Back to Help

Settings & billing

Security and MFA

Protect agency sign-in with passwords and multi-factor authentication (authenticator app). Client portal MFA is separate.

Where

Settings → Security.

Password

Change your password on the Security page when you need to. Use password reset from the login screen if you are locked out.

Your authenticator (agency)

Under Multi-factor authentication:

  1. Choose Set up authenticator (or Your authenticator when already started).
  2. Scan the QR code with an authenticator app (Google Authenticator, 1Password, Authy, and so on).
  3. Enter the code to confirm.
  4. Store recovery codes somewhere safe offline, not in Slack, email threads, or public Help.

When MFA is required (or after you enroll), sign-in asks for an Authenticator code on the verify step.

Require MFA for workspace members

Owners / admins can turn on Require MFA for workspace members.

  • Off (default): people can enroll optionally.
  • On: agency members must finish authenticator setup after sign-in before they keep using the app.

Tell the team before you flip this on.

Portal MFA (clients): different toggle

Client MFA is not the Security page toggle.

On the CRM company → portal General section, turn on Require MFA for portal users when clients must use an authenticator too. Clients then see Set up authenticator / Authenticator code on the portal side (/portal/mfa/...).

Agency MFA and portal MFA do not share enrollments. Someone who is both team member and portal user (avoid that email collision) would have two separate stories. See Client portal.

Lost phone / locked out

  1. Try recovery codes if you saved them.
  2. Otherwise an owner must help reset MFA for that member (or temporarily relax required MFA only if your process allows, prefer a proper reset).
  3. Re-enroll on a new device.

Do not paste recovery codes into tickets or chat if you can avoid it.

Things that trip people up

  • Turning on required MFA without warning the team.
  • Confusing Require MFA for workspace members with Require MFA for portal users.
  • Using a team email as a portal login and then mixing MFA prompts.
  • Losing the only device with no recovery codes.

Related

Still stuck? Contact support