Integrity
AdministrationAccount

Account Settings

Manage your profile identity, email, connected sign-in accounts, password, and security settings

Access your account settings by clicking your avatar in the top-right corner of the page and selecting Settings. This opens account settings with the Account tab selected by default.

Use Preferences for account-wide behavior defaults such as home routing, calendar week start, theme, and Issue workflow defaults. Use Notifications for Inbox and email delivery preferences.

Sign-in Methods

Integrity supports multiple ways to sign in to your account:

MethodDescription
Email & PasswordTraditional sign-in with your email address and a password you create
GoogleSign in using your Google account
GitHubSign in using your GitHub account
PasskeySign in with Touch ID, Windows Hello, a device PIN, or a security key after you add a passkey to your account

Your original sign-in method is determined when you first create your account. If passkeys are enabled for your workspace environment, you can add a passkey later for faster sign-in.

OAuth Sign-in (Google/GitHub)

If you signed up using Google or GitHub:

  • Your sign-in is managed by that provider
  • You do not have a separate password in Integrity
  • To change your password, visit your Google or GitHub account settings
  • Your account is automatically linked to your provider's email address

The Connected accounts settings page shows supported OAuth sign-in providers for your account. Provider action buttons are disabled for now.

Email & Password Sign-in

If you signed up with email and password:

  • You manage your password directly in Integrity
  • You can reset your password from the account settings or sign-in page

Password Management

For Email & Password Users

You can reset your password at any time:

  1. Open User Settings (click your avatar -> Settings)
  2. In the Account Security section, click Reset Password
  3. Check your email for the reset link
  4. Click the link to open the password reset page
  5. If you have 2FA enabled, enter your verification code from your authenticator app
  6. Enter your new password

If you have two-factor authentication enabled, you need to verify your identity with your authenticator app before changing your password. This ensures only you can reset your password, even if someone gains access to your email. After your password changes, other active sessions for your account must reauthenticate.

Password requirements:

  • Minimum 8 characters
  • At least one uppercase letter
  • At least one lowercase letter
  • At least one number
  • At least one special character

For OAuth Users (Google/GitHub)

If you signed in with Google or GitHub, you see:

  • Password: "Sign-in managed by [Provider]"
  • No password set indicator

To change how you sign in, manage your credentials through your OAuth provider:

Active Sessions

The Security & access settings page shows the browser sessions currently associated with your account.

An active browser session remains available for up to seven days without activity. Using Integrity renews that idle window, subject to the session's existing 30-day maximum lifetime and any security-sensitive action that requires reauthentication.

  • The current-session card shows your browser, operating system, approximate location, and last-seen time.
  • Other active sessions appear in a separate list with a count such as 2 other sessions.
  • Session details are hidden by default. Opening a row shows display-safe metadata such as device, masked IP address, last location, and original sign-in date. Integrity does not show tokens, secrets, raw IP addresses, or raw user agents in this surface.
  • Use Revoke Access in a session dialog for a session you do not recognize, or Revoke all to end every other active session while keeping your current session signed in.

Revoked sessions must reauthenticate before they can open protected workspace, Team, Module, artefact, review, baseline, or settings data again. When the revoked browser is online and connected to realtime updates, it is prompted to leave the app immediately; if the browser is asleep, offline, or disconnected, the next focus, refresh, or protected navigation enforces the same reauthentication check. Revoking one session targets that browser session and does not intentionally sign out every browser where the account is active.

Security-sensitive account changes use the same protection. Password changes, confirmed email changes, connected account removal, enabling or disabling 2FA, regenerating recovery codes, and using a recovery code require other active sessions to reauthenticate while keeping your current completion flow intact.

Integrity may also ask you to sign in again after inactivity or a long-running session. Repeated failed password sign-in attempts pause briefly and recover automatically; the sign-in page shows retry guidance without revealing whether a specific email address belongs to an account.

Passkeys

Passkeys let you sign in without typing your password. Depending on your device, the browser may ask for Touch ID, Face ID, Windows Hello, a device PIN, or a hardware security key.

You can manage passkeys from User Settings -> Account -> Account Security:

  1. Complete two-factor authentication for the current session if prompted
  2. Add a passkey and approve the browser prompt
  3. Rename a passkey so you can recognize the device or authenticator
  4. Delete passkeys you no longer use

A passkey is a faster sign-in credential, not a replacement for required two-factor authentication. After signing in with a passkey, Integrity still checks whether your session has completed the required 2FA step before allowing protected app access.

If you skip the passkey prompt during onboarding, you can add one later from Account Security. Password, Google, GitHub, and SSO sign-in options remain available where they apply to your account.

Profile Settings

Profile settings control how your account appears across every workspace where you are a member. Profile changes do not grant workspace, Team, Module, or restricted object access.

Generated Avatar

Integrity uses generated avatars in V1. Uploaded profile photos and external avatar URLs are not supported.

To customize your avatar:

  1. Open User Settings (click your avatar -> Settings)
  2. Choose Profile
  3. Click your current avatar or Create your portrait
  4. Customize your avatar's features
  5. Click Save to apply changes

Your avatar appears in:

  • The sidebar
  • Comments and activity feeds
  • Team member lists
  • Workspace member directories

Name, Title, Timezone, and Username

Your display name appears throughout Integrity when you comment, change records, or collaborate with teammates. You can update your full name, title, timezone, and username from Profile.

The username is a display alias only:

  • It does not need to be unique
  • It is not used for login
  • It is not used in routes, permissions, audit identity, invites, or mentions

To update profile fields:

  1. Open User Settings (click your avatar -> Settings)
  2. Choose Profile
  3. Edit the field
  4. Save the row

Email Address

Email is your account's global sign-in identity. You can start a self-service email change from Profile.

Email changes require:

  • Recent verification with your current password or authenticator code when required
  • Confirmation from your current inbox
  • Confirmation from the new inbox

Your profile email updates only after both confirmation links are accepted.

After the email change is confirmed, other active sessions for your account must reauthenticate before they can open protected app data again.

If you cannot access your current inbox, contact support. The self-service flow cannot bypass old-email confirmation.

Connected Accounts

Connected accounts show OAuth sign-in provider identities for your account. V1 covers sign-in providers only, such as Google and GitHub. It does not manage third-party integrations, API tokens, or authorized applications.

From Security & access > Connected accounts you can:

  • See connected OAuth sign-in identities
  • See supported provider rows for Google, GitHub, and Microsoft
  • View provider action buttons in a disabled state until account linking is enabled for this surface

If provider linking is enabled later and your account has two-factor authentication enabled, Integrity may ask you to complete the MFA challenge before connecting or disconnecting a provider.

Disconnecting a connected sign-in provider is treated as a security-sensitive change. If provider unlinking is enabled later, other active sessions must reauthenticate after the unlink completes.

Leave Workspace

From Profile, you can leave the current workspace. Leaving a workspace removes your active access to that workspace, including its Teams, Modules, artefacts, reviews, and settings. Historical activity remains preserved for audit history.

You cannot leave if you are the last owner. Add or transfer ownership to another owner before leaving.

Two-Factor Authentication

Two-factor authentication (2FA) adds an extra layer of security to your account. When enabled, you need a verification code from your authenticator app in addition to your sign-in method.

2FA is required for all Integrity accounts, regardless of how you sign in.

For detailed setup instructions, see Two-Factor Authentication.

FAQ

On this page