Skip to main content

Account and organization security

Account security combines user-owned credentials with organization policy. Follow the dashboard flow whenever possible so step-up checks and recovery choices remain attached to the current session.

Password lifecycle

Users can request a password reset, complete the reset with the issued recovery data, and change a password from an authenticated profile. Treat reset links and codes as credentials. Do not paste them into support tickets, logs, examples, or documentation.

Invitations

An organization invitation is a deliberate membership decision. Recipients can accept or reject it; administrators can list, resend, or cancel invitations that remain actionable. A completed or rejected decision should not be treated as a reusable invitation.

Organization two-factor policy

Organization administrators can require two-factor authentication. Users can inspect their status and complete enrollment with the supported authenticator flow. Backup codes are a recovery method, not a second copy of a password. Supported security workflows include:
  • Begin and complete two-factor enrollment
  • Replace an existing factor through a bounded rotation flow
  • Regenerate backup codes after an appropriate step-up check
  • Use email OTP or password verification where the current flow permits it
  • Disable two-factor authentication when policy and verification allow it
Store backup codes offline and never publish them. Regeneration invalidates the old recovery set.

Safe recovery

If an action requires recent verification, complete the prompted password, authenticator, email OTP, or backup-code step. Repeated failures may be rate-limited. If organization policy prevents completion, contact an organization administrator or VegaLake support without including credentials.