questions

**Can I require two-factor for the whole team?**

Yes, it can be enforced by organisation policy. For administration accounts it should always be mandatory.

**What if someone loses the phone with their second factor?**

An administrator can reset it for them. Which is why it matters that more than one person holds that permission.

**Does an external participant need two-factor?**

They have no account, so it does not apply. Their access is a personal link, and on advanced signatures they are verified with the SMS code.

**Can I enforce a minimum password length?**

Yes, there is a password policy configurable per organisation.

## Ejemplos

**An administrator gets a sign-in alert from a country where they have nobody.**

- Opens the device list and signs out the session she does not recognise
- Reviews the log for what that session did
- Requires two-factor on every account with administration rights

→ She knows exactly what was touched and closes the door the same day, instead of wondering for a week.

**There is one administrator and they are on holiday.**

- Names two administrators from the start

→ The account does not depend on one person.

**Nobody has reviewed who has access in years.**

- Schedules a periodic review

→ Access reflects today's organisation.

**The second factor is switched off.**

- Turns it on with advance notice

→ The account is protected without blocking anyone.

**A security notice arrives and nobody reads it.**

- Addresses notices to more than one person

→ The notice reaches somebody who can act.

**An account is shared between several people.**

- Gives each one their own account

→ The log says who did what.
