Skip to main content

Security

Settings5 min read

Settings → Security is the company policy: Require two-factor authentication and Session timeout (minutes). Your own password, authenticator, and Active Sessions live under Account settingsSecurity.

When this area is the right place

Use workspace Security when you want every member of this company to use an authenticator, or to sign people out after idle time in the browser.

Use Account settingsSecurity to change your password, turn 2FA on for yourself, or revoke a device.

Use Roles & permissions to decide who can open jobs, finances, or integrations. That is not on this screen.

Before you start

  • You can open Settings → Security (typically Owner or Admin).
  • An authenticator app is ready if you will turn on Require two-factor authentication (Google Authenticator, 1Password, or similar).

Set workspace policy

Open Settings → Security (nav group Account). The page title is Workspace settings. The card title is Security.

Turn on Require two-factor authentication if members must enroll before they can keep using this workspace.

Set Session timeout (minutes) if idle browsers should sign out. Leave it blank for no inactivity sign-out. Allowed range is 5 to 20160 minutes (14 days).

Choose Save changes. The in-app hint How these settings apply explains that timeout is idle mouse, keyboard, or scroll in this web app.

Enroll 2FA on your account

Open Account settings from the user menu → Security. The card is Two-factor authentication.

Choose Enable two-factor authentication. Scan the QR code (or Open in authenticator app / enter the secret). Type the 6-digit code, then Confirm and enable. Copy the backup codes (Save your backup codes / Copy all codes).

If the workspace already requires 2FA and you have not enrolled, SiteHut sends you here with Two-factor authentication required. You can open All Jobs or Sign out while you finish.

Review sessions

On the same Account Security page, Active Sessions lists browsers and devices. This device is the current one. Revoke a row you do not recognize, or Sign out other devices.

Login after 2FA is on asks for Authenticator code, then Verify and sign in. Use a backup code instead if you cannot open the app.

What done looks like

  • Workspace Security shows the toggle and timeout you saved.
  • Members without 2FA cannot stay in this workspace until they enroll.
  • Your account shows Two-factor authentication is on and a backup-code count.
  • Unknown sessions are gone.

Common mistakes

  • Looking for Password on workspace Security. That card is Account settings → Security.
  • Expecting a blank timeout to sign people out. Empty means no automatic sign-out from idleness.
  • Handing a field tablet over without Sign out or Revoke.
  • Creating a personal API key for a company integration. Use workspace API keys.
Access, privacy, and how to report a vulnerability

Give field staff Superintendent or Field Worker, and keep Owner / Admin for company administration. See Roles & permissions.

Application traffic uses HTTPS. Job data is scoped to the workspace. Files are delivered with signed storage URLs. The public write-up is Security overview. Subprocessors: sitehut.app/subprocessors. DPA: sitehut.app/dpa. Privacy: Legal.

Report a suspected vulnerability privately to support@sitehut.app. Scope and response targets: sitehut.app/security-disclosure. Do not test against other users' accounts.