Securing your account
Passkeys, passwords, two-factor and what to do when a device is gone.
#What actually guards your account
Four things can let you into sSystm: a passkey, a one-time link, a password, or a password plus two-factor. They are not tiers to climb — they are choices, and most people end up using two.
New accounts are created through a one-time link. Password registration is switched off entirely, so nobody arrives with a password as their only key; a password is something you add afterwards if you want one. What that buys you is that there is no account in the system whose security is one guessable string.
The full comparison, including which of them can be phished, is on Signing in.
#Passkeys, one per device
A passkey lives on the device you created it on and is bound to this site. Add one per device you actually use — a laptop and a phone is a good pair, because either can rescue the other.
Add and remove them under Settings → Security. Removing one has no effect on the others, which is what makes a lost device a small problem rather than a large one.
#If you want a password anyway
Some organisations require one. Set it under Settings → Security.
- Never had one? You are asked for the new password only. There is no old one to prove.
- Changing an existing one? You are asked for the old one as well, and every other session is signed out. A password change should end any session you did not start.
- Minimum eight characters. Length is what matters; a long passphrase beats a short scramble.
It is the only method that can be phished, reused across sites, or read out of somebody else’s breach. If you use one, turn on two-factor as well.
#Two-factor
Two-factor adds a rotating code from an authenticator app on top of whichever method you use. Turn it on under Settings → Security; you scan a code once and confirm with the first number it gives you.
Turning it on issues backup codes. Keep them somewhere other than the device running the authenticator app — if you lose that device and the codes were on it, nobody can let you back in, including us.
#When something is lost
| What you lost | How you get back in |
|---|---|
| Your password | Sign in with a one-time link, then set a new password in Settings. There is no reset email — see Signing in for why. |
| The device with your passkey | Sign in with a one-time link on another device, then remove the old passkey and add one for the device you are on. |
| Your two-factor device | Use a backup code. Then turn two-factor off and on again to pair the new device. |
| Your backup codes and the device | An owner in your organisation has to remove and re-invite you. We cannot bypass two-factor on your behalf — an account recovery we could perform on request is an account recovery anyone could talk us into. |
| Access to the email address itself | The address is the root of everything else. Change it in Settings before you lose the mailbox, not after. |
#Removing someone
Removing a person from the organisation ends everything at once: their session, their permissions, and any AI connection they had made. There is no lingering token that keeps working because it was issued earlier — see Tokens.
It does not touch the cloud account. That belongs to the organisation, not to the person who happened to connect it.
Geverifieerd met de app op