The first way into a workspace is a user account. This article brings together what an administrator has to check on the accounts of their organisation: the second factor, passwords, open sessions, and what to do when a colleague leaves.
The second factor: 2FA and SSO
Two-factor authentication adds a one-time code on top of the password. It is the measure that protects best against a password that has been guessed, reused elsewhere, or recovered from a data breach at another service.
2FA and SSO are available from the Business plan onwards.
The point often missed. Enabling 2FA on your own account only protects your account. A single member of the organisation without a second factor is enough to open the door to your shared workspaces. 2FA has to be checked account by account.
Passwords
A TimeTonic password protects access to all your workspaces, and it is also required in order to create an API key. Its strength therefore governs both.
Length before complexity
12 characters minimum, 16 preferably. A long phrase resists better than a short word loaded with symbols, and is easier to remember.
Four families of characters
Uppercase letters, lowercase letters, digits and special characters.
Nothing that can be guessed
Not your name, not your email address, not your company name, and nothing derived from any of the three. Those are the first combinations to be tried.
Unique to TimeTonic
A password reused elsewhere exposes you to a data breach at the other service. A password manager saves you from having to remember them.
Change your password immediately at the slightest doubt, and regularly outside of any incident.
Have you lost your password? The reset procedure is described in
Lost password.
Open sessions
A TimeTonic account can have several active sessions at the same time: browser, mobile app, and each API key in use. From your profile settings, the Log out your other sessions option closes them all at once.
This action also cuts off your integrations. API keys are among the sessions that are closed: your automation scenarios, your dashboards and your synchronisations stop until the keys have been regenerated. Keep it for cases of confirmed compromise; to cut off a single access, delete the key concerned.
Go further
Revoke an access
Sessions, API keys, share links, invitations: what to cut off, and how.
See the article →
When a colleague leaves
An account that is no longer used remains an exploitable account. The day a person leaves the organisation, or a partner assignment comes to an end, there are four points to deal with.
1
Remove the person from the workspaces
Workspace by workspace. This is what removes their access to the data, independently of their account.
2
Cancel pending invitations
An invitation that has not been accepted remains an open access. Check them at the same time.
3
List the API keys created from their account
A key inherits the scope of the account that created it. If integrations are running with a key generated by that person, they will have to be recreated from another account, ideally a dedicated API account that does not depend on anyone.
4
Deal with the secrets they knew
Passwords of encrypted fields, access to third-party tools, share links they had circulated: everything they knew is to be considered compromised, and must be renewed or cut off.
Go further
Set member rights
The roles available and what each one allows.
Read more →
Go further
Manage your invitations
Invite, track and cancel access to a workspace.
Read more →
Go further
Edit my profile and my options
Where to find sessions, API keys and your preferences.
Read more →