Skip to main content

Security Settings

Security settings control authentication requirements and data protection policies for your organisation. Access: SettingsOrganisationSecurity (Org Admin only).

Two-Factor Authentication (2FA)

SettingOptionsDefault
Require 2FA for all membersOn / OffOff
Grace period0–30 days7 days

Behaviour when 2FA is enforced

  • Existing members: Receive a notification on their next login with a countdown to the grace period deadline. They can continue accessing Kazinex during the grace period.
  • New members: Must set up 2FA during their first login session before accessing any project.
  • After grace period expires: Members who have not set up 2FA are prompted to complete setup on every login before accessing the organisation.

Supported 2FA methods

  • TOTP authenticator apps (Google Authenticator, Authy, Microsoft Authenticator)
  • Email OTP (fallback, if enabled by Kazinex support)

2FA compliance monitoring

Go to SettingsTeam to see 2FA status for each member:

  • Enabled — 2FA is set up
  • Pending — notified but not yet set up (within grace period)

Tutorial: Org Branding & Security Setup includes a step-by-step 2FA rollout process. See also Security Hardening admin guide for an enterprise rollout checklist.


Default Project Roles

SettingOptionsDefault
Default role for new project invitesreviewer / initiator / viewerreviewer

When a Project Admin invites a new member without specifying a role, this default applies. Change to viewer for projects where you want new members to have read-only access until explicitly upgraded.


File Type Restrictions

SettingOptionsDefault
Restriction modeAllow all / AllowlistAllow all
Allowed types (Allowlist mode)Configure MIME types and extensions

When to use an Allowlist

  • Your organisation does not want non-document files (executables, scripts, archives) stored in the document register
  • Compliance requirements mandate specific file formats only
  • Your storage provider has a known performance issue with certain file types

Configuring the allowlist

  1. Toggle Restriction mode to Allowlist.
  2. Click Add File Type → enter extension (.pdf) and MIME type (application/pdf).
  3. Repeat for each permitted type.
  4. Click Save.

See File Restrictions guide for recommended allowlists for construction, engineering, and professional services projects.


Guest Access Policy

SettingOptionsDefault
Allow guest sharesOn / OffOn
Maximum guest share expiry7 / 14 / 30 / 90 days / No limitNo limit
Allow download on guest sharesAdmin controls only / Sender controls / OffSender controls

Set Maximum guest share expiry to enforce a maximum link duration — individual Project Admins can set shorter expiry but not longer.


What's next