Security and Access
Protect individual accounts, enforce MFA for future members, and understand which workspace policy fields are active today.
Eigenn separates personal sign-in protection from workspace security policy. Settings → Account → Security manages your MFA devices. Settings → Security stores policy for the active workspace.
Personal MFA Devices
Open Settings → Account → Security to see enrolled factors and their enrollment dates.
Add an authenticator
- Select Add device.
- Select Continue.
- Scan the QR code with a TOTP authenticator.
- Use the manual setup key if you cannot scan the code.
- Enter the current six-digit code.
- Select Verify & enable.
The current add-device flow enrolls a TOTP authenticator app. It does not enroll a passkey, hardware security key, or trusted-browser device.
Remove an authenticator
Select Remove beside a factor. If the active workspace needs MFA for your membership and this is your last factor, Eigenn blocks the removal. Add a replacement factor first. Then confirm the new factor.
Keep at least two factors when uninterrupted access is important. The app does not display downloadable recovery codes in the current Account security page.
Workspace MFA Policy
Only a workspace owner can save Settings → Security.
Turn on Require MFA for New Members to make MFA mandatory for memberships created at or after the policy activation time.
This policy is prospective by design:
- Eigenn does not force current members into MFA when you turn on the policy.
- Eigenn redirects future members to MFA setup or verification before protected workspace pages.
- When you turn off the policy, Eigenn stops the future-member rule and clears its activation timestamp.
- A future member subject to the policy cannot remove their last factor.
Eigenn clears the MFA verification marker on a fresh sign-in and on logout. A user subject to the policy must confirm again before they continue to protected pages.
Workspace security settings
Settings → Security has two cards. Eigenn enforces every control on the page.
| Card | Setting | Enforcement |
|---|---|---|
| Access Control | Require MFA for New Members | Applies to memberships created at or after the activation time |
| Audit & Logging | Enable Audit Log | Controls whether Eigenn records routine write operations |
| Audit & Logging | Audit Log Retention | Sets how long Eigenn keeps routine audit records: 7, 30, 90, or 120 days |
New workspaces start with audit logging on and 90-day retention.
Earlier releases also showed session-timeout, IP-allowlist, data-retention, and customer-anonymization controls. Those controls saved a value that no session, request, or deletion path read, so Eigenn removed them. Enforce network and session restrictions at your identity provider, VPN, or proxy.
Audit logging
When Enable Audit Log is on, Eigenn records write operations with the actor, the action, the resource type, the result, the request duration, and the source IP address. Eigenn does not store free-form error text, because that text can contain personal data.
Eigenn always records security-sensitive events, even when you turn the setting off. These events cover workspace settings, roles and permissions, membership, and directory sync. A workspace cannot suppress the record of the action that disables auditing or of any privilege change.
A change to Enable Audit Log can take up to five minutes to apply, because Eigenn caches the value.
Retention
A nightly job deletes audit records in two passes:
- Records past the retention period of their category.
- Records older than the Audit Log Retention value that you selected.
The second pass applies only to routine business records. Security-sensitive records keep their longer compliance period, so a shorter workspace setting cannot delete them early.
The Settings → Security page saves policy. It does not display the recorded audit entries.
Configure the MFA policy
- Sign in as a workspace owner.
- Open Settings → Security.
- In Access Control, turn on Require MFA for New Members.
- Select Save.
- Invite a test member after activation.
- Confirm that Eigenn redirects the new member to MFA verification before a protected page.
- Confirm that a current member can still enter without that prospective rule.
Configure audit logging
- Sign in as a workspace owner.
- Open Settings → Security.
- In Audit & Logging, set Enable Audit Log and Audit Log Retention.
- Select Save.
Choose a retention period that meets your compliance obligation. Eigenn cannot recover a record after the nightly job deletes it.
A non-owner sees the page read-only. The server also rejects a non-owner write, so the read-only state is not the only check.
SSO and organizations
Organization setup is separate from the Security page. Open Settings → Account → Organizations to create or examine an organization. Use its administration link when it is available.
If domain-based sign-in says no team exists, an owner must first create and set up the identity organization. See Teams and Organizations for the supported organization workflow.
Account and workspace deletion
Delete your account
Settings → Account → General → Delete account permanently removes your user. Eigenn finds the sole-owned workspaces before deletion. Eigenn can then queue external cleanup for them. Eigenn also removes your membership in the workspaces that you do not solely own.
The current primary Account deletion dialog asks for confirmation. It does not ask you to enter the email again. It does not ask for a fresh MFA challenge.
Delete a workspace
Settings → General → Delete team is owner-only. It permanently removes the active workspace. Eigenn queues external-resource cleanup after the database deletion. Treat the action as irreversible even when external cleanup finishes later.
Access recovery
- Use the same Google, Apple, GitHub, email, or SSO identity method that you used for the account.
- When a user subject to the policy has no enrolled factor, the verification flow redirects to authenticator setup.
- If you lose a factor but keep another one, confirm with the second authenticator. Then add a replacement.
- If all factors are unavailable, use the public Contact page. The app has no self-service recovery-code screen or separate password-reset page.
- If SSO fails because the domain has no configuration, contact an organization owner. Do not create a second personal identity.
Never send an MFA secret, QR code, six-digit code, session cookie, or API credential to support.
Troubleshoot
Eigenn rejects a security policy save
Only an owner can update workspace Security. Confirm your role and active workspace.
Eigenn does not prompt a new member for MFA
Confirm that you turned on the policy before Eigenn created that membership. The rule is not retroactive. When you turn the policy off and on again, a current membership does not become new.
I cannot remove my last factor
Your membership is subject to the future-member MFA policy of the workspace. Add another authenticator. Confirm it. Then remove the old factor.
I turned audit logging off, but Eigenn still records entries
Eigenn caches the setting for up to five minutes. Eigenn also always records security-sensitive events, such as changes to settings, roles, membership, and directory sync.
I cannot find a session-timeout or IP-allowlist setting
Eigenn removed both controls, because nothing enforced them. Apply session and network restrictions at your identity provider, VPN, or proxy.