Team security
Enforce two-factor authentication, passkeys and single sign-on for your team
Your inbox holds customer conversations, contact data and connected channels — a compromised account exposes all of it. Team security lets owners and admins raise the bar for everyone on the team: require two-factor authentication, offer passkeys as a second factor, and require members to sign in through Google or Microsoft instead of a password.
All of it lives in Team Settings → Security (owners and admins only). Every control is off by default, so nothing changes until you enable it.
Enforce two-factor authentication
Turn on Enforce two-factor authentication and every member of the team must protect their account with a second factor before they can keep using Chatlane.
What members experience:
- On their next page load (not just their next login), members without 2FA are taken to Settings → Security and can't go anywhere else in Chatlane until they finish setup.
- Setup takes a minute: scan a QR code with any authenticator app (Google Authenticator, 1Password, Authy…) and confirm with a 6-digit code — or, if you've enabled passkeys for the team, register a passkey instead.
- From then on, signing in asks for the second factor after their password. This applies to the Google/Microsoft/Apple buttons on the login page too, so social login can't be used to skip the check.
- After confirming an authenticator app, members get recovery codes — one-time codes that work at the sign-in challenge if their device is lost. Tell your team to store these somewhere safe (a password manager) when they enrol.
A few things to know:
- Enforcement is account-wide. 2FA protects the member's whole Chatlane account, so if any team they belong to enforces it, they'll be asked to set it up — they can't dodge it by switching to another team.
- Admins and owners are enforced too, including whoever flipped the switch.
- Mobile app sessions are signed out when you enable enforcement, and members who haven't enrolled can't sign in to the app until they've set up 2FA on the web.
- If the team also requires SSO, members signing in through Google or Microsoft aren't asked for a second code — multi-factor is handled by the identity provider in that case (enable 2FA in your Google Workspace or Microsoft 365 admin console).
Passkeys
Passkeys let members use Face ID, Touch ID, or a hardware security key as their second factor instead of typing codes. Turn on Allow passkeys as a 2FA method and:
- Members can register passkeys on Settings → Security (each passkey gets a name — "MacBook", "YubiKey" — and can be removed later).
- At the sign-in challenge, members with a passkey see a Use a passkey button alongside the code input.
- A registered passkey counts as being enrolled in 2FA, so a member can satisfy enforced 2FA with a passkey alone — no authenticator app needed.
Passkeys are a second factor in Chatlane, not a replacement for signing in — members still enter their password (or use SSO) first.
Single sign-on
The login page always offers Continue with Google / Microsoft / Apple — any user can sign in that way if their Chatlane email matches. The Security section controls something stronger: which providers count for this team's SSO policy, and whether SSO is required.
- Tick the providers your team uses (Google, Microsoft, or both).
- Optionally turn on Require SSO for login.
When Require SSO is on:
- Members trying to sign in with an email and password are stopped and pointed at the SSO buttons instead.
- Only the providers you ticked satisfy the requirement — a sign-in through any other provider is rejected with a message naming the allowed ones.
- Members who are currently signed in with a password are asked to re-authenticate via SSO on their next action. They pick a provider, sign in, and land right back where they were.
- Password reset and password change are disabled for members' accounts everywhere — an account on an SSO-required team can no longer hold a usable password path.
- Existing mobile app sessions are signed out when you save; the app's Google/Microsoft sign-in buttons work as normal.
Before you enable Require SSO, make sure every member can sign in to the chosen provider with the same email address they use for Chatlane. A member whose work Google account is [email protected] but whose Chatlane account is [email protected] will be locked out until one of them changes.
Switching teams
Security follows the team you're working in. If you switch from a relaxed team into one that requires SSO, the re-authentication screen appears immediately — and because 2FA is account-wide, joining or belonging to any enforcing team requires enrolment no matter which team is currently open. Accepting an invitation into a protected team works the same way: you join first, then the security requirements apply on your next step.
Sessions
Settings → Security also shows every browser and device currently signed in to your account, with a Log out other sessions button. Changing your password signs out your other sessions automatically.
If a member is locked out
- Lost authenticator device → sign in with one of the recovery codes issued at setup, then disable and re-enrol 2FA from Settings → Security.
- Lost recovery codes too, but still signed in somewhere → disable and re-enrol 2FA from that session.
- Locked out of an SSO-required team because the provider account is gone → an admin can untick Require SSO temporarily so the member can sign in with a password and fix their provider account.
Notes for admins
- Enabling Enforce 2FA or Require SSO revokes members' existing mobile API tokens so old sessions can't bypass the new policy. Members simply sign in to the app again.
- API tokens created from Settings → API Tokens for integrations keep working — creating them requires a session that already satisfied your security policy.
- Security settings are per-team; members of several teams get the strictest combination of the teams they belong to.
Role requirements for managing these settings are covered in Roles and permissions. To limit which inboxes members can access, see Inbox permissions.