← Docs

Account, SSO, and security

Logging in, MFA, single sign-on, teammates, and module permissions.

Sign in

Email + password, or Google / Microsoft SSO if your workspace allows it. SSO domains are configured by your workspace admin.

Multi-factor authentication

Each workspace has an MFA policy: off, optional, or required. When required, every user must set up TOTP on first sign-in. Configure your authenticator app from Settings → Security.

Inviting teammates

Admins invite from Settings → Team. Invitees get an email with a one-time link; the invite expires after 7 days. You can resend or revoke at any time.

Roles and module permissions

  • Admin / Editor / Viewer at the workspace level.
  • Per-user module permissions can narrow this — e.g. an editor with projects: view but specs: edit only.

Both are managed at Settings → Team.

Forgot password

Use the Forgot password link on the sign-in screen. The reset link is valid for 30 minutes. The AI agent can also trigger a reset for you on request.

Suspicious activity

The active sessions list at Settings → Security shows every device with a live session. Revoke any you don't recognise; this invalidates the JWT immediately.

Need more help? Sign in to chat with support →