Skip to content

Security

The Security settings allow you to restrict access to your organization based on IP addresses. By configuring an IP allow list, only users connecting from approved IP addresses or ranges can use the application.

  1. Navigate to Admin SettingsSecurity
  2. You will see the IP Allow List configuration panel

The IP allow list lets you define which IP addresses or ranges are permitted to access your organization. When no restrictions are configured, all IP addresses are allowed.

  • Enter one or more CIDR ranges (IP address ranges in CIDR notation)
  • Only users whose IP address falls within one of the specified ranges can access the application
  • Users from other IP addresses will see a blocked access page
  1. In the Allowed CIDR Ranges text field, enter your IP ranges
  2. Enter one CIDR range per line
  3. Click Save

Example CIDR ranges:

192.168.1.0/24
10.0.0.0/8
2001:db8::/32

To allow access from all IP addresses again:

  1. Click Remove All Restrictions
  2. Confirm the action in the dialog
  3. All IP restrictions will be removed

Changes to the IP allow list may take up to 60 seconds to take effect across all services.

IP restrictions are useful for:

  • Office-only access: Restrict access to your organization’s office network
  • VPN enforcement: Ensure users connect through your corporate VPN
  • Compliance requirements: Meet regulatory requirements for access control

In the Two-factor authentication section, you can require all users in your organization to log in with an additional security step.

When two-factor authentication is required, all users must protect their account with an authenticator app (e.g. Google Authenticator, Microsoft Authenticator, or Authy). During login, a one-time code from the app is requested in addition to the password.

  1. Navigate to Admin SettingsSecurity
  2. Enable the Require two-factor authentication toggle
  3. The change applies at each user’s next login

Users who have not yet set up two-factor authentication will be prompted to do so at their next login before they can continue.

Disable the toggle to lift the requirement. Users who have already set up 2FA keep their configuration — it simply is no longer enforced.

  • Manage Users — Control who has access to your organization
  • Teams — Organize users into groups with specific permissions