Your account: name, password, sessions
Account settings (sidebar → Account, or your avatar menu) is your personal corner of the workspace — every role has it.
Your details
Your email, role, workspace, and join date are shown read-only. The display name — how you appear across the app — is yours to change any time.
Changing your password
Expand Change password, enter your current password and a new one (at least 12 characters), and save. New passwords are also checked against public data-breach lists, so a password known to have leaked in a breach elsewhere is rejected. Pick a fresh one you don’t use on other sites. Two things happen for your security:
- You’re signed out everywhere else. Every other device and browser session ends; only fresh sign-ins with the new password work. (Your current session continues for up to an hour before it re-checks.)
- A confirmation email goes to you, with the time of the change and a “if this wasn’t you, contact support immediately” line.
Forgot your password? Use “Forgot password?” on the sign-in page — the reset link it emails is valid for 1 hour, and completing a reset also signs you out everywhere.
Email verification
Until you verify your email you’ll see a gentle banner with a Resend button. Verification is a reminder, not a lock — nothing is blocked while unverified — but do it: it protects account recovery. The link in the verification email is valid for 24 hours; resend any time.
Sessions and signing out
You stay signed in on a device for up to 7 days of inactivity — active use extends it quietly. Sign Out (avatar menu) ends the session on this device only; the sign-out- everywhere effect comes from changing or resetting your password.
Two-step verification
You can set up an authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, or any other) from Account → Two-step verification.
What happens once it is on: signing in asks for your password, and then for a 6-digit code from your app. You can use one of your recovery codes instead of the app, and each recovery code works once.
Keep your recovery codes somewhere safe. They are shown to you exactly once, when you switch two-step verification on, and we cannot show them again because we only store a scrambled version. If you lose your phone and you do not have them, you will need to contact us to get back in.
Setting it up:
- Choose Set up two-step verification and scan the QR code with your app. Can’t scan? Type the key shown underneath instead.
- Enter the 6-digit code your app shows. Nothing is switched on until that code checks out — so if you scan the code and then lose the phone, you haven’t locked yourself out of anything.
- Save the recovery codes we show you. Each works once, and this is the only time we can show them. Lost them? Come back and generate a new set, which cancels the old ones.
Turning it off asks for your password, not a code. That’s deliberate: if losing your phone also meant losing the only way to switch it off, you’d be stuck.
If codes keep getting rejected
After several wrong codes in a row we pause sign-in on your account for 15 minutes, and we email you when that happens. If it happens a second time within the hour, the pause is 60 minutes. The email tells you which one you’re in. Wait it out and try again, or use a recovery code.
Read that email if you get one and it wasn’t you. By the time we ask for a code, your password has already been accepted, so someone entering wrong codes is someone who has your password. The code is the only thing stopping them. Change your password straight away.
We also email you whenever a recovery code is used, with how many you have left. If that wasn’t you, change your password and then switch two-step verification off and on again, which replaces every remaining code.
There’s no single sign-on in the current version.
For admins
Admins see two extra cards here: Billing (details) and the Danger zone for closing the account.