Security, sessions, and notifications
Protect your account (password, email, MFA), review where you are signed in, and choose which notifications you get and how: three personal Settings pages.
Outcome
You can change password/email/MFA on Security & Authentication, revoke sessions on Session Management, and set which notification types and channels you want on Notifications from the matching Settings card.
Who it's for
Any signed-in user with the matching Settings permissions
Prerequisites
- Access to Security & Authentication, Session Management, and/or Notifications cards on the hub
Steps
- From Settings → Organization & Access, open Security & Authentication (`/settings/security`). This page is personal: you manage your own account, not teammates’.
- On Security: change password (current + new + confirm → Change Password). Change email when offered (new email + current password; verification may go to the new address). Enroll MFA (two-step / TOTP): Enroll → scan QR or enter secret in an authenticator app → Verify. To disable MFA, follow Disable/remove; you may need one more authenticator code if this device remembered you. Session settings on this page (Remember me, session timeout) save to your preferences: balance shorter timeouts (safer) with convenience. Remember me only on devices you trust.
- Open Session Management (`/settings/sessions`). Review Active Sessions (device, browser, location/IP, last active). The current session is badged. Revoke a lost or unknown device. Sign out all other sessions if you suspect a stolen password: your current session stays. Revoking the current session signs you out here.
- From Settings → Operations & Data, open Notifications (`/settings/notifications`). Choose which notifications you get and how: turn types on or off per category (Shift, Invoice, Resource, Client, Team, System as shown), and toggle channels (email, and browser push notifications when your browser allows it). Browser push depends on permission and whether your browser supports it: do not assume it works everywhere. Changes auto-save; preferences are yours only.
- Working pattern: Security for credentials and MFA; Sessions for active devices; Notifications for which messages you want. Next in this cluster: data, import, and billing (cards may be hidden in simple mode).
