Skip to content

Users, roles & 2FA

Managing who can sign in to the dashboard, what they can do, and securing those accounts.

Where you do this: Cloud dashboard — kilasec.com/app/. Users & Roles for people; Settings → Two-factor authentication for your own 2FA. Inviting and role changes require the tenant_admin role; enrolling your own 2FA is available to any signed-in user.

Roles

RoleCan do
memberview the workspace
tenant_adminmanage policy, collectors, approvals, and users

Roles are set on Users & Roles by a tenant_admin, not self-selected.

Inviting people

Dashboard → Users & Roles. Access is account-based — there's no open signup. Add a teammate by email and pick their role; they set their own password on first sign-in and join your workspace. See Add a teammate. Change a role or disable an account from the same page at any time.

Two-factor authentication (2FA)

Kilasec supports authenticator-app 2FA (TOTP) with one-time recovery codes.

EnrollingDashboard → Settings → Two-factor authentication → Set up 2FA. Scan the QR with any authenticator app (Google Authenticator, 1Password, Authy) or enter the key manually, then confirm with a code. You're shown recovery codes once — save them; each works one time if you lose your authenticator.

Signing in with 2FA — after your password, you're prompted for the 6-digit code (or a recovery code). The password step alone does not create a session on a 2FA account.

Turning it off — requires re-entering your password, so a hijacked session can't silently strip the second factor.

We recommend every admin enrolls — the account holds control over your policy and fleet.

Changing a login email

Login email can be changed without disturbing the password or 2FA (they're keyed to the account, not the address). If you need to change the address on an account, contact Kilasec.

Documentation for kilasec — the AI Agent Firewall.