regulation10.com

Knowledge base / regulation10.com product guide

Two-factor authentication and account security

To set up two-factor authentication (2FA), go to Account, then Security, and enrol an authenticator app. Scan the QR code with the app, enter the 6-digit code it shows to confirm the pairing, and save the one-time recovery codes you are given somewhere safe. From then on, signing in takes your password plus a current code from your app.

The reason to do this is blunt: passwords leak. They are phished, reused across services, and exposed in third-party breaches, and none of that is within your control. A second factor means a leaked password alone is not enough to open your account. For a workspace that holds your organisation's compliance record, regulatory assessments, and evidence about your AI systems, the account is worth more to an attacker than most, and the few seconds a code costs at sign-in is the cheapest control you can buy.

Any standard authenticator app works: the platform uses time-based one-time codes, which is the widely supported open standard rather than anything proprietary. The app generates a fresh 6-digit code every 30 seconds on your device. The code never travels to you over email or SMS, which removes the interception routes those channels carry.

The recovery codes deserve more respect than they usually get. They are single-use codes that let you sign in when your device is lost, broken, or reset. Treat them like cash: store them in a password manager or printed in a genuinely secure place, and never in the same place as the device they are meant to rescue you from. Each code works once and is then spent.

If you lose your device, sign in with a recovery code, then go straight to Security and enrol a new authenticator. Enrolling the new device invalidates the old pairing, so a lost phone stops being a key to your account the moment you re-enrol. If you have used most of your recovery codes, generate a fresh set at the same time.

If you are locked out with no device and no recovery codes, you are not permanently stranded, but the path is intentionally harder: a workspace Owner or the platform team can help restore access after verifying who you are. The friction there is the security working as designed. An easy bypass for you would be an easy bypass for an attacker.

There is also a compliance angle. Access control questions appear in security reviews, vendor assessments, and most governance frameworks, and 'is multi-factor authentication enforced for accounts holding sensitive records' is a standard line item. Enrolling 2FA on the accounts that manage your AI compliance record is one of those controls that costs minutes and answers a question you will certainly be asked.

The practical order for a team: the workspace Owner enrols first, because that account can change billing and membership, then Admins, then everyone else. Do it on a calm day, not during an incident. Pair the rollout with a shared note on where recovery codes belong, so nobody improvises their own storage, and check completion in your next access review. A partially protected workspace gives a false sense of cover, because an attacker only needs the one account that skipped the step.

Steps

  1. Go to Account then Security and enrol an authenticator app.
  2. Scan the QR code and enter the 6-digit code.
  3. Save your one-time recovery codes somewhere safe.
  4. Enter a code from your app each time you sign in.
Two-factor authentication and account security | regulation10.com