Help Center/Workspaces, Team & White-label/Security: two-factor authentication, sessions and audit logs
Open OutreachFox →

Security: two-factor authentication, sessions and audit logs

Your OutreachFox account holds connected mailboxes, lead data and API keys, so it is worth locking down. This article covers turning on two-factor authentication (2FA), reviewing and ending session…

Draft — written from product facts + domain knowledge; UI labels to be verified before publishing.

Your OutreachFox account holds connected mailboxes, lead data and API keys, so it is worth locking down. This article covers turning on two-factor authentication (2FA), reviewing and ending sessions, and reading the audit log to see who changed what.

Two-factor authentication

2FA adds a six-digit code from an authenticator app to every login. It is per user, not per workspace. Owners can require it for everyone in a workspace.

Steps: enable 2FA for your account

  1. Click your avatar at the bottom-left, then Account settings → Security.
  2. Click Enable two-factor authentication.
  3. Scan the QR code with an authenticator app (Google Authenticator, Authy, 1Password, Microsoft Authenticator) or enter the setup key manually.
  4. Enter the six-digit code the app shows and click Verify.
  5. Download or copy the ten Recovery codes and store them somewhere safe. Each code works once and is the only way in if you lose your phone.
  6. Click Done.

From the next login you enter your password, then the code.

Steps: require 2FA for the workspace

  1. As Owner, open Settings → Security.
  2. Turn on Require two-factor authentication for all members.
  3. Click Save. Members without 2FA are prompted to set it up at their next login and cannot use the workspace until they do. Client viewers are included.

Recovering access

If you lose your authenticator, log in with a recovery code, then go to Account settings → Security, click Reset two-factor authentication and set it up again. If you have no recovery codes, the workspace Owner can click Reset 2FA next to your name in Settings → Team; you then set it up afresh at next login.

Sessions

Every browser and device you log in from creates a session. Sessions expire after 30 days of inactivity, or immediately when you change your password.

Steps: review and end sessions

  1. Open Account settings → Security → Sessions.
  2. Each row shows device, browser, approximate location, IP address and last activity. Your current session is marked.
  3. Click Log out next to a session you do not recognise, or Log out all other sessions to keep only the current one.
  4. Change your password straight afterwards if any session looked unfamiliar.

Owners and Admins can end another member's sessions from Settings → Team → three dots → Log out everywhere, which is the right first step when someone leaves the company.

Audit log

The audit log records security-relevant and destructive actions in the workspace for 12 months. Owners and Admins can read it.

Steps: read the audit log

  1. Open Settings → Security → Audit log.
  2. Filter by Actor, Action or Date range.
  3. Click a row to see details, including the previous and new value where relevant.
  4. Click Export CSV to download the filtered view.

Logged actions include: login and failed login, 2FA enabled or reset, member invited, role changed, member removed, ownership transferred, API key created or revoked, webhook added or changed, mailbox connected, deleted or moved, campaign deleted, contacts exported, contacts deleted, billing changes and workspace deletion requests.

Tips

  • Turn on Require two-factor authentication before inviting any client viewers.
  • Rotate API keys when a member with Admin access leaves; keys are not tied to the person who created them.
  • Check the audit log weekly for Contacts exported and API key created events you did not expect.
  • Use a password manager and a unique password; OutreachFox does not support SMS codes, so an authenticator app is required.

Troubleshooting

  • Code rejected: the phone's clock is out of sync. Enable automatic time in the phone settings and retry.
  • Locked out with no recovery codes and no Owner available: contact support from the email address on the account; identity verification takes one business day.
  • Audit log missing an event: only actions listed above are recorded. Routine edits such as changing email copy are not.

Related articles

  • Create workspaces, invite members and set roles
  • Transfer workspace ownership and move mailboxes between workspaces
  • API keys and authentication
  • Export your account data
  • Delete your account and GDPR requests

Was this helpful?

More in Workspaces, Team & White-label