Skip to main content
One switch on this tab decides whether everyone in your lab has to prove who they are with a second factor before a patient record will open. Beneath it sits the log of every time that requirement was bypassed.

What this tab controls

The card is headed Security Settings — “Manage your clinic’s security settings.” The switch is owner-only. A manager or an accountant sees it in its current position, greyed out, with no Save Changes button.
Passkeys and your own authenticator are set up on your personal account, not here — see Your account security. This tab decides the rule for everyone; that page is where each person satisfies it.

Turn it on

1

Set up your own second factor first

Do this before switching the requirement on, so you are not locked out of your own lab. See Two-factor authentication.
2

Tell your team it is coming

Everyone will be stopped at their next sign-in and asked to enrol. A scientist discovering this mid-run is avoidable — give a day’s notice and let people enrol early.
3

Switch Require Two-Factor Authentication on

Then select Save Changes. You get “Security settings updated successfully”.

What changes once you save

It applies from each person’s next sign-in, not immediately. Anyone already signed in keeps working until their session ends. At that next sign-in, a colleague with no second factor is stopped and walked through setting up an authenticator app before they can reach anything. After that, patient records and results only open from a session that has passed the second factor — a session that has not is refused, even though the password was right. A passkey counts as one factor and does not satisfy this. Signing in with a passkey is still single-factor, so someone using one will still be asked to enrol an authenticator. This surprises people; say it out loud when you announce the change. Two doors stay open, and both are recorded. From Staff and teams an owner can Reset two-factor for someone who has lost their device, or Grant emergency access for a time-boxed window with a reason. Every use of either — plus any use of a recovery code — appears on the Security alerts card here, with a severity, and stays in the audit log permanently. Acknowledging an alert records that you have seen it; it does not undo anything. Switching the requirement back off stops new people being asked to enrol. It does not remove the second factor from anyone who already has one.

Check it worked

Sign out and back in yourself: you should be asked for your second factor. Then ask a colleague who has not enrolled to sign in — they should be stopped and taken through setup before they can open a patient record. Anyone bypassing it later appears on the Security alerts card within moments.

Common issues

You are a manager or an accountant. This is owner-only. Ask the lab owner, or see Roles.
An owner can Reset two-factor from Staff and teams — it signs their sessions out and invalidates their recovery codes, and they enrol again next time. The owner needs their own two-factor on to do it.
Use Grant emergency access on their staff row. It is time-boxed, needs a reason, expires by itself and is recorded on this tab.
That is correct. A passkey is one factor. It does not satisfy a two-factor requirement.
It only renders when there is something to show, and only to people allowed to see it. No card means no bypass events.
Everything is in the audit log, kept for seven years. See Audit log.