

**Settings → Security** is where you manage how you sign in — and, if you are an
admin, what the rest of your agency can use.

## Your own sign-in [#your-own-sign-in]

* **Passkeys** — set up Face ID, a fingerprint, or your device PIN on each device you use. See [passkeys](/docs/signing-in/passkeys).
* **Password** — your everyday way in. To change it, we email you a 6-digit code first.
* **Two-step verification** — also called two-factor authentication (2FA) or MFA. Add a code from an authenticator app for extra protection. You get backup codes to save when you turn it on.

## For agency admins [#for-agency-admins]

Admins decide which sign-in methods the whole agency can use — passkeys,
password, Google, and email code. Turn off the password method once your team is
comfortable with codes, for example.

The **email code cannot be turned off** — it is how everyone can always get back
in. Every change to these settings is recorded in your agency's
[audit log](/docs/account/audit-log).

