Workspace administration · how to

Manage profile, password, MFA, and sessions

Update personal identity, password, authenticator MFA, and active sessions for every signed-in role.

3 min readUpdated August 12, 2026
For
Owner, Admin, Member
Availability
Your current plan and entitlements
Product evidence
WRKZY · reviewed August 12, 2026
Editorial review
WRKZY Editorial
Before you begin
  • Access to your own WRKZY account and current authentication method
  • A secure recovery email or approved identity-verification path
  • A trusted authenticator/device when enabling MFA
  • The ability to reauthenticate after password or session changes

These controls belong to each user

Open Settings → Profile & security. Every signed-in role manages their own profile, password, MFA, personal connections, and active sessions. Workspace role does not let an Admin read another person's password or MFA code.

Keep personal credentials separate from workspace administration

  1. 01
    ProfilePublic teammate identity

    Display name, photo, role context, and availability help people recognize the account in shared work.

  2. 02
    PrivatePrivate sign-in controls

    Password changes and recovery belong to the individual account, not the shared workspace profile.

  3. 03
    ProtectMulti-factor authentication

    A second factor protects sign-in; setup codes and recovery material must never be shared.

  4. 04
    ReviewActive sessions

    Review device, time, and location evidence and revoke sessions that are no longer trusted.

  5. 05
    BoundaryWorkspace membership

    Owners and Administrators govern workspace access separately from a person's private credentials.

Teammates can see the work identity they need, while password, MFA, recovery, and active sessions remain private account controls. Owners and Administrators govern membership, not another person's credentials.

Update your profile

  1. In Profile, confirm display name, work email, role/job details, phone, locale, timezone, and availability.
  2. Upload only a supported, appropriately sized work image.
  3. Select Save profile.
  4. If changing email, complete the authentication provider's verification before assuming the new address is active.
  5. Check the header/profile menu for the updated identity.

Use profile timezone for personal display expectations; workspace reporting timezone is a separate business default.

Change your password

  1. In Password, enter the current password and the new strong, unique password.
  2. Confirm the new password and save.
  3. Sign out and test the new password in a private browser window before ending the current recovery path.
  4. Store it in an approved password manager; never send it to support.

Enable authenticator MFA

  1. In Authenticator MFA, start setup.
  2. Add the displayed account to a trusted authenticator.
  3. Enter the current six-digit code and enable MFA.
  4. Sign out of a test session and verify the second-factor prompt.
  5. Keep recovery access according to your organization's identity policy.

Disabling MFA also requires verification. Never ask another person to read an authenticator code to you.

Review sessions

Open Active sessions or Settings → Profile & security → Active sessions. Compare device/browser, active since, last seen, and current-device marker. End a session you no longer use. If you suspect compromise, use the available action to sign out other sessions or all sessions, then change the password and review MFA.

Security response
ObservationActionFollow-up
Recognized old deviceSign out that sessionConfirm it shows ended
Unknown active sessionSign out other/all sessions immediatelyChange password, verify MFA, notify owner/security contact
Repeated auth errorsConfirm they are yours before retryingOwner reviews Security audit if risk remains
Lost authenticatorUse the approved account-recovery pathDo not create a second account to bypass MFA

Personal versus workspace security

  1. 01
    AccountOrganization

    The customer account and ownership boundary.

  2. 02
    ScopeWorkspace

    The operating area where customer work and configuration live.

  3. 03
    GovernOwner

    Controls the organization, subscription, and highest-risk access.

  4. 04
    ConfigureAdministrator

    Configures members, channels, defaults, and operating controls.

  5. 05
    OperateMember

    Works customer queues, records outcomes, and escalates exceptions.

Personal credentials and sessions belong to the user; workspace Owners govern membership and owner-only authentication audit.

Safe recovery

If profile save fails, validate required name/email and image constraints. If the current password is rejected, stop repeated guessing and use the authorized recovery flow. If MFA setup fails, verify device time and use a fresh code. Preserve safe error text, time, browser, and whether the current session remains available—never password, QR secret, or one-time code.

Account security verified
  • Profile identity and availability are accurate
  • Password is unique and tested safely
  • Authenticator MFA completed and challenged
  • Active sessions reviewed
  • Unknown access ended and escalated
  • No credentials or codes copied into evidence
Was this guide useful?

Choose an answer. No message text or personal information is collected.

Still need help?

Contact WRKZY support with the workspace name and a safe, redacted example.

Contact support about this guide