Help Center

Find answers, guides, and tutorials to help you get the most out of CareCade

AI-Powered

Security Settings

AdministratorsSettings & Configuration

Configure 2FA, session management, and passkeys.


Accessing Security Settings

  1. Go to SettingsSecurity
  2. Configure organization-wide security

Two-Factor Authentication (2FA)

Organization Setting

OptionDescription
OptionalUsers can enable if they want
RequiredAll users must enable 2FA
Required for AdminsOnly Admin+ must enable

2FA Methods

  1. Authenticator App (Recommended)

    • Google Authenticator
    • Authy
    • Microsoft Authenticator
  2. Email Code

    • Code sent to email
    • Fallback option
  3. Passkeys (Most secure)

    • Face ID, Touch ID, Windows Hello
    • Hardware security keys

Passkeys (WebAuthn)

What Are Passkeys?

Passwordless sign-in using:

  • Face ID (iPhone, Mac)
  • Touch ID (Mac)
  • Windows Hello
  • Security keys (YubiKey)

Enabling Passkeys

Admins can:

  1. Go to Security Settings
  2. Toggle Allow Passkeys
  3. Users can then add passkeys in their profile

User Setup

  1. Go to ProfileSecurity
  2. Click Add Passkey
  3. Follow device prompts
  4. Name the passkey
  5. Done — can sign in with biometric

Session Management

Session Timeout

How long before inactive users are logged out:

SettingRecommended
Web sessions8-24 hours
Mobile sessions30 days

Active Sessions

Users can view and revoke sessions:

  1. Profile → Security → Active Sessions
  2. See all logged-in devices
  3. Click Revoke to force logout

Password Requirements

Configure password policy:

SettingOptions
Minimum length8-16 characters
Require uppercaseYes/No
Require numbersYes/No
Require symbolsYes/No
ExpirationNever, 30, 60, 90 days

Account Lockout

Prevent brute force attacks:

SettingRecommended
Failed attempts before lock5
Lockout duration30 minutes
Reset after30 minutes

Admin Actions

Force Password Reset

Make specific user reset password:

  1. Go to Team → Select user
  2. Click Force Password Reset
  3. User must reset on next login

Force Logout

Sign out user from all devices:

  1. Go to Team → Select user
  2. Click Revoke All Sessions
  3. User logged out everywhere

Audit Logging

Security events are logged:

  • Login attempts (success/fail)
  • Password changes
  • 2FA changes
  • Passkey additions
  • Session revocations

View at SettingsAudit Logs.


Tips

  • Require 2FA for admins — Minimum security
  • Use passkeys — Most secure option
  • Review audit logs — Catch suspicious activity
  • Set reasonable timeouts — Balance security and usability

Related Articles

Was this article helpful?

Need More Help?

Can't find what you're looking for?

Contact Support

Send Feedback

How's your experience?

Security Settings - CareCade Help Center | CareCade