Authentication methods
Multi-factor authentication
Add a second factor to your own account:1
Open your account settings
Open your account menu and go to Account Settings → 2FA.
2
Set up the authenticator
Start MFA setup and scan the QR code with an authenticator app (Google Authenticator, Authy, 1Password, and more).
3
Confirm with a code
Enter the 6-digit code from your authenticator to finish setup.
4
Save your backup codes
Download and store the one-time backup codes. At sign-in, you can enter an 8-character backup code instead of an authenticator code.
Single sign-on
SSO is available on Scale, Scale+, and Enterprise plans and is configured by the organization Owner in Admin Settings → Identity and access:- Domain verification — prove ownership of your email domain with a DNS TXT record before setting up SSO
- SAML 2.0 or OIDC — choose the protocol your identity provider supports
- Require SSO — optionally disable all other sign-in methods for your users
- Provisioning — invite users manually, auto-create accounts on first SSO login (JIT), or sync your directory with SCIM
Roles and permissions
Access is controlled at two levels. An organization role applies across every workspace; a workspace role can grant a specific member a different level in one workspace.Organization roles
Workspace roles
Permission matrix
Data security
BYOK is about model access, not encryption keys: workspaces on Scale, Scale+, and Enterprise plans can route LLM inference through their own AWS Bedrock credentials for cost control and data residency.
Audit logs
Organization activity — sign-ins, administrative changes, and agent actions — is recorded in Admin Settings → Audit Logs, available on Scale, Scale+, and Enterprise plans. Filter by user, action, and date, and export entries for compliance review.Security best practices
- Enable MFA for every member, especially Owners and Admins — or enforce SSO and let your identity provider require it.
- Assign the minimum role each member needs, and review access quarterly.
- Use read-only cloud credentials where possible, scoped to the services and regions agents need.
- Rotate credentials — cloud keys, SCIM tokens, and webhook secrets — on a regular schedule.
- Review audit logs for unexpected administrative changes or sign-ins.
Related
Custom Guardrails
Choose built-in protections and add patterns for your team’s identifier formats
Single Sign-On
Verify your domain, connect your identity provider, and enforce SSO
SCIM Provisioning
Automate user and group sync from your identity provider
Organization Management
Manage members, roles, and workspaces
Bring Your Own Key
Route LLM inference through your own AWS Bedrock account