
1. In short
Two-step authentication adds a second layer of protection when signing in to the platform: after the username and password, the user enters a 6-digit code generated by an authenticator app on the phone (Google Authenticator, Microsoft Authenticator or any compatible app) or received by e-mail. Even if the password reaches an unauthorised person, they cannot get into the account without the code. The code is only requested on new devices — a device can be marked as "trusted" for 30 days. The feature is optional and is enabled individually, by each user, from their own account; it can be used by Administrator and Employee users, as well as by client portal users.
2. Where to find it
- the user menu → Account → My Account → the Security card
- in the client portal: the user icon in the top bar → the Security option
- → edit the employee → the Access section → the Reset 2FA button (for administrators)
- Clients → the client record → the Account tab → the Reset 2FA button (for administrators)
- → the Notification section (the three new templates)
- → the Module filter → Users
3. Before you start
- For the app method you need an authenticator app installed on your phone (Google Authenticator, Microsoft Authenticator or any compatible app).
- For the e-mail method, the account must have a valid e-mail address; otherwise the option is unavailable.
- API accounts do not have this option. There is no company-level setting that can enforce it on all users.
- For the administrator reset you need the edit permission in the Employees module (the Financial category).
4. Enabling it from your own account, with an authenticator app
Step 1. Open the user menu and choose . Find the Security card, which holds the Two-step authentication switch, off by default.

Step 2. Turn on the Two-step authentication switch. Below the switch, in the same card, the steps of the setup wizard appear.
Note: if you turn the switch off or press Cancel during setup, you give up the setup and nothing is saved.
Step 3. At the Choose the method step, pick Authenticator app (marked Recommended; the codes are generated by the app on your phone, without depending on e-mail).

Step 4. Press Continue. The Scan the QR code step shows the QR code and, below it, the secret in text form (Or enter the secret manually).
Step 5. Scan the QR code with the authenticator app or enter the displayed secret manually. In the app, the account appears with the issuer "iFlows" and the username you sign in with.

Step 6. Fill in the Verification code field with the 6-digit code shown by the app.
| Field | What you fill in | Required |
|---|---|---|
| Verification code | the 6-digit code from the authenticator app | Yes |
Step 7. Press Verify. The code in the app changes every 30 seconds; the immediately previous or next code is also accepted.
Note: the setup wizard expires after 30 minutes ("The activation session has expired. Start the setup again.").
Step 8. At the Backup codes step, the platform shows 10 backup codes (XXXX-XXXX format), only once ("Save these codes. They are shown only once."). Each code can be used a single time, instead of the code from the app or from e-mail — for example if the phone is lost. Save the codes with Copy (to the clipboard) or Download (text file).
Step 9. Press I have saved the codes. Two-step authentication becomes active. You receive the "2FA security notification" e-mail (with the date and IP address of the action), and the "2FA enabled" event is recorded in the Activity Log.
Warning: two-step authentication only becomes active after you press the I have saved the codes button. If the page is closed before that, the setup does not stay active and has to be started from scratch.
5. Enabling it with a code by e-mail
The differences from enabling it with an app
Step 1. At the Choose the method step, pick Code by e-mail. The code will be sent to the account e-mail address (for example contact@clientdemo.com).
Note: the option is unavailable if the e-mail address is missing or invalid ("The e-mail method requires a valid e-mail address on the account.").
Step 2. Press Continue. The platform immediately sends an e-mail with the activation code; the QR code step does not appear for this method.
Step 3. Fill in the Verification code field with the 6-digit code received by e-mail. If you did not receive the code, press Resend code (available at the earliest after 30 seconds, with a counter shown).
Step 4. Press Verify. The e-mail code is valid for 10 minutes; a new code cancels the old one, and after 5 wrong entries that code becomes unusable and has to be resent.
Step 5. Continue with the Backup codes step, identical to steps 8–9 of the app setup.
6. Managing it from the account, after enabling
Step 1. Open → the Security card. With the feature active, the card shows the Active method (Authenticator app or E-mail), Enabled on (date and time) and Backup codes left, as well as the Change method and Regenerate backup codes actions.
Step 2. Choose the action you need:
- Change method — switches from app to e-mail or the other way round. After confirmation you go through the Choose the method, setup and verification steps again; right after Verify the new method becomes active, without the backup codes screen — the existing codes stay valid (no new ones are generated). Until it is finished, the old method stays active.
- Regenerate backup codes — replaces all the codes (used or not) with 10 new ones, shown on the same screen as when enabling.
- turning the Two-step authentication switch off — completely disables the feature (the method, the secret and the backup codes are deleted). You receive the "2FA disabled" e-mail.
Step 3. In the Confirm with password and code section, which appears in the card for any of the three actions, fill in the fields below.
| Field | What you fill in | Required |
|---|---|---|
| Current password | the account password | Yes |
| Authentication code | the code from the app, the code received by e-mail (sent automatically when the section is opened, for the e-mail method — "We have sent a 6-digit code by e-mail. You can also use a backup code.", with the Resend code button and a 30-second counter) or a backup code | Yes |
Step 4. Press the action button: Disable (when turning the switch off), Regenerate or Continue (when changing the method); with Cancel you give up. The chosen action runs; when changing the method or regenerating the codes you receive the "2FA security notification" e-mail, and the matching event appears in the log ("2FA method changed", "2FA codes regenerated" or "2FA disabled").
Note: after 5 failed attempts (password or code) in 5 minutes, the security operations are blocked temporarily ("Too many attempts. Try again in a few minutes."). The counter is cleared on a successful verification.
7. Signing in with two-step authentication
Step 1. Enter the username and password on the sign-in page, as usual. If the feature is active on the account, you automatically land on the Two-step authentication page. Until the correct code is entered you are not signed in and cannot access any page.
Step 2. Fill in the Authentication code field.
| Field | What you fill in | Required |
|---|---|---|
| Authentication code | the code from the app, the code by e-mail (sent automatically when the page opens, for the e-mail method) or a backup code (also accepted without the hyphen or with lowercase letters) | Yes |
| Remember this device for 30 days | checkbox, unticked by default; if you tick it, the code is no longer requested on that browser for 30 days | No |
Note: for the e-mail method, the Resend code button sends a new code, with a 30-second counter between sends.
Step 3. Press Continue. The code is verified and you are signed in. With Back to sign in you return to the sign-in page.
Note: the verification page is valid for 5 minutes from the moment the password was entered; after it expires you are sent back to the sign-in page. After 5 wrong codes in 5 minutes, signing in is blocked temporarily ("Too many attempts. Try again in a few minutes.").
8. Reset by an administrator
Use this procedure when a user no longer has access to the authenticator app, to the e-mail or to the backup codes. After the reset, the user signs in with the password only and can enable the feature again themselves.
For an employee
Step 1. Open and go into editing the employee (for example John Smith).
Step 2. In the Access section, find the Two-step authentication row and press the Reset 2FA button. The row only appears if the employee has the feature active and has an activated iflows Account.
Step 3. In the Warning! window ("Are you sure you want to reset two-step authentication?") press Reset 2FA (or Close to give up). The enrolment is deleted, the targeted user receives the "2FA disabled" e-mail, and "2FA reset by admin" appears in the administrator's log.
For a client portal user
Step 1. Open Clients and the client record (for example Demo Client SRL).
Step 2. Open the Account tab and press the Reset 2FA button, shown in the row of buttons below the form (on the right, next to Delete) only if that user has the feature active.
Step 3. Confirm with Reset 2FA in the same Warning! window. The effects are the same as for employees.
Note: the employee list has no column for the two-step authentication state; the only indicator is the presence of the Reset 2FA button in the edit form.
9. The e-mail templates and the log
Step 1. Open . In the Notification section three new system templates appear:
- Two-step authentication code — the 6-digit code, valid for 10 minutes;
- 2FA security notification — enabling, method change, code regeneration, with the date and IP address;
- 2FA disabled — disabling by the user or a reset by an administrator.
Note: the templates are locked — the name, subject, sender and content cannot be changed, they cannot be archived, deleted or cloned, and the Bcc field must stay empty ("Bcc is not allowed for two-step authentication templates."). The variants in other languages are picked automatically based on the user's language. In the template editor the new variables User First Name, Authentication Code, Request Date and Time, IP Address, Security Action and Authentication Method are available.
Step 2. Open and pick the new Users option in the Module filter; in the Action filter the options 2FA enabled, 2FA disabled, 2FA method changed, 2FA codes regenerated and 2FA reset by admin are available.
Note: the events also appear in the Recent Activity card in Reports.
10. What you see afterwards
- In the Security card in My Account: the switch on, the Active method, Enabled on and Backup codes left, with the Change method and Regenerate backup codes actions.
- When signing in on a new device: the Two-step authentication page, after the password is entered.
- E-mails received: "2FA security notification" (on enabling, method change, code regeneration) and "2FA disabled" (on disabling or a reset by an administrator).
- , the Users module: the events "2FA enabled", "2FA disabled", "2FA method changed", "2FA codes regenerated", "2FA reset by admin"; the same events also appear in the Recent Activity card in Reports.
- In the Sign-in History, the entry is recorded only after the correct code is entered.
11. Rules and limits
- Enabling is individual, from each user's own account (Administrator, Employee or portal user). API accounts cannot have two-step authentication. There is no company setting that can enforce it on everyone.
- Two-step authentication only becomes active after the I have saved the codes button is pressed; if the wizard is closed before that, the setup starts from scratch. The setup wizard expires after 30 minutes.
- The code in the app changes every 30 seconds; the immediately previous or next code is also accepted. A code from the app cannot be reused.
- The e-mail code is valid for 10 minutes; a new code cancels the old one; after 5 wrong entries the code becomes unusable and has to be resent. The minimum interval between resends is 30 seconds.
- Backup codes: 10 codes of 8 characters (XXXX-XXXX format), each single use; shown only once; they stay valid when the method is changed; on regeneration all of them are replaced.
- After 5 failed attempts (code or password) in 5 minutes, signing in or the security operations are blocked temporarily. The counter is cleared on a successful verification.
- The verification page at sign-in is valid for 5 minutes from the moment the password was entered; after it expires the user is sent back to the sign-in page.
- The "trusted" device (30 days) automatically loses its validity when: the password is changed, two-step authentication is disabled or reset, and the method is changed. Signing out and regenerating the backup codes do not affect it.
- If the account has been deactivated in the meantime, the code verification is refused.
- If the e-mail with the code cannot be sent (invalid address), the verification page shows a warning and recommends using a backup code or contacting an administrator.
- The e-mail method is unavailable without a valid e-mail address on the account.
- The reset by an administrator deletes the enrolment.
Fixed values
| Parameter | Value |
|---|---|
| Wrong attempts allowed | 5 in 5 minutes (code or password) |
| Minimum interval between e-mail code resends | 30 seconds |
| Validity of the e-mail code | 10 minutes, maximum 5 wrong entries |
| Backup codes | 10 codes of 8 characters, each single use |
| Validity of the verification page at sign-in | 5 minutes |
| Validity of the setup wizard | 30 minutes |
| Trusted device | 30 days |
12. Settings and permissions
There are no new settings in the platform interface: enabling is individual, from each user's account.
- enabling, changing the method, regenerating the codes and disabling — any Administrator, Employee or Client user, only for their own account;
- Reset 2FA (employees and portal users) — the edit permission in the Employees module (the Financial category); administrators have access by default.
13. Impact on other modules
- Authentication: signing in has two stages; the entry in the Sign-in History is recorded only after the correct code. The sign-in page of the technical administration panel also goes through the platform.
- API: unaffected — API accounts cannot have two-step authentication.
- Employees: the "eye" icon in the employee list now opens a full details page (with the Back, Edit, Deactivate/Delete buttons), instead of the window used until now.
- Client portal: the user icon in the top bar becomes a menu, with the new Security option.
- E-mail templates: three new locked system templates, and six new variables in the editor.
- Activity Log / Reports: the Users module and the five 2FA actions; the events also appear in the Recent Activity card.
