Security Settings
Password and two-factor authentication
At a Glance
- Change your password via Settings > Security (reset link sent by email)
- Enable two-factor authentication for additional account protection
- Each team member manages their own security settings
Security Settings
Protect your WorkSnap Pro account with password management and two-factor authentication.
Overview
Security settings help protect your account and your customers' data. Every team member manages their own security settings.
To access: Go to Settings > Security
Password Management
Changing Your Password
To change your password:
- Go to Settings > Security
- Click Reset Password or Change Password
- You'll receive an email with a password reset link
- Click the link in the email
- Enter your new password
- Confirm the new password
- Click Save or Update Password
Note: Password resets are handled via email for security. You won't enter your old password in the app.
Password Requirements
Strong passwords help protect your account:
- Minimum length: 8 characters (12+ recommended)
- Mix characters: Use uppercase, lowercase, numbers, and symbols
- Avoid common passwords: Don't use "password123" or similar
- Unique password: Don't reuse passwords from other sites
Forgot Your Password?
If you can't log in:
- Go to the login page
- Click Forgot Password?
- Enter your email address
- Click Send Reset Link
- Check your email (and spam folder)
- Click the link and create a new password
Reset links expire after a limited time for security.
Two-Factor Authentication (2FA)
Two-factor authentication adds an extra layer of security by requiring a code from your phone in addition to your password.
How 2FA Works
- You enter your email and password
- WorkSnap asks for a verification code
- You open your authenticator app
- Enter the 6-digit code shown
- You're logged in
Even if someone knows your password, they can't access your account without your phone.
Setting Up 2FA
What you'll need:
- An authenticator app on your phone (see recommendations below)
- Access to your WorkSnap account
Steps:
- Go to Settings > Security
- Find Two-Factor Authentication section
- Click Enable 2FA or Set Up
- Open your authenticator app on your phone
- Scan the QR code shown on screen
- Enter the 6-digit code from your app
- Click Verify or Confirm
- Save your backup codes (important!)
Recommended Authenticator Apps
| App | Platform | Notes |
|---|---|---|
| Google Authenticator | iOS, Android | Simple, widely used |
| Microsoft Authenticator | iOS, Android | Includes backup features |
| Authy | iOS, Android, Desktop | Cloud backup, multi-device |
| 1Password | iOS, Android, Desktop | Built into password manager |
All these apps work with WorkSnap Pro's 2FA.
Backup Codes
When you enable 2FA, you'll receive backup codes. These are one-time codes you can use if you lose access to your authenticator app.
Important:
- Save backup codes somewhere safe
- Each code can only be used once
- Store them separately from your password
- Consider printing them and keeping in a secure location
Using 2FA to Log In
After 2FA is enabled:
- Enter your email and password as usual
- When prompted, open your authenticator app
- Find WorkSnap Pro in your app
- Enter the current 6-digit code
- Click Verify
Tip: Codes change every 30 seconds. If a code doesn't work, wait for the next one.
Lost Access to Authenticator
If you can't access your authenticator app:
Option 1: Use a backup code
- On the 2FA prompt, look for Use backup code link
- Enter one of your saved backup codes
- You'll be logged in
Option 2: Contact an Owner
- Contact an Owner in your organization
- They may be able to assist with account recovery
- You may need to verify your identity
Option 3: Contact Support
- If you're the only Owner, contact support
- Provide proof of identity and account ownership
- Support can assist with account recovery
Disabling 2FA
To turn off two-factor authentication:
- Go to Settings > Security
- Find Two-Factor Authentication
- Click Disable 2FA
- Enter your password or verification code
- Confirm the action
Warning: Disabling 2FA makes your account less secure. Only disable if necessary.
Session Security
Active Sessions
WorkSnap may show your active login sessions:
- Device type: Phone, tablet, or computer
- Browser: Chrome, Safari, Firefox, etc.
- Location: Approximate location based on IP
- Last active: When you last used that session
Signing Out Other Sessions
If you see unfamiliar sessions or want to secure your account:
- Go to Settings > Security
- Find Active Sessions or Logged-in Devices
- Click Sign Out next to specific sessions
- Or click Sign Out All Other Sessions
This forces re-login on all other devices.
When to Sign Out Sessions
Consider signing out sessions when:
- You see a device you don't recognize
- You've lost a phone or laptop
- You used a shared or public computer
- You're concerned about account security
Account Security Best Practices
For Everyone
- Use a strong, unique password - Different from other accounts
- Enable two-factor authentication - Best protection available
- Don't share your login - Each person should have their own account
- Log out on shared devices - Never stay signed in on public computers
- Keep your email secure - Password resets go there
For Business Owners
- Require 2FA for team - Consider making it mandatory
- Review team access regularly - Remove people who leave
- Use appropriate roles - Don't give admin access unnecessarily
- Monitor for unusual activity - Know who's accessing what
Recognizing Security Threats
Phishing emails - Fake emails pretending to be from WorkSnap
- Check the sender's email address carefully
- Don't click links in suspicious emails
- Go directly to the app instead of clicking email links
- WorkSnap will never ask for your password via email
Suspicious login attempts
- Unexpected 2FA prompts when you're not logging in
- Password reset emails you didn't request
- Notifications about logins from unfamiliar locations
What to do:
- Don't approve unexpected 2FA requests
- Change your password immediately
- Review and sign out unfamiliar sessions
- Enable 2FA if not already on
- Contact support if you believe your account was compromised
Security Settings by Role
All team members can manage their own security settings:
| Setting | Owner | Admin | Member |
|---|---|---|---|
| Change own password | Yes | Yes | Yes |
| Enable/disable own 2FA | Yes | Yes | Yes |
| View own sessions | Yes | Yes | Yes |
| Sign out own sessions | Yes | Yes | Yes |
Note: You manage your own account security. Owners and Admins cannot change other users' passwords or 2FA settings.
Common Security Questions
Is my data encrypted?
Yes. WorkSnap Pro uses encryption:
- In transit: All data encrypted via HTTPS
- At rest: Database encryption for stored data
- Payments: Handled by PCI-compliant processors (Stripe, PayPal, Square)
Can I require 2FA for my team?
Currently, 2FA is optional for each user. Encourage your team to enable it by explaining the security benefits.
What happens if I lose my phone?
- Use a backup code to log in
- Disable 2FA on the compromised account
- Set up 2FA again with your new phone
- Contact support if you're locked out
How do I know if my account was hacked?
Warning signs:
- Documents created that you didn't make
- Settings changed unexpectedly
- Password changed without your knowledge
- Emails sent that you didn't write
- Unfamiliar login sessions
If you suspect compromise, immediately change your password and enable 2FA.
Previous: Organization Settings Next: Subscription & Billing
What Happens Next
- 1Password reset email arrives within minutes
- 2Click the link to set your new password
- 32FA setup requires an authenticator app
Common Questions
- Why do I need to reset via email instead of entering my old password?
- Email-based resets are more secure. If someone has your current password, they still can't change it without email access.
- What authenticator apps work with WorkSnap?
- Any TOTP-compatible app works: Google Authenticator, Authy, Microsoft Authenticator, 1Password, etc.
- I lost access to my authenticator — how do I log in?
- Contact support with your account email. We'll verify your identity and help you regain access.
Was this article helpful?