This page covers the security controls available on your FacilityLane account: password management, two-factor authentication (2FA), and what happens when an Admin resets a password.

Change your password

1

Open security settings

Go to Settings → Security.
2

Enter your current password

You must confirm your current password before setting a new one.
3

Set the new password

Enter and confirm the new password, then select Save. Use it on your next login on web and mobile.
Security settings showing current password, new password, and confirm password fields

The change password form in security settings

Forgot your current password? Log out and use Forgot password? on the login page instead — see Account setup.

Set up two-factor authentication

Two-factor authentication adds a verification code on top of your password at login.
1

Open the 2FA section

In Settings → Security, select Enable Two-Factor Authentication.
2

Link your authenticator app

Scan the displayed QR code with an authenticator app (such as Google Authenticator or Authy), or enter the setup key manually.
3

Confirm with a code

Enter the 6-digit code from your authenticator app to verify the setup.
4

Finish

2FA is now active. On every login, you enter your password and then a current code from the app.
Two-factor authentication setup showing a QR code to scan and a field to enter the verification code

The 2FA setup screen with QR code and verification code entry

If you lose access to your authenticator app, you will be unable to log in with 2FA. Contact your organization Admin for help regaining access.

Admin password resets

Admins can reset any user’s password from the Users page:
  1. Open the user’s record.
  2. Select Reset Password.
  3. The user is placed into a forced password change: on their next login they must set a new password before they can access anything else.
User record showing the admin reset password action with confirmation

The reset password action on a user record

The same forced password change applies to a user’s very first login after accepting an organization invite. See Account setup.

Security best practices

  • Require 2FA for Admins and Managers, who can change organization-wide settings.
  • Use location-scoped access and least-privilege roles so users only see the data they need.
  • Disable users as soon as they leave the team.