EIGENN.
docsguidesapichangelogpricingsign in
EIGENN.

Manage Security and Billing

Run an owner review of MFA policy, access boundaries, subscription state, delegates, usage, and destructive controls.

Examine security and billing together, because subscription state can block writes. Current role behavior also gives Members access to plan operations. Run this review as a workspace owner. Record the controls that your organization uses to compensate.

1. Confirm Owner Continuity

Before you change policy or billing:

  1. Open the membership view.
  2. Confirm the intended owner accounts.
  3. Make sure that at least one other authorized recovery contact exists when continuity needs it.
  4. Remove stale membership only after the ownership is safe.

Do not delete an owner account or workspace while it is the only path to business records.

2. Check Personal MFA

Open Settings → Account → Security.

  • Confirm that your active authenticator appears.
  • Add a replacement factor before you retire an old device.
  • Check the factor that you added with a six-digit code.
  • Remove the old factor only after the replacement works.

The current add-device flow supports TOTP authenticator apps. It does not show passkeys or recovery codes.

3. Set the Future-Member MFA Rule

Open Settings → Security.

  1. Turn on Require MFA for New Members.
  2. Select Save.
  3. Record the activation date in your internal access procedure.
  4. Test with a membership that you create after that date.

The rule does not apply retroactively. Current members need a separate enrollment campaign and verification process.

4. Classify the Other Security Fields

Examine each visible field. But separate the stored intent from the active enforcement.

ControlOwner action today
Session TimeoutSave only as policy metadata; keep the session controls that you checked outside this product
IP WhitelistSave only; enforce trusted networks at the identity, VPN, proxy, or firewall layer
Audit Log toggle and retentionSave only; do not claim an active audit pipeline or purge schedule
Data RetentionSave only; keep a checked retention procedure outside this setting
Anonymize Deleted CustomersSave only; do not assume deletion invokes anonymization

If an audit or a customer contract asks about enforcement of a control, answer from the observed system behavior. Do not answer from the Settings toggle.

5. Check SSO and Organization State

Open Settings → Account → Organizations and select the relevant organization.

  • Confirm the organization domain.
  • Examine the identity-administration links that are available.
  • Confirm SSO connections in the identity administration system.
  • Test sign-in with a non-owner account.

The workspace Security page does not set up SSO. Organization administration is the supported identity path.

6. Reconcile Billing State

Open Settings → Billing.

  1. Compare Current Plan with the hosted billing portal.
  2. Check for a Cancelling badge.
  3. Select Manage billing.
  4. Confirm the payment method and the platform invoices.
  5. Compare order history with provider records.
  6. Record the intended renewal owner.

Local plan state can lag checkout or cancellation. Use the provider state before you buy again or promise continued paid access.

7. Control Who Can Change the Plan

Current billing permissions let Owners and Members do these actions:

  • Start paid-plan checkout
  • Open the hosted billing portal
  • Schedule subscription cancellation with the Free option

A Viewer cannot do those writes. Only an Owner can change billing delegates.

If plan changes need owner approval, do not use Member as a purely operational role without one more control. Examine the membership design with Manage Team Access.

8. Treat Delegates as Labels

An Owner can toggle a member as a billing delegate. Check the saved badge after each change.

Do not depend on the delegate list to:

  • Grant billing access
  • Send renewal notices
  • Send the Send Reminder menu action

Those actions do not now happen automatically. Tell the designated billing owner through your current channel.

9. Check Usage and Do Not Trust the Fallback

Open Settings → Usage and compare:

  • Seats
  • Active bank connections
  • Current-month Inbox items
  • Current-month invoices
  • Storage

Use detail CSV exports for evidence when the data looks credible.

If the page shows Free, zero for every metric, and No limit everywhere, it probably shows its error fallback. Do not use that state for capacity or billing decisions. Compare the actual resource pages and the hosted billing portal.

10. Schedule a Downgrade Safely

When you select Free, Eigenn asks for confirmation. Eigenn then schedules cancellation at period end.

Before you confirm:

  1. Examine the paid features and quotas that the workspace uses.
  2. Export the necessary billing and operational records.
  3. Find the active workflows, webhooks, API keys, and connections.
  4. Communicate the effective date.
  5. Select Free.
  6. Confirm the change.
  7. Check the cancellation in the hosted portal.

The local Current Plan card can stay paid until the provider synchronizes.

11. Review Destructive Controls

Delete account

This action deletes the user and any solely owned workspaces. It then queues external cleanup for those workspaces.

Delete team

Owner-only permanent deletion of the active workspace. Storage and connected-provider cleanup can continue asynchronously.

Remove custom email domain

Owner-only. Clears the workspace sender configuration and returns email to the default domain.

Remove bank connection

This action stops sync for that connection and changes usage. Check downstream reconciliation before you remove the connection.

Review Cadence

Run this review:

  • Before you invite a new department
  • After an owner or billing contact changes
  • Before plan renewal or downgrade
  • After an identity or payment incident
  • Before you describe a Settings control in a compliance questionnaire

Troubleshoot

A Member changed billing unexpectedly

Current billing permissions let a Member make that change. Examine the role assignment and the provider-side billing access again. Then document an approval control.

A saved security setting has no visible effect

That form enforces only the prospective MFA rule now. Treat the other values as stored policy intent.

The cancellation badge does not appear

Open the hosted billing portal and compare provider state. Local cancellation data can lag.

Usage contradicts Billing

If Usage is all zero and unlimited, discard it as the fallback. Use Billing and the actual records. Then contact support.

Send Reminder did not notify a delegate

The menu action is not implemented. Send the reminder through an operational channel outside that control.

Related Pages

  • Security and Access
  • Billing and Usage
  • Settings Overview
  • Teams and Organizations
  • Troubleshoot Account Access
  • Support

Maintain Transaction Rules

Design, backfill, confirm, prioritize, and replace transaction rules without damage to your reporting intent.

Manage Team Access

Invite teammates, assign roles, check acceptance, switch workspaces, and remove access, but keep at least one owner.

On this page

1. Confirm Owner Continuity2. Check Personal MFA3. Set the Future-Member MFA Rule4. Classify the Other Security Fields5. Check SSO and Organization State6. Reconcile Billing State7. Control Who Can Change the Plan8. Treat Delegates as Labels9. Check Usage and Do Not Trust the Fallback10. Schedule a Downgrade Safely11. Review Destructive ControlsDelete accountDelete teamRemove custom email domainRemove bank connectionReview CadenceTroubleshootA Member changed billing unexpectedlyA saved security setting has no visible effectThe cancellation badge does not appearUsage contradicts BillingSend Reminder did not notify a delegateRelated Pages

Eigenn docs

current product

Overview
Overview
OverviewAccount PreferencesAssistant AutomationAssistant Command CenterBank ConnectionsBilling and UsageBudgets and ForecastCommand CenterCustomer LifecycleCustomer RecordsCustomersDeveloper PlatformDocument Processing and ExtractionDocument VaultFinancial Analytics and ReportsFinancial OverviewInvoice InsightsInvoice ProductsInvoicesMarketplace IntegrationsNotifications and BrandingOnboarding and SupportOverviewReceivablesReceivables AnalyticsReceivables ControlsSecurity and AccessSettings OverviewStress TestsTeams and OrganizationsTone Profiles and ExperimentsTransaction Categories and RulesTransactionsWeekly Finance RitualWorkflow ExecutionsWorkflow PausesWorkflowsWorkspace Inbox and Approvals
OverviewBuild and Review a ForecastBuild Your First WorkflowConfigure Assistant OperationsConfigure Notifications and BrandingConfigure Receivables ControlsConnect Transaction RecordsCreate and Manage CustomersCreate and Send InvoicesDeveloper API SetupFirst Cash ReviewInvoice Collection WorkflowMaintain Transaction RulesManage Security and BillingManage Team AccessManage the Invoice LifecycleMCP WorkflowsMonitor and Recover WorkflowsOrganize and Share DocumentsProcess Inbox ItemsReconcile and Categorize TransactionsReview a Customer Finance RecordRun a Finance Operating ReviewRun a Receivables Tone ExperimentRun a Runway Stress TestRun Your First Command Center ReviewSet Up a WorkspaceTroubleshoot Account AccessWebhook DeliveryWeekly CFO Review
OverviewIntegrationsMCPSDKsWebhooks
OverviewAuthenticationBank Accounts APICustomers APIErrorsForecasts and Stress Tests APIInvoice Payments APIInvoices APIPaginationRate LimitsRemote Tracker API StatusTracker Categories APITracker Entries and Timers APITracker Projects APITransactions APIWebhooks API StatusWorkflows API Status
Overview
Overview