Protect access without slowing down the project.
Use individual accounts, appropriate workspace roles and two-factor authentication for privileged users. Keep authentication separate from customer, project and testing permissions.
Start from your account security page
Your personal security controls live in My Account → Security. This is where users can review two-factor authentication status, update their password and manage account-level security settings without needing workspace administrator access.

Set up two-factor authentication
When you enable two-factor authentication, Valtoroq presents a QR code that can be scanned with an authenticator app such as Microsoft Authenticator, Google Authenticator or 1Password. If scanning is not convenient, use the manual secret shown on the page.
- Open My Account → Security.
- Start the 2FA setup flow.
- Scan the QR code with your authenticator app.
- Enter the verification code generated by the app.
- Save your recovery codes in a secure location.

Signing in with 2FA
After 2FA is enabled, Valtoroq asks for your authentication code during sign-in. If the device is trusted and your security policy allows it, you can choose to trust the device for a limited period to reduce repeated prompts.

Change your password
Users can change their password directly from the Account Security page. The current password is required, and the new password should be unique to Valtoroq and stored in a password manager whenever possible.
- Use a password that is long and unique.
- Avoid reusing a password from any other service.
- If you suspect exposure, change the password immediately.
Recovery codes
Recovery codes are your fallback if you lose access to your authenticator app or replace your device. Store them somewhere secure and separate from your normal day-to-day login device.
Password reset
If you do not remember your current password, use the Forgot password flow from the sign-in screen. If the reset message does not arrive, check spam or junk folders and confirm that your organization is not filtering emails from Valtoroq.
For administrators
Workspace administrators should issue each user an individual account, assign the correct role and encourage or require 2FA based on company policy. Authentication protects account access, while roles and permissions control what a user can see and do inside the workspace.
If a user loses access to their authenticator app, an administrator can reset that user's 2FA and ask them to enrol again. For day-to-day work, remember that account security settings are personal and separate from workspace settings.
Access problems
If you can sign in but cannot see a project, document or action, the issue is normally workspace membership, subscription entitlement or role permissions rather than your password or 2FA.