Built in, not a paid add-on
Ready for the security review
Access is a permission check all the way down, sessions can be pulled the moment someone leaves, sensitive actions ask again before they run, and consequential changes are written to a log you can export.
- Meet
- Capture
- Act
Sign-in
Two-factor that a company can actually mandate
A member can switch on email two-factor for themselves, and an organisation can require it for everyone, a floor no individual can lower. A browser that has already passed can be trusted for thirty days, and that trust is dropped the moment a password changes or is reset.
- Organisation-wide requirement, not just a personal preference
- Trusted devices for thirty days, cleared on password change or reset
- Codes stored only as hashes, with a ten-minute life and a hard attempt cap
Two-factor authentication is on
Email code · required by your organisation
Active sessions
- This device
Desktop app · Windows
Lisbon · now
- Revoke
Android app
Lisbon · 2 h ago
- Revoke
Chrome · macOS
Porto · yesterday
Sessions and boundaries
Access you can take back, from anywhere you choose
Sessions are tracked rather than implied by a token, so disabling an account or forcing a logout takes effect on the next request. Every login attempt is recorded with its source, and IP allow and deny lists put a hard boundary in front of the whole platform.
- Revoke one session or every session for an account
- Step-up reauthentication before sensitive changes
- Login attempts recorded; IP allow and deny lists enforced
Evidence
An audit trail, exportable
Consequential actions are written with their actor, target and time, queryable per organisation. When someone asks who changed a permission six weeks ago, the answer is an export rather than a fortnight of log searching.
- Per-organisation activity, filterable by actor and action
- Export for whoever is asking
- Written by the same service the product uses
Related
Works with the rest of the office
Can we require two-factor for everyone in our organisation?
What happens to an account when someone leaves?
Is access controlled below the level of the whole app?
Do you keep our data if we self-host?
Ask us the hard questions
Send the security questionnaire. We would rather answer it now than halfway through a rollout.