Account protection
Security & sign-in
Two-factor required — all roles
Signing in
Two ways to start a session: email magic link or email + password. Magic-link is the recommended path — we email you a one-tap link, valid for 15 minutes and single-use. Password sign-in is available once you set one in Settings → Security.
After your first factor verifies, you will be prompted for your six-digit authenticator code. Codes refresh every 30 seconds, and we allow 90 seconds either side of the current code to absorb a phone whose clock has drifted a little. Your device clock still needs to be roughly right, so leave automatic date and time switched on (and, if your authenticator app offers a “time correction” option, use it). If a code is rejected, check the clock before anything else, then wait for the next code.
Two-factor authentication (within 14 days)
Every account must enrol an authenticator app (Google Authenticator, 1Password, Authy, Bitwarden, etc.) within 14 days of sign-up. During the grace period a banner at the top of every page reminds you and counts down the days remaining. After 14 days you can still sign in, but every page sends you straight to the enrolment screen until you have enrolled.
- Open Settings → Two-factor authentication.
- Scan the QR code with your authenticator app, or copy the secret manually if scanning is not possible.
- Enter the 6-digit code from the app to verify enrolment.
- Save the ten recovery codes — they are shown only once. Store them in a password manager or print them.
Recovery codes
- Ten codes per enrolment. Each one is single-use.
- Shown once at enrolment and once after regeneration.
- If you lose access to your authenticator, use a recovery code from the sign-in challenge page.
- Regenerate from Settings → Two-factor authentication if codes run low. The old set stops working immediately.
Lost authenticator AND recovery codes
Contact support. We will verify your identity out-of-band (a callback to a known number, recovery email, or another trusted channel) before resetting your two-factor settings. After the reset, you will be required to enrol a fresh authenticator on your next sign-in. You will also receive an email recording who reset your 2FA and when — if you did not request the reset, contact support immediately.
Adding a device, and disabling two-factor
To put your authenticator on a second phone, tablet or password manager, use Add another device on the two-factor page. It re-shows the same setup code, so both devices give the same six digits — your existing devices and recovery codes keep working.
Two-factor is mandatory for every account, so Disable 2FA does not let you carry on without it: it turns two-factor off and you are sent straight back to enrolment. Only use it if you want to start again with a completely fresh secret.
Sessions, sudo, and time display
- Web sessions last up to 14 days from when you sign in — the clock does not reset as you use the app — and they also end after 7 days without activity, whichever comes first. Sessions in the installed mobile app last 90 days.
- Sensitive actions (changing your password, changing your email, disabling 2FA) require a fresh sign-in within the last 10 minutes. You may be asked to re-authenticate.
- All timestamps in the app are shown in UK local time and follow British Summer Time automatically.
- If you suspect a session is compromised, change your password from Settings → Security. Saving a new password ends every other signed-in session immediately — you stay signed in only on the device you changed it from.