Skip to content

Account Security

CRM-only users have no billing backend to fall back on, so the workspace carries its own account area. Everything you need to look after your own login lives here, and login challenges and account emails keep you in the interface you started in.

Open it from your initials at the top right of any page.

The page shows a card for each part of your account, with its current state and a link to change it.

CardWhat it covers
PasswordChange your password. You must enter your current password first.
Email addressChange the address on your login. The new address is verified before it takes effect.
AuthenticatorSet up or replace your two-factor authenticator app.
Backup codesSingle-use codes for signing in when you cannot reach your authenticator. The card warns you when you are running low.
API keyCreate or replace the key your own integrations use. See Machine access.
AI assistantsThe assistants connected to your login, with the ability to connect a new one or revoke an existing connection.

Below the cards sit three links: Request administrator assistance, the Privacy policy, and Log out.

Two-factor authentication works exactly as it does in the billing platform. A remembered browser records which kind of verification it completed, and only an authenticator satisfies authenticator-protected functions.

If a login method is unavailable to you, the sign-in pages say why rather than simply failing, so you know whether to fix your own setup or ask an administrator.

Connecting an assistant through the CRM approves it on the CRM sign-in, so a CRM-only user can connect one without needing backend access. An assistant never gains access you do not already hold, and every write capability stays switched off platform-wide until an administrator enables it.

See Machine access for what an assistant can read and do in the CRM, and AI Assistants for the full connector guidance.