Security
Security settings apply to your whole organization. There is no per-workspace variation: tightening a policy tightens it everywhere, including sandbox.
Two-factor authentication
Two-factor can be required organization-wide. Turning it on affects everyone, including people who are mid-session, so plan the moment rather than discovering it.
Individuals can enrol before it is mandatory. Doing that first, then switching on the requirement, is the sequence that avoids locking your own team out on a Monday morning.
Sessions
Session policy decides how long somebody stays signed in and when they must re-authenticate. Shorter sessions are safer and more annoying; the right answer depends on whether your team works from shared machines.
What is recorded
Kontier keeps an audit trail of what changed, when, and who did it. It is what answers "why does this invoice say that" months later, and it is the reason a finalised invoice is immutable rather than editable.
Audit retention is configured by whoever runs the installation, not per organization.
Data export and erasure are operator-assisted
GDPR export and erasure exist, but they are not exposed in the dashboard or the public API. If you need to satisfy a data request, email engineering@kontier.eu.
Practical advice
Three things worth doing before you are busy:
- Enrol in two-factor before requiring it, so the switch is uneventful.
- Give API keys an expiry. A key with no expiry outlives the integration it was made for.
- Use
allowed_ipsfor machine-to-machine keys. A leaked key is useless from an address you did not list.
Reference
| Topic | When you need it |
|---|---|
| Team and roles | Who can do what |
| API keys | Scopes, rotation, IP restrictions |
| Organization settings | Where security settings live |