Account security
Your individual Sencai account has its own security settings, separate from
anything an organization Owner or Admin controls at the organization level.
Manage them from your profile → Security tab
(/gravity/userprofile, then select the Security tab).
Two-factor authentication (2FA)
Section titled “Two-factor authentication (2FA)”Sencai supports TOTP-based two-factor authentication - a 6-digit code from an authenticator app such as Google Authenticator, Authy, or 1Password.
Enabling 2FA:
- From the Security tab, select Set up 2FA.
- Scan the QR code (or enter the shown secret manually) in your authenticator app.
- Enter the 6-digit code it generates to confirm the code works before 2FA is actually turned on for your account.
Once enabled, every future sign-in prompts for a code from your authenticator app after your password, on a dedicated screen.
Disabling 2FA requires entering a current, valid 6-digit code from your authenticator app - this is intentional, so 2FA can’t be turned off by anyone who only has your password.
Before enabling 2FA, make sure your authenticator app itself has its own backup (most modern authenticator apps support cloud backup or a documented transfer process) so a lost phone doesn’t also mean a lost authenticator.
Password
Section titled “Password”Change your password from the Security tab by entering your current password and a new one (minimum 10 characters). Changing your password may sign out your other active sessions - see below.
If your organization has SSO enforcement turned on, this form isn’t relevant for your sign-in - your organization’s identity provider is the only accepted way in, and there is no separate Sencai password to change for that purpose.
Active sessions
Section titled “Active sessions”The Security tab lists your current sign-in sessions (by client and IP address, with last-seen and started timestamps) as reported by the identity provider. Select Sign out next to any session to revoke it immediately - useful if you signed in on a device you no longer have, or want to end a session you don’t recognize.
Email address
Section titled “Email address”Changing your email address from the Security tab requires verifying the new address before it becomes active - you’ll receive a verification link at the new address, and your account keeps using the current address until you confirm it.
Personal notification settings
Section titled “Personal notification settings”Notification preferences are a separate screen: Settings → Notifications
(/gravity/settings/notifications). There you control email categories
(product updates, marketing, and a digest - security and billing
notifications are always sent and can’t be turned off) and, separately,
browser push notifications with optional event-type filters.
What you control vs. what an org admin controls
Section titled “What you control vs. what an org admin controls”Your password, 2FA, active sessions, and personal notification preferences are yours alone - no organization Owner or Admin can see or change them. What an organization’s Owner or Admin can control, at the organization level, includes:
- Requiring SSO for every member (see Single sign-on) - once enforced, password sign-in stops working for that organization’s members entirely, regardless of your own personal password.
- Restricting which IP ranges can reach the organization at all - see IP allowlisting.
- Your role within that organization (Owner, Admin, Member, Auditor, or Viewer) - see Roles & permissions.
- Personal API tokens are yours to create and revoke, but an organization’s tier determines whether the feature is available at all - see API tokens.
What’s next
Section titled “What’s next”- Single sign-on - organization-level authentication requirements
- IP allowlisting
- API tokens
- Roles & permissions