Account & security settings

Manage your personal profile, two-factor authentication, holiday mode, and organization security policies.

Personal settings live under Settings → Personal and apply to you, wherever you have access. Organization-wide security policies live under Organization and Workspace settings.

Your profile

Under Settings → Personal → Account settings:

  • Name, email address, and photo.
  • Timezone — used to localize the times you see across Spectra.

Holiday mode

Going away? Holiday mode (under Account settings) pauses your alerts and on-call responsibilities for a date range you set — away from and away until — so notifications route to the rest of the team while you’re out. It affects only your own notifications, not your monitors.

How sign-in works

Spectra uses magic-link authentication — there’s no password to set or change. You sign in by entering your email and clicking the secure link Spectra sends you. Manage everything else under Settings → Personal → Security.

Two-factor authentication (2FA)

Add a second step on top of the magic link. Under Settings → Personal → Security → Set up 2FA:

  1. Get an authenticator app — Google Authenticator, 1Password, Authy, Duo Mobile, or Microsoft Authenticator (any TOTP app).
  2. Scan the barcode shown, or enter the secret key manually.
  3. Enter the 6-digit code from the app to activate.

After that, every sign-in asks for a fresh 6-digit code (it refreshes every 30 seconds in your app) in addition to the magic link.

Organizations can require 2FA for all members as a security policy, so everyone must enable it before they can access the workspace.

Active sessions

Security also lists where you’re currently signed in — device, browser, location, and last activity. Revoke any session to sign that device out immediately, or revoke all other sessions to sign out everywhere except your current device.

Organization security policies

Owners and admins can enforce account-wide protections:

  • Require 2FA for all members — no one can access the workspace until they’ve enabled it.
  • Allow domain-based join — people with your organization’s email domain can request to join without a direct invite.
  • Single Sign-On (SSO / SAML) — available on the Enterprise plan for centralized identity.

Deleting your account

You can delete your own account from Account settings. If you’re the Org Owner, you’ll need to transfer ownership first. Account deletion is permanent.

Next steps

Can't find what you need? Email [email protected] — we're happy to help.