PlatformGovern
A sign-in that does not rest on a password alone
Each company decides how strict to be: no requirement, an email code or an authenticator app. Anyone who prefers can sign in with a passkey.
Company policy
- No requirement
- Email code
- Authenticator app
Your sign-in
- Authenticator appOn
- Passkeys1 device
- Recovery codesSaved
Illustrative example
Several ways to confirm who is signing in
Email code
A one-time code, sent to the person's address at every sign-in.
Authenticator app
TOTP codes from an authenticator app, with recovery codes shown once to get back in if a phone is lost.
Passkeys
Sign in with the fingerprint, face or PIN of the device, with no codes to copy. A passkey sits beside the password, and each company chooses whether to allow it.
Trusted devices
A device that has already been verified skips the code for a limited time. If the company changes its policy, trusted devices are revoked.
The policy, in three steps
- 01
Choose the policy
For each company: no requirement, an email code or an authenticator app.
- 02
People enrol themselves
With the app policy, anyone without an authenticator sets one up at their next sign-in: nobody is locked out.
- 03
Recover without a ticket
If someone loses their phone, an administrator resets their authenticator and they set up a new one at their next sign-in.
In detail
- Methods
- Email code, TOTP, passkeys, recovery codes, trusted devices.
- Policy
- Set per company; you can always go back to no requirement.
- Several companies
- Someone who belongs to more than one company is asked for the strictest policy.
- Open sessions
- A policy change does not close them: the requirement applies from the next sign-in.
- Passkeys
- Allowed company by company; they do not replace the password.
Frequently asked questions
No. With the authenticator app, anyone without one sets it up at their next sign-in. The email policy cannot be switched on if the mail service cannot deliver codes, and you can always go back to no requirement.
No, they sit beside it: signing in with the password stays available. Each company chooses whether to allow passkeys.
They stay open and the requirement applies from the next sign-in. The company's trusted devices, though, are revoked.
Bring us a question you can't answer today.
We start from a real question your business has and walk the path from source to dashboard with your systems, not a demo dataset.