How-to guide

Configure staff two-factor authentication

Enable and verify an additional authentication factor for staff login.

Audience: StaffFeature: StaffPermission-aware
Feature pathProfile → Two-factor Authentication
Before you beginThe screen or action may be hidden when your role lacks permission, the related module is inactive, or a required setting has not been configured. Ask an administrator to review access rather than using another person’s account.

What this feature does

Enable and verify an additional authentication factor for staff login. Britixo CRM keeps the result connected to the relevant customer, staff member and operational history where the feature supports those relationships. That connection is important for search, reporting, client portal visibility and future automation.

Step-by-step workflow

  1. Open Profile → Two-factor Authentication using an administrator or appropriately permitted account.
  2. Review the current value and understand which users, records or automated processes it affects.
  3. Enter or select the new configuration values. Keep labels concise and use the approved business terminology.
  4. Where credentials, email, webhooks or cron are involved, begin with a test or sandbox configuration.
  5. Save the change and confirm that Britixo CRM reports success.
  6. Test the affected workflow with a non-critical record and with a restricted user where permissions are relevant.
  7. Document the operational change and use the available reset or rollback option if the result is not correct.

Important fields and decisions

Name and emailConfirm this information is accurate and appropriate for the record.
RoleConfirm this information is accurate and appropriate for the record.
DepartmentsConfirm this information is accurate and appropriate for the record.
PermissionsConfirm this information is accurate and appropriate for the record.
LanguageConfirm this information is accurate and appropriate for the record.
Active and authentication settingsConfirm this information is accurate and appropriate for the record.

Checks before completion

  • Apply least-privilege access.
  • Use a unique email account.
  • Reassign work before deactivation.
  • Check whether the result should be visible to a customer contact or only to staff.
  • Confirm the final status, activity entry, generated document or notification before leaving the record.
Permission and data safetyDeletion, refunds, signature clearing, module changes, payment configuration and privacy actions can affect linked records or legal history. Use the least destructive action available and follow your organisation’s approval process.