Security Settings
Manage your password, enable two-factor authentication, view active sessions, and configure security preferences.
Security Settings
Keep your Workestra account secure with password management, two-factor authentication, and session monitoring.
Screenshot needed � add an annotated image showing this UI
Coming Soon: The Security & Access page is currently under development. Full functionality will be available in an upcoming release.
Password Management
Changing Your Password
- Navigate to Settings > Security
- Scroll to the Password section
- Enter your current password
- Enter your new password (minimum 8 characters)
- Confirm the new password
- Click Update Password
Use a strong, unique password. We recommend using a password manager to generate and store complex passwords.
Password Requirements
| Requirement | Specification |
|---|---|
| Minimum length | 8 characters |
| Maximum length | 128 characters |
| Complexity | Any characters allowed |
| History | Cannot reuse last 5 passwords |
Two-Factor Authentication (2FA)
Add an extra layer of security with Time-based One-Time Password (TOTP) authentication.
Enabling 2FA
- Go to Settings > Security
- Click Enable Two-Factor Authentication
- Scan the QR code with your authenticator app (Google Authenticator, Authy, 1Password, etc.)
- Enter the 6-digit code from your app
- Save your backup codes in a secure location
- Click Verify and Enable
Important: Backup codes are your only way to recover access if you lose your authenticator device. Store them securely offline.
Using 2FA
After enabling, you'll be prompted for a 6-digit code:
- Every time you sign in
- When switching devices
- After clearing browser cookies
Disabling 2FA
- Go to Settings > Security
- Click Disable Two-Factor Authentication
- Enter your current password to confirm
- 2FA is immediately disabled
Disabling 2FA reduces your account security. Only disable if absolutely necessary.
Active Sessions
Monitor and manage devices where you're currently signed in.
Viewing Active Sessions
The Active Sessions section shows:
| Information | Description |
|---|---|
| Device | Browser and operating system |
| Location | Approximate location based on IP |
| IP Address | Network address (partially masked) |
| Last Active | When the session was last used |
| Current | Indicates your current session |
Revoking Sessions
To sign out of another device:
- Find the session in the list
- Click Revoke or Sign Out
- That device is immediately logged out
If you forgot to sign out on a public computer, revoke that session immediately from here.
Revoke All Sessions
To sign out everywhere (including your current device):
- Click Revoke All Other Sessions to keep only your current session
- Or click Sign Out Everywhere to end all sessions including this one
Brute Force Protection
Workestra automatically protects against password attacks:
| Protection | Behavior |
|---|---|
| Failed attempts | 6 failed logins trigger a lockout |
| Lockout duration | 15 minutes |
| Email notification | Alert sent to your email on lockout |
| Progressive delay | Increasing delays between attempts |
Session Timeout
For security, inactive sessions are automatically ended:
- Web sessions: 7 days of inactivity
- Mobile sessions: 30 days of inactivity
- API keys: No automatic expiration
You can manually sign out anytime from the user menu (avatar → Sign out).
Security Best Practices
For Your Account
- Enable 2FA — The single best security improvement
- Use a password manager — Generate and store unique passwords
- Revoke old sessions — Regularly review active sessions
- Keep email secure — Your email is your account recovery method
For Your Workspace
- Limit Owner/Admin roles — Only trusted individuals
- Use custom roles — Grant minimum necessary permissions
- Review audit logs — Monitor for suspicious activity
- Enable SSO — For enterprise security requirements
What to Do If You Suspect Unauthorized Access
- Change your password immediately
- Revoke all active sessions
- Review audit logs for suspicious activity
- Contact your workspace admin if you see unauthorized actions
- Contact support at security@workestra.app for urgent issues
Next Steps
- Data & Privacy — GDPR export and audit logs
- Roles & Permissions — Workspace access control