Skip to main content

Profile and two-factor authentication

This page covers the per-user account settings every Retrievy user controls for themselves: name and email, password rotation, and the two-factor authentication (2FA) enrollment flow with recovery codes. None of this is shared with the rest of your workspace, so each teammate manages their own.

The in-app pages live at Settings → Account → Profile and Settings → Account → Security.

Before you start

  • A Retrievy workspace login. No special permissions are required, every user can edit their own profile, password, and 2FA.
  • For 2FA: an authenticator app installed on your phone or laptop (any standard TOTP app works, such as Google Authenticator, Microsoft Authenticator, 1Password, Bitwarden, Authy).
  • If your account was created via SSO (Google or Microsoft), password rotation is disabled for your account and the Update password section will be unused. Password login is blocked at sign-in for SSO-provisioned users.

Profile

The Profile page shows an identity card at the top (avatar with your initials, your name, your email, an ACTIVE SESSION badge, and your user ID) followed by an editable form under the ACCOUNT RECORDS section.

Update your name and email

  1. Open Settings → Account → Profile.
  2. Edit Full Name. Up to 255 characters, required.
  3. Edit Email Address. Must be a valid email and unique across the workspace.
  4. Click Commit Changes.

A green Security Profile Synchronized confirmation appears next to the button. The identity card refreshes immediately with the new values.

Avatar

Retrievy generates your avatar from the first letter of each of the first two words of your full name. There is no avatar upload today. Change your name to change the initials shown in the avatar tile.

Verify your email

If your email address has never been verified (or you changed it to a new one), an amber banner appears below the form:

Your email address is unverified.

Resend verification email

Click Resend verification email. Retrievy sends a verification link to the new address and shows a SENT badge in the banner. Open the link from your inbox to verify. The banner disappears on your next page load.

Changing your email always resets verification. Until you verify the new address, you may lose access to features that gate on a verified email (notifications, password resets to that address).

Password

The Security page opens with the Update password section under the ACCESS CREDENTIALS header. Three fields side by side: Current Password, New Password, Confirm New Password.

Rotate your password

  1. Open Settings → Account → Security.
  2. Enter your Current Password.
  3. Enter your New Password. In production, Retrievy enforces:
    • At least 12 characters.
    • Mixed case (at least one uppercase and one lowercase letter).
    • At least one letter and at least one number.
    • At least one symbol.
    • The password must not appear in the HaveIBeenPwned breach corpus.
  4. Re-enter the same value in Confirm New Password.
  5. Click Rotate Password.

A green Credential Store Updated confirmation appears next to the button. The three fields clear.

If validation fails, all three fields are cleared and you get a per-field error. Common errors:

  • The current password is incorrect.
  • The password must be at least 12 characters.
  • The password has appeared in a data leak. Please choose a different password.

Forgotten password

If you cannot log in to rotate the password from inside the app, use the Forgot password? link on the login page. Retrievy emails a reset link to your verified address. The reset endpoint is rate-limited to 5 requests per IP per minute.

SSO-provisioned accounts

If your account was originally created by signing in with Google or Microsoft, password login is permanently disabled. The login form will reject the password with Please log in with Google (or Microsoft). Password authentication is disabled for this account. Use the SSO button on the login screen.

Two-factor authentication

The IDENTITY VERIFICATION section sits below the password form. It shows a single card with the heading Two-factor authentication and the description Add an additional layer of security to your account by requiring more than just a password to log in.

When 2FA is disabled, the card shows an Enable 2FA button and an info row at the bottom: When enabled, you will be prompted for a secure pin during login via a TOTP application.

When 2FA is enabled, the card border turns brand green, an ENFORCED badge with Standard TOTP Protocol appears under the heading, the right side shows a Disable 2FA button, and a recovery codes panel appears underneath.

Enable 2FA

  1. Click Enable 2FA. A modal opens titled Enable two-factor authentication with the body To finish enabling two-factor authentication, scan the QR code or enter the setup key in your authenticator app.
  2. Scan the QR code with your authenticator app. If you cannot scan (no camera, desktop authenticator), click the or, enter manually separator to reveal the alphanumeric setup key. Use the copy icon on the right of the key field, then paste it into your authenticator's manual-entry flow.
  3. Click Continue. The modal advances to Verify authentication code with the prompt Enter the 6-digit code from your authenticator app.
  4. Open your authenticator app and read the current 6-digit code for the Retrievy entry. Type it into the Enter 6-digit Code OTP input.
  5. Click Verify & Activate. If the code is correct, the modal closes and the card flips to its enabled state. Use Back to return to the QR-code screen, or close the modal to abort.

The 6-digit code is time-based and rolls over every 30 seconds. If the modal rejects the code, wait for your authenticator to refresh and try the new value. Retrievy rate-limits 2FA attempts to 5 per minute per session.

Store your recovery codes

Right after 2FA is enabled, a panel appears under the card titled IDENTITY RECOVERY TOKENS with the description Recovery codes let you regain access if you lose your 2FA device. Store them in a secure password manager.

  1. Click View recovery codes. The 8 codes render in a two-column grid in monospaced text. Each code is single-use.
  2. Copy all 8 codes into your password manager. Save them under the same entry as your Retrievy login. Do not store them in the same place as your authenticator app (defeats the purpose).
  3. Click Hide recovery codes when done.

If you ever burn through codes (lost device, used them up logging in), open the same panel and click Regenerate codes. The button is only visible while the codes are revealed. Regenerating instantly invalidates every previous code, so update your password manager immediately after.

Recovery codes are the only way back in

If you lose your authenticator device and you do not have recovery codes saved, your workspace admin cannot reset your 2FA from inside Retrievy. The only path back is contacting Retrievy support, who will require additional identity verification. Save the codes when you enable 2FA, not later.

Sign in with 2FA enabled

Next time you log in, after the email and password step, Retrievy shows the Two-factor challenge screen. Enter the 6-digit code from your authenticator. To use a recovery code instead, click the use a recovery code link, paste an unused recovery code, and submit. That code is then burned.

Disable 2FA

  1. On Settings → Account → Security, click Disable 2FA in the top-right of the Two-factor authentication card.
  2. The card flips back to its disabled state immediately. The QR-code secret and all recovery codes are deleted.

You can re-enable 2FA at any time. Re-enabling generates a new QR-code secret and a new set of recovery codes (any old codes you might still have on paper are invalid).

caution

Disabling 2FA removes a real layer of protection on your account. If your password has been compromised and you disable 2FA, the attacker can log in immediately. Only disable when you are about to re-enroll on a new device.

What about administrators resetting someone's 2FA?

Retrievy does not expose a tenant-admin "reset 2FA for this user" action today. If a teammate is locked out and has no recovery codes, the path is:

  1. Have them use a recovery code from their password manager if available.
  2. If no codes remain, contact Retrievy support from the workspace owner's email address with the locked-out user's identity. Support will verify and reset out-of-band.

A dedicated admin reset is on the roadmap.

How this affects your Retrievy Index

Profile and 2FA settings do not affect your Retrievy Index. They sit alongside the security posture work, not inside it. The index measures the security of the cloud and infrastructure you connect to Retrievy, not the security of individual Retrievy logins.

Enforcing 2FA on every Retrievy user is a baseline control your auditors will look for. Track adoption through your own identity provider, or through the Audit Trail. Retrievy records an entry every time a user enables or disables 2FA, with the actor, source IP, and timestamp captured on the row.

Troubleshooting

Symptom: The verification email never arrived. Fix: Check spam. If still missing, confirm the address on the profile is the one you actually receive mail at, click Resend verification email again, and wait up to 2 minutes. If your tenant uses a custom SMTP, ask your workspace admin to check the mail logs.

Symptom: Rotate Password returns The password has appeared in a data leak. Fix: Pick a different password. Retrievy checks new passwords against the HaveIBeenPwned breach corpus and rejects anything that has ever leaked publicly. This check is a non-negotiable production safeguard.

Symptom: The 6-digit code from my authenticator app is always rejected. Fix: Check your phone's clock. TOTP codes are time-based, so a clock that drifts by more than 30 seconds invalidates every code. Enable automatic time sync in your phone's settings, then try again. If your authenticator app has its own time-sync setting (Google Authenticator: Settings → Time correction for codes), use it.

Symptom: I lost my phone and never saved my recovery codes. Fix: Contact Retrievy support from your verified workspace email. Support will verify your identity out-of-band and reset 2FA on the account. There is no in-app self-service path without recovery codes.

Symptom: I clicked Enable 2FA but the modal shows Failed to fetch setup data. Fix: Close the modal and reopen it. The QR-code generation occasionally fails on slow connections. If it fails repeatedly, log out, log back in, and try again. If still broken, contact support.

Symptom: I changed my email and now my SSO login does not work. Fix: SSO is keyed on the email returned by Google or Microsoft, not the email on your Retrievy profile. Changing your Retrievy email does not migrate your SSO link. If you need to change the SSO email, contact your workspace admin to remove and reinvite you on the new address.