Organization security
Require two-factor authentication for everyone in your workspace.
Organization settings live at Settings → Team members → Options, and are visible to admins. They apply to everyone in the workspace.
Roles
| Role | What it means |
|---|---|
| Admin | Manages the team, roles, invitations, and organization settings |
| Member | Works in the product: roles, candidates, outreach, and scheduling |
Admins are unaffected by the requirement below; it describes what everyone in the organization must have.
Require two-factor authentication
Turning this on means every member of the organization must hold a second factor: a passkey or an authenticator app.
Enforcement is immediate and there is no grace period. A member without a factor is held at an enrollment screen on their next sign-in, which names your organization as the one asking, and explains why. They can enroll on the spot.
This can interrupt colleagues mid-work, so the confirmation tells you how many members are currently unprotected before you turn it on.
The requirement is enforced in the backend, not just in the interface. A member without a factor is refused organization data everywhere: the dashboard, the API, and agent surfaces alike.
You must have a second factor on your own account before you can require it of everyone else. This is the same rule GitHub applies, and for the same reason: an admin who set the policy and skipped it would meet their own gate on the next sign-in.
Turning the requirement off does not remove anybody's factors; it only stops requiring them.
Audit log
Security events are recorded in the organization's audit log: enabling and disabling two-factor, adding and removing passkeys, regenerating recovery codes, and changes to the requirement above, along with who made the change and when.
Next steps
- For your own account: Account security
- API credentials and scopes: Authentication
Last updated on