Who must have it
- It is mandatory for the Approver and Reviewer roles. If a user with one of these roles has not enabled it, the app forcibly redirects them to a setup screen before letting them use the rest of the system.
- For everyone else, including Generator, it is optional but recommended.
How to set it up
You set it up with an authenticator app such as Google Authenticator:
1. Scan a QR code, or enter a key manually.
2. Confirm with a 6-digit code.
3. The recovery codes are displayed — store them somewhere safe. They let you get in if you lose the device with the authenticator.
At every login
If 2FA is active, you are asked for the 6-digit code or, alternatively, a recovery code in the XXXX-XXXX format. Limit of 5 attempts per minute.
When approving transfers
A 6-digit code is required when approving (Approver) or forwarding/reviewing (Reviewer) a transfer.
Managing it from your profile
From My Profile → Security you can enable, confirm or disable 2FA, and regenerate or view your recovery codes again. All of these actions ask you to re-confirm your password.
If you lost access to your authenticator app, use one of your recovery codes. If you do not have those either, contact support.