Skip to main content

Security Settings

The Security page centralizes authentication and account protection controls. Access: Go to Settings → Profile → Security.

Authentication Methods

The top section includes:
  • Email (verification and change flow)
  • Password (set/change)
  • Phone (add/edit)
  • MFA status and management

Multi-Factor Authentication (MFA)

itellicoAI supports authenticator-app MFA (TOTP) with recovery codes.

Enable MFA

1

Open Security

Go to Settings → Profile → Security.
2

Enable MFA

In the MFA row, click Enable.
3

Complete authenticator setup

Follow the TOTP setup flow and confirm with a valid code.
4

Store recovery codes

Save your recovery codes in a secure location.

Disable MFA

You can disable MFA from the same section. The flow requires security confirmation.
Disabling MFA reduces account security. Keep MFA enabled in production accounts.
For most business users, a good baseline is:
  • password set and up to date
  • MFA enabled
  • recovery codes stored safely
  • unfamiliar sessions revoked

Password Management

Change your password from the Security page. Current password is required, and new passwords must meet current policy requirements (minimum length and validation rules).

Active Sessions

The Active Sessions table shows currently active device sessions. Each row includes:
  • Device/browser
  • Location (when available)
  • Last activity
  • Current-session indicator
Actions available:
  • Revoke individual sessions
  • Revoke all other sessions

Login Activity

Review recent security-relevant activity, including:
  • Login events
  • Password changes/resets
  • MFA success/failure events
  • Event metadata (device, location, IP, timestamp)
Use this section to review recent access and authentication events.

Connected Social Accounts

Security also includes connected social providers (for example Google and Apple) where enabled. You can connect/disconnect providers from this section, subject to account safety checks (for example avoiding lockout if no other login method exists).

Security Best Practices

Require MFA for owners/admins and any user with elevated permissions.
Check active sessions and login activity for unfamiliar devices or locations.
Keep passwords unique and rotate exposed credentials quickly.
Store MFA recovery codes in a secure password manager or vault.

FAQs

Use a recovery code. If recovery options are unavailable, contact support@itellico.ai.
You can revoke other sessions from the table. Your current session remains active unless you log out.
Use Settings → Profile → Security in the authentication methods section.

Next Steps

Team Management

Align member roles with your security model

API Keys

Rotate and manage programmatic credentials

User Profile

Configure UI mode, theme, and language