Skip to content

Your account and security

These controls live under AccountSecurity in Settings and apply to you alone, whatever your role. Your colleagues each have their own.

Two-factor authentication is worth setting up on your first day, because it is not only about signing in. Granting or revoking a role, deactivating a member and exporting the audit log all ask for a code, so an administrator without it is stopped at exactly the moments that matter most.

Sqoura uses a code from an authenticator app on your phone — Google Authenticator, Authy or any other TOTP app.

  1. Press Enable 2FA.
  2. Scan the QR code with your authenticator app. If your app cannot scan, use the Manual entry key shown beside it.
  3. Type the six-digit code into Verification code and press Verify & Enable.
  4. Your backup codes appear, with the warning that they can only be shown once. Save them somewhere you can reach without your phone, then press I’ve saved my codes.

The card then reads 2FA is enabled.

To turn it off, press Disable 2FA and enter either a current code from your app or one of your backup codes. You cannot disable it without one.

A hardware key — a YubiKey, a Google Titan or similar — can be registered as well. Type a name into Key name, press Register Key and touch the key when your browser asks.

Each registered key shows when it was last used and when it expires, and expired keys are tagged as such. The bin icon removes one.

The Change Password card sits on AccountMy Profile. Enter your current password, then the new one twice; a strength meter and a Passwords match line sit under the fields. Press Update Password.

The rule is at least 12 characters, including an upper-case letter, a lower-case letter and a digit. That is the whole rule. There is no expiry, no reuse check and no organisation-level override — see the warning at the foot of this page.

A wrong current password comes back as “Current password is incorrect.”

The Active Sessions card lists every device currently signed in to your account: the browser and operating system, the address it connected from, and when the sign-in happened.

The one you are reading this on is tagged This device and has no button. Every other row has Revoke, which signs that device out immediately.

Check this if you have ever signed in on a shared or borrowed computer. Revoking is instant and costs you nothing — that device simply has to sign in again.

Below that, a log of security events on your account: sign-ins, sign-outs, sign-ins that used your second factor, password changes, two-factor changes, profile updates and revoked sessions. Each row carries the time, the address and the device. Load more pages through it 30 at a time.

This is yours alone. For what everyone in your organisation has been doing, see Activity and audit log.

If your Settings menu has a Security section under Organization, the Support access card at the top of it is where you control whether Sqoura staff may open a session inside your account to help you.

  • The consent setting decides what is permitted. Changing it takes effect straight away.
  • Any live support session is listed while it is running, and you can end one yourself from that list.
  • Tightening the setting also ends sessions it no longer permits, and you are told how many were ended.

Everyone involved is told about it too. A support session starting and ending both raise notices that nobody can switch off, precisely so that account access cannot be made silent — see Notifications.

The history is not summarised on the card, deliberately. As the card puts it: “The complete record of who entered your organisation and what they did — request by request, reads included — is kept in your audit trail rather than summarised here. It is append-only: neither you nor we can edit it after the fact.”