Security

Two factor authentication and access policy

Enroll an authenticator app or email code, save backup codes, satisfy sign in challenges, and enforce workspace two factor policy safely.

agaro supports two independent second factor methods: a time based authenticator app and a six digit email code. A user can enroll either method or both.

Enroll an authenticator app

  1. Open Account Settings → Security and Privacy.
  2. Find Authenticator app and select setup.
  3. Scan the QR code with an authenticator such as 1Password, Google Authenticator, or Authy, or enter the displayed secret manually.
  4. Enter the current six digit code.
  5. Confirm your account password.
  6. Save the ten one time backup codes shown after successful enrollment.

The authenticator secret is encrypted at rest. A code that was just used cannot be replayed in the same time window.

Backup codes are stored as protected one way verification records and can be used once. Save them somewhere separate from the device that holds the authenticator.

Regenerate backup codes

Open the Authenticator app card and select Regenerate backup codes. Confirm your password. The previous backup codes are invalidated and ten new codes are shown once.

Regenerate after using several codes, after copying them to an unsafe location, or when a person who could see them no longer should.

Disable the authenticator method

Select disable and confirm your password. Disabling removes the authenticator enrollment and backup codes for that method. It does not disable an independently enrolled email code method.

If workspace policy requires two factor authentication and no other method remains, the user must enroll again to continue after enforcement.

Enroll email code

  1. Open Account Settings → Security and Privacy.
  2. Find Email code and begin setup.
  3. agaro sends a six digit code to the signed in user's email address.
  4. Enter the code and account password.
  5. Confirm enrollment.

The plaintext email code is not stored. Its hash is stored temporarily with a ten minute expiry and an attempt limit. Issuance and verification are rate limited.

Email code depends on access to the mailbox and reliable email delivery. An authenticator app is usually the stronger primary method because it avoids an email delivery hop.

Sign in with two factor authentication

After password sign in, agaro directs an enrolled or required user to the second factor challenge. If both methods are available, the authenticator is the normal first choice and the page offers email code as an alternative.

Enter a current authenticator code, a remaining backup code, or the active email code. Successful verification sets a signed marker bound to the current user and session.

Too many incorrect attempts triggers rate limiting or burns the pending email code. Request a fresh email code only after the displayed wait.

Workspace policy

Open Settings → Security and Access → Security Policy as a Super Admin or Manager. Managers can review the policy. Only a Super Admin can change it.

PolicyEffect
OptionalMembers may enroll but are not required by workspace policy
Required for employeesEmployee role members must enroll
Required for everyoneEvery workspace member, including administrators, must enroll

The page shows how many current members are enrolled in an authenticator app. Email code enrollment is a separate method and can also satisfy the supported challenge policy.

Grace period

When enabling a required policy, set a grace period from 0 to 365 days. During the grace period, users who have not enrolled can enter the app to complete setup. After the deadline, applicable unenrolled users are blocked until they enroll.

Use a realistic period, notify the team, and verify every critical administrator has a method before enforcing immediately.

Administrative recovery

Workspace user administration includes controlled enrollment state management for recovery and offboarding. Administrative reset actions are audited and role gated.

Before resetting another person's second factor, verify their identity through an approved channel. Do not accept a request based only on an email from the locked account.

Troubleshooting

Authenticator codes are rejected

Confirm the device clock is automatic, use the account entry for the correct agaro user, and wait for a fresh code. A code accepted moments ago cannot be reused.

I lost the authenticator device

Use a saved backup code or the enrolled email code method. If neither is available, follow your organization's verified administrative recovery process.

Email code did not arrive

Check spam and delivery delay, then wait before requesting another code. Repeated requests are rate limited and each new code replaces the prior pending code.

Policy enforcement locked out an administrator

Use another verified Super Admin and the supported administrative recovery path. Do not disable security controls through database changes or shared credentials.

The Security Policy page is read only

Managers may review it, but only a Super Admin can save the workspace policy.