> For the complete documentation index, see [llms.txt](https://docs.theseaai.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.theseaai.com/accountsetup/security-settings.md).

# Security settings

## Multi-factor authentication

MFA adds an extra verification step at sign-in. When enforced, every member in the organization must use an authenticator app (TOTP) to access Beachside.

### Enable MFA for your organization

When you enable MFA, it applies to all members in the organization. Members who are not enrolled will be required to set up MFA at their next login.

* All members will be prompted to enroll the next time they log in.
* Members cannot access Beachside until enrollment is complete.
* During enrollment, members will also receive recovery codes (one-time backup codes).

{% hint style="info" %}
**Only Organization Admins can enable MFA.**\
Before you turn it on, make sure you have access to an authenticator app so you can complete MFA sign-in and avoid locking yourself out.
{% endhint %}

<figure><img src="https://3377749587-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOUQ3EAPIPziQuBKQgmTy%2Fuploads%2FzXs7uSovAkH9ZA56oGyV%2Fimage.png?alt=media&amp;token=93d66d09-a584-4edf-ab3b-90ae9121ab74" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}

#### **Go to&#x20;**<kbd><mark style="color:$primary;">**Teams**<mark style="color:$primary;"></kbd>**&#x20;in the top navigation**

{% endstep %}

{% step %}

#### **Go to&#x20;**<kbd><mark style="color:$primary;">**Organization settings**<mark style="color:$primary;"></kbd>

You can access it from the left sidebar, below your teams.
{% endstep %}

{% step %}

#### **Click on&#x20;**<kbd><mark style="color:$primary;">**Enable MFA**<mark style="color:$primary;"></kbd>

The button is on the right. It will open a popover.
{% endstep %}

{% step %}

#### **Click on&#x20;**<kbd><mark style="color:$primary;">**Enable MFA**<mark style="color:$primary;"></kbd>

Confirm you want to enable MFA for all users in your organization.
{% endstep %}
{% endstepper %}

***

### Reset MFA for a member

Use this when someone lost their phone, changed devices, or can’t access their authenticator app and recovery codes.

* All members will be prompted to enroll the next time they log in.
* Members cannot access Beachside until enrollment is complete.
* During enrollment, members will also receive recovery codes (one-time backup codes).

<figure><img src="https://3377749587-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOUQ3EAPIPziQuBKQgmTy%2Fuploads%2Fxyp01klIgkHWBm7mr3mc%2Fimage.png?alt=media&amp;token=eaf0d8c1-c39a-463b-9c4e-20b8798137dc" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}

#### **Go to&#x20;**<kbd><mark style="color:$primary;">**Teams**<mark style="color:$primary;"></kbd>**&#x20;in the top navigation**

{% endstep %}

{% step %}

#### **Go to&#x20;**<kbd><mark style="color:$primary;">**Manage all members**<mark style="color:$primary;"></kbd>

You can access it from the left sidebar, below your teams.
{% endstep %}

{% step %}

#### **Find the team member in the list**

You can also search for their name or email address.
{% endstep %}

{% step %}

#### **Hover on the member and select**  <i class="fa-ellipsis-vertical">:ellipsis-vertical:</i>

{% endstep %}

{% step %}

#### **Click on&#x20;**<kbd><mark style="color:$primary;">**Reset authenticator**<mark style="color:$primary;"></kbd>

{% endstep %}
{% endstepper %}

***

## Unlocking locked members

Beachside locks an account after <mark style="color:$primary;">**`5 failed sign-in attempts`**</mark> & <mark style="color:$primary;">**`3 failed authentication code attempts`**</mark> to protect it from password or code guessing. A member locked by failed sign-ins needs an admin to unlock them; a member locked by failed MFA authentication can recover with a recovery code, or you can reset it for them.

### Finding locked members in team management page

Locked members show a status in your member list telling you why and which action to take:

<table><thead><tr><th width="156.0390625">Locked reason 1</th><th width="296.234375">Admin action</th><th>Member action</th></tr></thead><tbody><tr><td>5 failed sign-in attempts </td><td><ol><li>Confirm the request comes from the member directly</li><li>Click on <mark style="color:$primary;"><strong><code>Unlock user</code></strong></mark>  will send an password reset email to members automatically</li></ol></td><td><ol><li>Receive an email to reset password</li><li>Click from the email to finish the reset process</li><li>Log in again </li></ol></td></tr></tbody></table>

<figure><img src="https://3377749587-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOUQ3EAPIPziQuBKQgmTy%2Fuploads%2FInKxPKeGFXmwipCiKyvU%2Fimage%2010.png?alt=media&amp;token=2f27cba4-ed46-45b5-a811-8d18b035cbad" alt=""><figcaption><p>Locked - too many sign-in attempts</p></figcaption></figure>

<table><thead><tr><th width="153.8671875">Locked reason 2</th><th width="303.76171875">Admin action</th><th>Member action</th></tr></thead><tbody><tr><td>3 failed authentication code attempts</td><td><ol><li>Confirm the request comes from the member directly</li><li>Click on <mark style="color:$primary;"><strong><code>Reset authenticator</code></strong></mark> will send an authenticator reset email to members automatically</li></ol></td><td><ol><li>Receive an email to reset authenticator</li><li>Click from the email to log in again and reset the code</li></ol></td></tr></tbody></table>

<figure><img src="https://3377749587-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOUQ3EAPIPziQuBKQgmTy%2Fuploads%2F2s8PSZrRWMeqptKzgHZG%2Fimage%2011.png?alt=media&amp;token=62384470-f677-4b9b-afe5-a7d86ebc3116" alt=""><figcaption><p>Locked - too many authenticator code attempts</p></figcaption></figure>

### After your unlock action

The member will get an email to either re-set password or MFA code. After successful finish the reset, they can sign in again.

***

## FAQ

<details>

<summary><strong>What happens when admin get locked?</strong></summary>

You can contact other admins on the team to unlock you. If you're the only admin and locked, please contact our support team to restore access.

</details>

<details>

<summary><strong>A member says they're locked, but I don't see a status.</strong></summary>

Refresh the list, or check they haven't already recovered on their own with a recovery code — the status clears when they do.

</details>

<details>

<summary><strong>Can I unlock an account that isn't locked?</strong></summary>

No — Unlock only applies while an account is actually locked. But MFA authentication can be reset at anytime.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.theseaai.com/accountsetup/security-settings.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
