Security and Access
Protect individual accounts, enforce MFA for future members, and understand which workspace policy fields are active today.
Eigenn separates personal sign-in protection from workspace security policy. Settings → Account → Security manages your MFA devices. Settings → Security stores policy for the active workspace.
Personal MFA Devices
Open Settings → Account → Security to see enrolled factors and their enrollment dates.
Add an authenticator
- Select Add device.
- Select Continue.
- Scan the QR code with a TOTP authenticator.
- Use the manual setup key if you cannot scan the code.
- Enter the current six-digit code.
- Select Verify & enable.
The current add-device flow enrolls a TOTP authenticator app. It does not enroll a passkey, hardware security key, or trusted-browser device.
Remove an authenticator
Select Remove beside a factor. If the active workspace needs MFA for your membership and this is your last factor, Eigenn blocks the removal. Add a replacement factor first. Then confirm the new factor.
Keep at least two factors when uninterrupted access is important. The app does not display downloadable recovery codes in the current Account security page.
Workspace MFA Policy
Only a workspace owner can save Settings → Security.
Turn on Require MFA for New Members to make MFA mandatory for memberships created at or after the policy activation time.
This policy is prospective by design:
- Eigenn does not force current members into MFA when you turn on the policy.
- Eigenn redirects future members to MFA setup or verification before protected workspace pages.
- When you turn off the policy, Eigenn stops the future-member rule and clears its activation timestamp.
- A future member subject to the policy cannot remove their last factor.
Eigenn clears the MFA verification marker on a fresh sign-in and on logout. A user subject to the policy must confirm again before they continue to protected pages.
Applied and Saved Workspace Policies
The Security page presents four groups. Their current behavior is not identical.
| Setting | Current effect |
|---|---|
| Require MFA for New Members | Eigenn enforces this for memberships created after activation |
| Session Timeout | Saved on the workspace. The current session layer does not read this value to expire inactive sessions |
| Enforce IP Whitelist and its address list | Eigenn confirms and saves the list. The list does not now restrict sign-in or page access |
| Enable Audit Log | Saved. It does not turn a workspace audit-log viewer on or off in the current app |
| Audit Log Retention | Saved. It does not now control automatic log deletion |
| Data Retention | Saved. It does not now schedule customer-data removal |
| Anonymize Deleted Customers | Saved. Current customer deletion paths do not use it as an anonymization switch |
Treat saved-only values as policy intent, not proof of enforcement. Do not cite them as an implemented compliance control until the relevant behavior is available and independently confirmed.
Configure the Enforced MFA Policy
- Sign in as a workspace owner.
- Open Settings → Security.
- In Access Control, turn on Require MFA for New Members.
- Select Save.
- Invite a test member after activation.
- Confirm that Eigenn redirects the new member to MFA verification before a protected page.
- Confirm that a current member can still enter without that prospective rule.
When you change the Session Timeout in the same card, Eigenn saves the selected 12-hour, 24-hour, 48-hour, or 7-day value. It does not now change session expiry behavior.
IP Restrictions
The form accepts one IPv4 address, full IPv6 address, or IPv4 CIDR range per line. Examples include 192.0.2.10 and 10.0.0.0/24.
Eigenn applies schema validation to the values. Only an owner can save them. The app request path does not check them now. Keep network enforcement at your identity provider, VPN, reverse proxy, or another control that you confirmed until Eigenn enforcement is available.
Audit and Data-Retention Settings
The UI offers:
- Audit log on or off
- 7, 30, 90, or 120 days of audit retention
- 30 days, 90 days, one year, or indefinite customer-data retention
- Anonymization of deleted customers
These values persist on the workspace. They are not evidence that Eigenn generates logs, purges logs, or transforms customer deletion. Use the exported records and the controls that your organization confirmed. Involve legal or security owners for retention policy.
SSO and Organizations
Organization setup is separate from the Security page. Open Settings → Account → Organizations to create or examine an organization. Use its administration link when it is available.
If domain-based sign-in says no team exists, an owner must first create and set up the identity organization. See Teams and Organizations for the supported organization workflow.
Account and Workspace Deletion
Delete your account
Settings → Account → General → Delete account permanently removes your user. Eigenn finds the sole-owned workspaces before deletion. Eigenn can then queue external cleanup for them. Eigenn also removes your membership in the workspaces that you do not solely own.
The current primary Account deletion dialog asks for confirmation. It does not ask you to enter the email again. It does not ask for a fresh MFA challenge.
Delete a workspace
Settings → General → Delete team is owner-only. It permanently removes the active workspace. Eigenn queues external-resource cleanup after the database deletion. Treat the action as irreversible even when external cleanup finishes later.
Access Recovery
- Use the same Google, Apple, GitHub, email, or SSO identity method that you used for the account.
- When a user subject to the policy has no enrolled factor, the verification flow redirects to authenticator setup.
- If you lose a factor but keep another one, confirm with the second authenticator. Then add a replacement.
- If all factors are unavailable, use the public Contact page. The app has no self-service recovery-code screen or separate password-reset page.
- If SSO fails because the domain has no configuration, contact an organization owner. Do not create a second personal identity.
Never send an MFA secret, QR code, six-digit code, session cookie, or API credential to support.
Troubleshoot
Eigenn rejects a security policy save
Only an owner can update workspace Security. Confirm your role and active workspace.
I turned on IP restrictions but access still works elsewhere
That is the current behavior. Eigenn saves the setting, but the setting does not restrict sign-in or page access. Apply a network control that you confirmed outside Eigenn.
Eigenn does not prompt a new member for MFA
Confirm that you turned on the policy before Eigenn created that membership. The rule is not retroactive. When you turn the policy off and on again, a current membership does not become new.
I cannot remove my last factor
Your membership is subject to the future-member MFA policy of the workspace. Add another authenticator. Confirm it. Then remove the old factor.
I changed Session Timeout but remained signed in
Eigenn saves the value now without session-expiry enforcement. Sign out manually when you leave a shared or untrusted device.