Account security and recovery
Manage passwords, organization two-factor policy, enrollment and recovery codes.
Account security combines personal credentials with organization policy. Use the dashboard's security flows so verification and recovery steps remain attached to your current session.
Passwords and invitations
You can request a password reset, complete it with the issued recovery data, or change your password from an authenticated profile. Reset links and codes are credentials; keep them out of support tickets and logs.
Organization invitations have an explicit accept or reject decision. Administrators can resend or cancel invitations while they remain actionable. See access management for membership and role assignment.
Two-factor authentication
Organization administrators can require two-factor authentication. Check your enrollment status and follow the supported authenticator flow to begin and complete enrollment.
| Action | What to expect |
|---|---|
| Enroll | Complete setup and verification before relying on the new factor. |
| Replace a factor | Use the rotation flow and complete its verification steps. |
| Regenerate backup codes | Complete the required verification; the previous recovery set becomes invalid. |
| Disable two-factor authentication | Organization policy and verification determine whether this is permitted. |
Store backup codes offline in a secure location. Keep only the current recovery set after regeneration.
Recover access
If an action requires recent verification, complete the password, authenticator, email OTP or backup-code step offered by that flow. Repeated failures may be rate-limited.
When organization policy prevents recovery, contact an organization administrator or Vegalake support. Include the affected action and a redacted error; never include passwords, reset links, OTPs or backup codes.