Skip to main content
Security settings page

Settings > Security

This view can look different dependent on your user role.
See Visibility & Permissions for details.

Primary Purpose

Control how your team signs in to the admin.
Choose which methods users can sign in with: Email & Password, Google, Microsoft, or Facebook. Users can only access your account when signed in with one of the selected methods. At least one method must stay selected. New accounts allow all four methods until you restrict them.
Allow Email & Password sign-in for users who hold the Account settings > Security > Manage permission, even when Email & Password is not a selected sign-in method. This acts as an escape hatch: a user with that permission can still sign in and fix the configuration if an identity provider is misconfigured.

Users & Roles

Team members, system roles, and custom roles.

Profile

Your personal details and interface language.

Visibility and Permissions

This page is the one settings page with no view gate — it is visible to every system role, so a user can always reach their own security settings. Saving changes is gated by account_settings:security, which only Owner and Admin hold. For what each operation means and the full role matrix, see Users & Roles.