What this tab controls
The card is headed Security Settings — “Manage your clinic’s security settings.”
The switch is owner-only. A manager or an accountant sees it in its current position, greyed out, with no Save Changes button.
Passkeys and your own authenticator are set up on your personal account, not here — see Your account security. This tab decides the rule for everyone; that page is where each person satisfies it.
Turn it on
1
Set up your own second factor first
Do this before switching the requirement on, so you are not locked out of your own lab. See Two-factor authentication.
2
Tell your team it is coming
Everyone will be stopped at their next sign-in and asked to enrol. A scientist discovering this mid-run is avoidable — give a day’s notice and let people enrol early.
3
Switch Require Two-Factor Authentication on
Then select Save Changes. You get “Security settings updated successfully”.
What changes once you save
It applies from each person’s next sign-in, not immediately. Anyone already signed in keeps working until their session ends. At that next sign-in, a colleague with no second factor is stopped and walked through setting up an authenticator app before they can reach anything. After that, patient records and results only open from a session that has passed the second factor — a session that has not is refused, even though the password was right. A passkey counts as one factor and does not satisfy this. Signing in with a passkey is still single-factor, so someone using one will still be asked to enrol an authenticator. This surprises people; say it out loud when you announce the change. Two doors stay open, and both are recorded. From Staff and teams an owner can Reset two-factor for someone who has lost their device, or Grant emergency access for a time-boxed window with a reason. Every use of either — plus any use of a recovery code — appears on the Security alerts card here, with a severity, and stays in the audit log permanently. Acknowledging an alert records that you have seen it; it does not undo anything. Switching the requirement back off stops new people being asked to enrol. It does not remove the second factor from anyone who already has one.Check it worked
Sign out and back in yourself: you should be asked for your second factor. Then ask a colleague who has not enrolled to sign in — they should be stopped and taken through setup before they can open a patient record. Anyone bypassing it later appears on the Security alerts card within moments.Common issues
Someone has lost their phone and cannot sign in
Someone has lost their phone and cannot sign in
An owner can Reset two-factor from Staff and teams — it signs their sessions out and invalidates their recovery codes, and they enrol again next time. The owner needs their own two-factor on to do it.
Someone needs access right now, mid-run
Someone needs access right now, mid-run
Use Grant emergency access on their staff row. It is time-boxed, needs a reason, expires by itself and is recorded on this tab.
I signed in with a passkey and was still asked to enrol
I signed in with a passkey and was still asked to enrol
That is correct. A passkey is one factor. It does not satisfy a two-factor requirement.
The Security alerts card is not there
The Security alerts card is not there
It only renders when there is something to show, and only to people allowed to see it. No card means no bypass events.
I need the full history, not just recent alerts
I need the full history, not just recent alerts
Everything is in the audit log, kept for seven years. See Audit log.