For the complete documentation index, see llms.txt. This page is also available as Markdown.

Security settings

Multi-factor authentication

MFA adds an extra verification step at sign-in. When enforced, every member in the organization must use an authenticator app (TOTP) to access Beachside.

Enable MFA for your organization

When you enable MFA, it applies to all members in the organization. Members who are not enrolled will be required to set up MFA at their next login.

  • All members will be prompted to enroll the next time they log in.

  • Members cannot access Beachside until enrollment is complete.

  • During enrollment, members will also receive recovery codes (one-time backup codes).

Only Organization Admins can enable MFA. Before you turn it on, make sure you have access to an authenticator app so you can complete MFA sign-in and avoid locking yourself out.

1

Go to Teams in the top navigation

2

Go to Organization settings

You can access it from the left sidebar, below your teams.

3

Click on Enable MFA

The button is on the right. It will open a popover.

4

Click on Enable MFA

Confirm you want to enable MFA for all users in your organization.


Reset MFA for a member

Use this when someone lost their phone, changed devices, or can’t access their authenticator app and recovery codes.

  • All members will be prompted to enroll the next time they log in.

  • Members cannot access Beachside until enrollment is complete.

  • During enrollment, members will also receive recovery codes (one-time backup codes).

1

Go to Teams in the top navigation

2

Go to Manage all members

You can access it from the left sidebar, below your teams.

3

Find the team member in the list

You can also search for their name or email address.

4

Hover on the member and select

5

Click on Reset authenticator


Unlocking locked members

Beachside locks an account after 5 failed sign-in attempts & 3 failed authentication code attempts to protect it from password or code guessing. A member locked by failed sign-ins needs an admin to unlock them; a member locked by failed MFA authentication can recover with a recovery code, or you can reset it for them.

Finding locked members in team management page

Locked members show a status in your member list telling you why and which action to take:

Locked reason 1
Admin action
Member action

5 failed sign-in attempts

  1. Confirm the request comes from the member directly

  2. Click on Unlock user will send an password reset email to members automatically

  1. Receive an email to reset password

  2. Click from the email to finish the reset process

  3. Log in again

Locked - too many sign-in attempts
Locked reason 2
Admin action
Member action

3 failed authentication code attempts

  1. Confirm the request comes from the member directly

  2. Click on Reset authenticator will send an authenticator reset email to members automatically

  1. Receive an email to reset authenticator

  2. Click from the email to log in again and reset the code

Locked - too many authenticator code attempts

After your unlock action

The member will get an email to either re-set password or MFA code. After successful finish the reset, they can sign in again.


FAQ

What happens when admin get locked?

You can contact other admins on the team to unlock you. If you're the only admin and locked, please contact our support team to restore access.

A member says they're locked, but I don't see a status.

Refresh the list, or check they haven't already recovered on their own with a recovery code — the status clears when they do.

Can I unlock an account that isn't locked?

No — Unlock only applies while an account is actually locked. But MFA authentication can be reset at anytime.