genai
SECURITY LAB
DocsFor teamsLogin policy

Login policy

This page covers how your team signs in, how to turn off password sign-in for everyone, and what happens when you remove someone.

genaisecuritylab.com/team/login-config
Login policy: sign-in methods, allowed email domains, and SSO enforcement.
Login policy: sign-in methods, allowed email domains, and SSO enforcement.

Sign-in methods

Every member signs in one of three ways: email and password, a one-time emailed link, or OAuth through Google or GitHub. OAuth carries your identity provider's own login and MFA, so it's the strongest of the three by default.

Team plans add a login policy an admin can configure: turning off password sign-in for the whole workspace, and restricting which email domains can be invited in the first place. Enterprise plans add full SSO/SCIM against your own identity provider — see pricing for what's included at each tier.

Sign-in methodAvailable by defaultWhen password sign-in is disabled
Email and passwordYesRefused
One-time email linkYesStill works
Google / GitHub OAuthWhere enabledStill works

Enforcing the policy

From your workspace's login policy settings, a team admin can disable password sign-in entirely. Before that switch can be turned on, the admin has to prove the workspace's email actually works: request a one-time test link to their own inbox, and complete a real sign-in with it. A second admin can't ride on the first admin's proof — each admin who wants to flip the switch runs the test themselves.

Send yourself the test link firstCompleting your own one-time link is what unlocks the toggle, so do it before you plan to flip the switch — enabling the policy is then a single click, with no mail-delivery surprise in the way.

Nobody is exempt once it's on — not even the workspace owner. Turning the policy back off, by contrast, needs no proof: restoring password sign-in can't lock anybody out, so it takes effect immediately. At their next attempt, a member who tries a password sees a plain refusal pointing them to a one-time link or OAuth instead.

Removing a member

Removing someone deactivates their membership right away: they lose access to the workspace's assignments and shared coverage immediately, and their seat frees up for the next invite the same moment.

It's a deactivation, not a deletion. Their past evidence submissions and audit entries stay exactly where they are, tied to their name. Invite the same address back later and it reactivates that same membership directly, so their history picks up again instead of starting over. See inviting members for the other side of the roster. The workspace owner can't be removed.

Sessions and recovery

Turning the login policy on or off doesn't reach back into sessions that already exist. A token issued before the change stays valid until it expires on its own — up to a day, by default — so enforcement is immediate for the next login attempt and gradual for anyone already signed in.

Because there's no password once the policy is on, "forgot password" isn't the recovery path — a fresh one-time link, or your OAuth identity, is. If your workspace's email breaks after the policy is already on and nobody can complete a link, our support team can restore password sign-in for your workspace so you're never stranded for good.

Was this page helpful?
Previous
Usage and engagement