Home Team and Access Security and audit logs

Security and audit logs

Last updated on August 23, 2026

Security and audit logs

Two-factor authentication

Two-factor authentication (2FA) adds a one-time code from an authenticator app on top of your password.

Turning it on

  1. Open Profile Settings and find the two-factor authentication section.
  2. Click to enable two-factor authentication.
  3. Scan the QR code with an app: Google Authenticator, Authy or any TOTP-compatible one. If you cannot scan it, enter the secret key manually.
  4. Enter the six-digit code from the app and confirm.

Backup codes

Once 2FA is on, the platform shows your backup codes. Each works once and exists for the case where you lose access to your authenticator.

Save them immediately — they are never shown again. Later you can only regenerate them, which invalidates the old ones.

Turning it off

Disabling 2FA requires your password and a verification code.

Account security settings

Settings → Security holds sign-in options that apply to the whole account.

Audit logs

Settings → Audit Logs keeps a history of what happened in the account: who signed in and when, who created or changed an inbox, automation rule, macro, team or webhook, and who invited or modified a user.

Each entry shows the user, the action and the IP address.

The log is what you reach for when you need to know who changed a setting, or to investigate an access incident. It is available on paid plans.

Recommendations

  • Turn 2FA on at least for administrators.
  • Remove agents as soon as they leave — it is both a security measure and a saving on your plan.
  • Do not share one account between people: audit entries become impossible to attribute.
  • Treat API access tokens like passwords.