2FA confirmation when changing permissions
Every change to a user, role, or permission requires fresh confirmation with a code. The window lasts 15 minutes and expires when you switch companies.
Changes to users and roles are high-risk operations. Every one requires fresh confirmation with a 2FA code, regardless of your permissions.
Step by step
Complete the confirmation
- Save the change as usual — Update role, Save roles, Delete, and so on.
- Instead of saving, the 2FA verification required window opens with the subtitle This action is sensitive — confirm your identity with a code from your authenticator app and a blue notice: After verification, we will not ask you again for the next 15 minutes.
- Enter the six-digit code from your authenticator app in Verification code.
- Click Confirm or press Enter in the code field.
- The window disappears and the operation runs automatically. Do not click save a second time — the system repeats your request for you.
An incorrect code stays in the window and highlights the field with Invalid code. Correct it and click Confirm again.
Cancel closes the window and abandons the operation. You will not see an error message — the change simply was not saved.
If you do not have 2FA yet
- Instead of a code prompt, you will see Two-factor verification required, with the subtitle This action is sensitive — enable 2FA on your account before performing it.
- Click Go to 2FA settings. The system takes you to your account settings, on the Security tab.
- Enable 2FA (Two-factor authentication (2FA) — enabling it, backup codes, and disabling it), return to the previous screen, and repeat the action from the beginning — an unfinished save does not wait for you.
Check where 2FA is required
- Open your account settings from the avatar in the upper-right corner and go to the Security tab.
- In the Two-factor authentication (2FA) section, click Where is 2FA required?
- A list expands, preceded by: After you enable 2FA, the following actions require a fresh code (the step-up session is valid for 15 minutes): — it covers user and role management, company data and integration keys, sync schedules, and more.
- Collapse the list with the same button, whose label changes to Hide list.
The list is maintained alongside the code. If you need to know whether an operation will ask for a code, this is the first place to check.
What it looks like
You save a change and the system opens a dialog asking for a code. After you enter it, the operation runs automatically — you do not need to click save again.
If 2FA is not enabled yet, you will be taken to the security settings to enable it instead (Two-factor authentication (2FA) — enabling it, backup codes, and disabling it).
The confirmation window lasts 15 minutes
After one confirmation, subsequent operations within 15 minutes do not ask for a code. During a longer configuration session, the system will ask again — this is not a fault.
The window expires when you switch companies
Remember this because it can be surprising: switching the active company clears the confirmation. You configured roles in company A, switched to B — the first change in B will ask for a code again.
The confirmation also expires when you sign out or disable 2FA.
Reading never asks for a code
Viewing user lists, roles, login history, statistics, and the field catalogue never requires a code. Only saving does.
An API token cannot change permissions
A hard rule: a personal access token cannot perform any of these operations. A scanner or script cannot take over your right to change roles, even if the token belongs to an administrator. Access is denied immediately and cannot be bypassed (API keys — your personal tokens).
The same applies to technical account tokens used by programs such as n8n: they cannot perform any operation requiring 2FA confirmation, and they do not even have read access to users, roles, or permissions.
Trusted devices are different
A trusted device skips the code at sign-in. It never replaces confirmation for a sensitive operation (Sessions and devices — who is logged into your account).
Other places that ask
Besides roles and users: company data, integration keys, mappings, sync schedules, technical accounts and their tokens, inventory settings, replenishment, returns, and more. You can see the full list in your account settings on the Security tab (Two-factor authentication (2FA) — enabling it, backup codes, and disabling it).
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo