Account security and MFA
Every person should use their own account. Shared accounts weaken attribution, separation of duties and incident response.
Enrol MFA
Section titled “Enrol MFA”Use the MFA control in the sidebar to begin enrolment. Scan the displayed authenticator setup with an approved application, enter the current code and store any recovery material according to your organisation’s security process. Do not send setup secrets or recovery codes through chat or email.
MFA enrolment protects future sign-ins and supports step-up verification for sensitive actions. Runtime Policy Approvers must enrol MFA before they can approve or reject policies. MFA does not hide their assigned pending policies; it prevents the decision until strong verification is complete.
Step-up actions
Section titled “Step-up actions”Actions such as security changes, write-token creation, trial activation and sensitive approvals may require the current password and/or authenticator code. Reauthentication is deliberately short-lived and applies to the exact operation being performed.
Account lifecycle
Section titled “Account lifecycle”- Invite users to the correct tenant and role.
- Verify identity through the approved organisational process.
- Require MFA for privileged and approval roles.
- Review sessions, tokens and role assignments after job changes.
- Suspend access promptly when no longer required.
- Use administrator-supported recovery rather than creating a replacement shared account.
If compromise is suspected
Section titled “If compromise is suspected”Suspend the account, revoke sessions and API tokens, reset credentials, review the Audit Trail and investigate affected records. Restore access only after identity and device security are confirmed.