Account and organization security
Account security combines user-owned credentials with organization policy. Follow the dashboard flow whenever possible so step-up checks and recovery choices remain attached to the current session.Password lifecycle
Users can request a password reset, complete the reset with the issued recovery data, and change a password from an authenticated profile. Treat reset links and codes as credentials. Do not paste them into support tickets, logs, examples, or documentation.Invitations
An organization invitation is a deliberate membership decision. Recipients can accept or reject it; administrators can list, resend, or cancel invitations that remain actionable. A completed or rejected decision should not be treated as a reusable invitation.Organization two-factor policy
Organization administrators can require two-factor authentication. Users can inspect their status and complete enrollment with the supported authenticator flow. Backup codes are a recovery method, not a second copy of a password. Supported security workflows include:- Begin and complete two-factor enrollment
- Replace an existing factor through a bounded rotation flow
- Regenerate backup codes after an appropriate step-up check
- Use email OTP or password verification where the current flow permits it
- Disable two-factor authentication when policy and verification allow it