Account & security
Turn on two-factor authentication, set your theme and timezone, review your sign-in history, and read the workspace audit log.
Your account settings control how Sangria looks and behaves for you, and give you a record of how your account is being accessed. Admins get an additional workspace-wide security record — the audit log.
Theme
Choose your theme to match how you like to work. Your theme is set per workspace, so you can use a different look in each one — a light theme where you work in daylight and a dark theme in a workspace you check late at night, for example. Changing it in one workspace leaves the others as they were.
Timezone
Your timezone is auto-detected when you sign in, and it's used to show times throughout Sangria correctly for you. Most people never touch it. If it's ever wrong — you're traveling, or you sign in from a different region — you can edit it so timestamps and scheduling line up with where you actually are.
Notification settings
Notification preferences live with the rest of your account settings. Rather than duplicate the list here, the full set of what you can tune — and where each control lives — is documented in one place. See Notifications.
Sign-in history
Review your recent sign-ins to spot anything you don't recognize. Each entry shows:
- Method — Google, GitHub, or password.
- Device — the browser or app used.
- IP address — where the sign-in came from.
- Approximate location — derived from the IP address.
Failed sign-in attempts on your account are recorded too, so you can tell if someone is trying to get in.
See something you don't recognize?
If a sign-in or a failed attempt doesn't look like you, change your password and let a workspace admin know.
Two-factor authentication
Add a second step at sign-in so a stolen password alone isn't enough to get into your account. Sangria uses time-based one-time codes (TOTP) from an authenticator app — Google Authenticator, 1Password, Authy, and most password managers work. (Prefer no codes at all? See Passkeys to sign in with your fingerprint or face instead of a password.)
Turn it on
- Go to Account → Settings → Two-factor authentication and choose Enable.
- Scan the QR code with your authenticator app (or type the key in by hand).
- Enter the 6-digit code the app shows to confirm, then save your recovery codes.
Recovery codes
Enabling 2FA gives you a set of one-time recovery codes. Save them somewhere safe — each one works once to get in if you lose your authenticator. You can generate a fresh set anytime from the same screen (which replaces the old ones); you'll need a current code to do it.
Save your recovery codes
They're shown only once. Without them, losing your authenticator can lock you out — a workspace admin would have to reset your 2FA.
Signing in with 2FA on
After your password, you'll be asked for the current 6-digit code before you're let in. Lost your device? Choose Use a recovery code instead.
Workspaces that require 2FA
An admin can make 2FA required for a workspace (see Workspaces). If you open a workspace that requires it and haven't set up 2FA yet, you'll be prompted to set it up before you can continue.
Turning it off
From the same screen you can turn off 2FA. You'll need a current code to confirm, so nobody on an unattended session can quietly remove it.
Locked out?
If you lose your authenticator and your recovery codes, a workspace admin can reset your two-factor from Members management — that clears it from your account so you can set it up fresh next time you sign in. Contact an admin to do this. Admins: the action lives in the ⋯ menu next to a member (and shows for any member who has 2FA on, including the primary owner); it's recorded in the audit log. (Passkeys are a separate sign-in method, not 2FA — a reset leaves them alone.)
Passkeys
A passkey lets you sign in with your device's fingerprint, face, PIN, or a hardware security key — no password to type. It's stored on your device and never leaves it, which also makes it resistant to phishing.
Add a passkey
Go to Account → Settings → Passkeys and choose Add a passkey. For your security you'll first confirm it's you — your password, or a code from your authenticator app if you use one — since a passkey is a way into your account. Then your browser or device prompts you to create it, and it's saved. Add one per device you sign in from; each is listed with when it was added and last used, and you can rename or remove any of them.
Register on more than one device
A passkey is tied to the device that created it. Add one on each device you use (and keep your email-and-password sign-in as a fallback) so losing a single device doesn't lock you out — there are no recovery codes for passkeys.
Sign in with a passkey
On the sign-in screen, choose Sign in with a passkey and confirm on your device — no email or password needed. Because unlocking the passkey already proves it's you (fingerprint / face / PIN), signing in this way goes straight through, even in a workspace that requires two-factor authentication.
Remove a passkey
Remove a passkey from Account → Settings → Passkeys — on a lost or shared device, for instance. Removing your last passkey just means you sign in with your email and password (or Google / GitHub) as usual.
Audit log
Admins get a workspace-level audit log — a record of security- and admin-relevant actions across the workspace. It captures:
- Workspace, permission, and ownership changes.
- Member changes — role changes, removals, reactivations, and 2FA resets.
- Channel create, update, and delete.
- Admin message edits and deletes.
- Integration changes.
Each entry shows who did it, the target of the action, and when it happened. Names are captured at the time of the action, so old entries still read correctly even after someone is renamed or leaves the workspace — an entry keeps the name as it was when the action took place, rather than showing a blank or a stale reference later on. That makes the log dependable for after-the-fact review.