> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vegalake.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Account and organization security

> Manage passwords, invitations, two-factor enrollment, recovery, and organization policy.

# Account and organization security

Account security combines user-owned credentials with organization policy. Follow the dashboard flow whenever possible so step-up checks and recovery choices remain attached to the current session.

## Password lifecycle

Users can request a password reset, complete the reset with the issued recovery data, and change a password from an authenticated profile. Treat reset links and codes as credentials. Do not paste them into support tickets, logs, examples, or documentation.

## Invitations

An organization invitation is a deliberate membership decision. Recipients can accept or reject it; administrators can list, resend, or cancel invitations that remain actionable. A completed or rejected decision should not be treated as a reusable invitation.

## Organization two-factor policy

Organization administrators can require two-factor authentication. Users can inspect their status and complete enrollment with the supported authenticator flow. Backup codes are a recovery method, not a second copy of a password.

Supported security workflows include:

* Begin and complete two-factor enrollment
* Replace an existing factor through a bounded rotation flow
* Regenerate backup codes after an appropriate step-up check
* Use email OTP or password verification where the current flow permits it
* Disable two-factor authentication when policy and verification allow it

Store backup codes offline and never publish them. Regeneration invalidates the old recovery set.

## Safe recovery

If an action requires recent verification, complete the prompted password, authenticator, email OTP, or backup-code step. Repeated failures may be rate-limited. If organization policy prevents completion, contact an organization administrator or [VegaLake support](mailto:support@vegalake.com) without including credentials.
