- Access to your own WRKZY account and current authentication method
- A secure recovery email or approved identity-verification path
- A trusted authenticator/device when enabling MFA
- The ability to reauthenticate after password or session changes
These controls belong to each user
Open Settings → Profile & security. Every signed-in role manages their own profile, password, MFA, personal connections, and active sessions. Workspace role does not let an Admin read another person's password or MFA code.
Keep personal credentials separate from workspace administration
- 01ProfilePublic teammate identity
Display name, photo, role context, and availability help people recognize the account in shared work.
- 02PrivatePrivate sign-in controls
Password changes and recovery belong to the individual account, not the shared workspace profile.
- 03ProtectMulti-factor authentication
A second factor protects sign-in; setup codes and recovery material must never be shared.
- 04ReviewActive sessions
Review device, time, and location evidence and revoke sessions that are no longer trusted.
- 05BoundaryWorkspace membership
Owners and Administrators govern workspace access separately from a person's private credentials.
Update your profile
- In Profile, confirm display name, work email, role/job details, phone, locale, timezone, and availability.
- Upload only a supported, appropriately sized work image.
- Select Save profile.
- If changing email, complete the authentication provider's verification before assuming the new address is active.
- Check the header/profile menu for the updated identity.
Use profile timezone for personal display expectations; workspace reporting timezone is a separate business default.
Change your password
- In Password, enter the current password and the new strong, unique password.
- Confirm the new password and save.
- Sign out and test the new password in a private browser window before ending the current recovery path.
- Store it in an approved password manager; never send it to support.
Enable authenticator MFA
- In Authenticator MFA, start setup.
- Add the displayed account to a trusted authenticator.
- Enter the current six-digit code and enable MFA.
- Sign out of a test session and verify the second-factor prompt.
- Keep recovery access according to your organization's identity policy.
Disabling MFA also requires verification. Never ask another person to read an authenticator code to you.
Review sessions
Open Active sessions or Settings → Profile & security → Active sessions. Compare device/browser, active since, last seen, and current-device marker. End a session you no longer use. If you suspect compromise, use the available action to sign out other sessions or all sessions, then change the password and review MFA.
| Observation | Action | Follow-up |
|---|---|---|
| Recognized old device | Sign out that session | Confirm it shows ended |
| Unknown active session | Sign out other/all sessions immediately | Change password, verify MFA, notify owner/security contact |
| Repeated auth errors | Confirm they are yours before retrying | Owner reviews Security audit if risk remains |
| Lost authenticator | Use the approved account-recovery path | Do not create a second account to bypass MFA |
Personal versus workspace security
- 01AccountOrganization
The customer account and ownership boundary.
- 02ScopeWorkspace
The operating area where customer work and configuration live.
- 03GovernOwner
Controls the organization, subscription, and highest-risk access.
- 04ConfigureAdministrator
Configures members, channels, defaults, and operating controls.
- 05OperateMember
Works customer queues, records outcomes, and escalates exceptions.
Safe recovery
If profile save fails, validate required name/email and image constraints. If the current password is rejected, stop repeated guessing and use the authorized recovery flow. If MFA setup fails, verify device time and use a fresh code. Preserve safe error text, time, browser, and whether the current session remains available—never password, QR secret, or one-time code.
- Profile identity and availability are accurate
- Password is unique and tested safely
- Authenticator MFA completed and challenged
- Active sessions reviewed
- Unknown access ended and escalated
- No credentials or codes copied into evidence