Skip to content

Security Center & Devices

Control how people reach your workspace: which email domains can join, which devices are trusted, and approving new devices.

Screenshot: Security center — TODO

Email domain whitelist

Open Security Center (/admin/security).

Add the domains your organisation uses (e.g. company.com). New accounts must use a whitelisted domain. Add, remove, activate, or deactivate domains as needed.

Device approvals

Open Settings → Device Approvals (/settings/devices).

When someone signs in from a browser or device your workspace has not seen before, they do not get straight in. They land on a "this device needs approving" page, and the device appears in your queue.

Each row shows who signed in, a summary of the browser and operating system, the address they came from, and when the device was first and last seen. Devices waiting on you sort to the top.

Open the Actions menu on a row to:

  • Approve — the person can sign in from that device from now on. They just sign in again.
  • Deny — sign-in from that device is refused.
  • Revoke — withdraws an approval you granted earlier.

The first device someone uses is approved automatically

Otherwise a brand-new workspace's very first administrator would be locked out with nobody able to let them in — and switching this on would queue everybody who was already working normally. So the first device each person ever signs in from is trusted silently; every device after that needs you. Auto-approved rows are labelled Auto (first device) so you can tell them apart from ones a person decided on.

Revoking takes effect at the next sign-in

A revoked device is refused the next time it signs in. If that device has a session open right now, it stays open until it ends — revoke the device and have the person signed out if you are dealing with a lost or stolen laptop.

If someone is queued unexpectedly

Almost always one of: they are in a private/incognito window, they cleared their cookies, they are on a different browser, or they replaced the machine. Each of those genuinely is a new device as far as the workspace is concerned. Approve it if you recognise them; deny it if you do not.

If everyone sees "We can't verify this device right now"

That is not a refusal — it means the service that stores approved devices did not answer, and we stop rather than let unverified devices through. It is usually brief. If it persists, it is a platform issue, not a problem with anyone's account.

Approver ≠ owner

A device should be approved by someone other than its owner. Approvals are part of the workspace's zero-trust posture — review them rather than rubber-stamping.