Last updated September 7, 2026
Your Account Security
Your ProvenMap account reaches your architecture — every board, every source, every insight your team has built. This page covers the controls that protect it: a second step at sign-in, what happens when you lose it, and how account recovery works.
This is about you as a person signing in. For the credentials your plugins and agents use, see Signing In & Credentials — those are separate, and they don't share a lifecycle with your login.
Turn on two-factor authentication
Two-factor authentication adds a second step after your password: a six-digit code from an authenticator app on your phone. Someone who steals your password still can't sign in without your phone.
You'll find it in Profile, under Two-factor authentication. Choose Set up authenticator app, scan the QR code with your app, and enter the code it shows you to confirm the pairing.
Any standard TOTP app works, including Google Authenticator, 1Password, and Authy. We don't offer SMS as a second factor because attackers can redirect a phone number without accessing your account.
Turning it on for yourself is what makes us ask you for a code. There's no separate "enforce" step for your own account — enrolling is enabling.
Once it's on, you'll enter a code each time you sign in. You can turn it off from the same place. We'll email you whenever the setting changes so you can spot a change you didn't make.
If you sign in with Google or enterprise SSO
You won't see the two-factor controls, and that's deliberate rather than an oversight.
When you use Google or your company's identity provider, that provider authenticates you. We never see a password, so we have no second step to add. Configure your second factor in the identity provider.
If your organization needs every member on MFA, this is the path that gets you there. See Requiring it across your organization below.
If you lose your authenticator
A lost or wiped phone would otherwise lock you out permanently — only you can turn off your own second factor, and you need the app to do it.
So an organization admin can reset it for you. On the Team page, they open the menu next to your name and choose Reset 2FA. That clears the registered device; you can then sign in with your password alone and set up a new authenticator.
If you're the only admin, add a second one before you turn two-factor on. An organization with one admin who loses their phone has nobody who can perform the reset.
Passwords and recovery
Change your password from Profile, under Password. As with two-factor, we email you when it changes.
If you've forgotten it, use Forgot password on the sign-in page. Recovery runs entirely through your registered email address — there's no SMS route, so nobody can take over your account by taking over a phone number.
Requiring it across your organization
We don't have an organization-wide MFA switch in the portal today. Enrolling is per person.
If you need a hard requirement across your team, enforce MFA in your identity provider and require SSO for your domain. Every member then authenticates through a provider you control, with whatever policy you set there. Enterprise SSO walks through verifying a domain and turning on required SSO.
Requiring SSO for a verified domain refuses password and Google sign-up for that domain at the identity layer. Make sure the people you expect to sign in can reach your provider before you turn it on.
What's next
Enterprise SSO
Verify a domain, register your identity provider, and require SSO for everyone on it.
Permissions & Access Control
Who can reset a member's second factor, and what else an admin can do.
Signing In & Credentials
The separate credentials your plugins and agents use.
Organization Settings
Members, roles, and the rest of what an admin manages.





