Security and audit logs
Security and audit logs
Two-factor authentication
Two-factor authentication (2FA) adds a one-time code from an authenticator app on top of your password.
Turning it on
1. Open Profile Settings and find the two-factor authentication section.
2. Click to enable two-factor authentication.
3. Scan the QR code with an app: Google Authenticator, Authy or any TOTP-compatible one. If you cannot scan it, enter
the secret key manually.
4. Enter the six-digit code from the app and confirm.
Backup codes
Once 2FA is on, the platform shows your backup codes. Each works once and exists for the case where you lose access to
your authenticator.
Save them immediately — they are never shown again. Later you can only regenerate them, which invalidates the old ones.
Turning it off
Disabling 2FA requires your password and a verification code.
Account security settings
Settings → Security holds sign-in options that apply to the whole account.
Audit logs
Settings → Audit Logs keeps a history of what happened in the account: who signed in and when, who created or changed an
inbox, automation rule, macro, team or webhook, and who invited or modified a user.
Each entry shows the user, the action and the IP address.
The log is what you reach for when you need to know who changed a setting, or to investigate an access incident. It is
available on paid plans.
Recommendations
- Turn 2FA on at least for administrators.
- Remove agents as soon as they leave — it is both a security measure and a saving on your plan.
- Do not share one account between people: audit entries become impossible to attribute.
- Treat API access tokens like passwords.