Documentation
Tutorials
Workflows
Kebab actions
Daily Work
Dashboard & Reports
Quality Control
ISO 17025
Logs
Contacts
Billing
Analysis Setup
Settings
Initial Setup
Help & Reference
Architecture decisions
Initial Setup
0:000:00

Login & Security (MFA)

This guide covers logging into the system, setting up two-factor authentication (MFA) and configuring security settings. Data security is a core requirement of ISO 17025 (§8.4).


Login

  1. Enter your email and password
  2. If MFA is enabled, a 6-digit code field appears — it auto-submits once 6 digits are entered
  3. After login, the system checks if your password has expired or if MFA setup is required
If your password has expired, you will be prompted to change it before continuing.

MFA Setup

MFA (Multi-Factor Authentication) adds a second layer of security. It uses an authenticator app (Google Authenticator, Authy, Microsoft Authenticator).

Enabling MFA

  1. Click the shield icon in the navigation bar
  2. A QR code appears — scan it with your authenticator app
  3. If you can't scan, use the manual entry key shown below the QR code
  4. Enter the 6-digit code from the app to verify
  5. MFA is now active for every future login

Disabling MFA

  1. Click the shield icon again
  2. Enter your current 6-digit code to confirm
  3. MFA is disabled
For accredited laboratories, enabling MFA for all users is recommended.

Security Settings

Go to Settings → Security (Lab Directors only).

Passwords & Login

SettingDescription
Minimum password lengthMinimum number of characters
Password expiry (days)Days until password expires (0 = no expiry)
Session timeout (minutes)Auto-logout after inactivity (0 = disabled)
Max failed login attemptsFailed logins before account lockout
Lockout duration (minutes)How long the account stays locked

Authentication

SettingDescription
Mandatory MFAAll users must enable an authenticator app
MFA reminderShows a reminder at login if MFA is not enabled
E-signature on approvalRequires password re-entry when approving an analysis

Audit Trail

SettingDescription
Audit log retention (days)How long audit records are kept (0 = forever)

FAQ

What if I lose access to my authenticator app?

A Lab Director can reset a user's MFA from the Users page. After reset, the user must set up MFA again.

How do I unlock a locked account?

The account unlocks automatically after the lockout duration. A Lab Director can also unlock it manually.

Why am I asked for my password when approving an analysis?

If "E-signature on approval" is enabled, password re-entry is required as an electronic signature — an ISO 17025 requirement.