Account Security
Harden your own sign-in: authenticator-app two-factor codes backed by recovery codes, a review of your active browser sessions, and linked Google, Microsoft, or Slack sign-in — all from your profile.
Updated
Account Security lets you harden your own ApproveThis sign-in from the Profile page, where the Security, Connected Accounts, Sessions, and Danger Zone tabs are grouped as separate tabs. This guide covers the first half of turning on two-factor authentication: reaching the setup screen where the QR code and manual setup key appear. Two-factor here is authenticator-app TOTP only — there is no SMS, no email codes, and no passkeys or hardware keys. You'll need an account with a password set; users created purely through OAuth sign-in don't see the Security tab at all.
Who this is for: admin.
On the Security tab, click 'Enable' under Two-Factor Authentication and confirm your password — the QR code and setup key appear, ready to scan with your authenticator app
Turning on two-factor adds a second sign-in step backed by an authenticator app, and the password re-confirmation here protects the setting from anyone sitting at an unlocked browser. Note that 2FA is per-user opt-in — there is no admin setting that requires it across a workspace — and enabling it turns off auto-login on emailed approval and view links for you, so those emails send you to the normal login page instead.
-
Sign in with your own admin account.
-
Click Security to open the security settings for your profile.

Step 2 -
Under Two-Factor Authentication, click Enable.

Step 3 -
Enter your account password in Password — the example uses
docs-password.
Step 4 -
Click Confirm to verify the password and continue to two-factor setup.

Step 5
The two-factor setup screen appears with the prompt Scan with your authenticator app above the QR code and manual setup key.