Two-Factor Authentication
Your CRM holds your customer list, your pipeline and your invoices. A password alone protects all of it. Two-factor authentication (2FA) adds a second check, so a stolen or guessed password isn't enough on its own.
How It Works
After your password, SwiftlyCRM asks for a six-digit code from an authenticator app on your phone. The code changes every 30 seconds and is generated on your device - it isn't sent by SMS or email, so it can't be intercepted or SIM-swapped.
Turning It On
You'll need an authenticator app. Any of these work:
- Google Authenticator
- Microsoft Authenticator
- Authy
- 1Password, Bitwarden, or most password managers
Then:
- Go to Settings → My Preferences and start two-factor setup
- Scan the QR code with your authenticator app
- Enter the six-digit code it shows, to confirm it's working
- Save your backup codes somewhere safe
Important
Save your backup codes before you finish setup. They are the only way back into your account if you lose your phone - support cannot bypass 2FA for you, because an account recovery route that works for us would also work for an attacker.
Backup Codes
Backup codes are single-use codes that work in place of your authenticator app. Each one works once, then it's spent.
Keep them somewhere you can reach without your phone - a password manager on your laptop, or printed and filed. Storing them only on the phone that runs your authenticator defeats the point.
Signing In With 2FA On
Enter your email and password as usual, then the current code from your app. If you tick remember me, you won't be asked for a code on that device again for a while - which is fine on your own laptop and a bad idea on a shared machine.
If You Lose Your Phone
Use a backup code to sign in, then immediately:
- Turn 2FA off
- Turn it back on and scan the new QR code with your new device
- Save the fresh set of backup codes
Your old codes stop working as soon as you re-enrol.
Tip
If you're rolling this out to a team, get everyone to store their backup codes in the same place your team already keeps shared credentials. The support burden from 2FA is almost entirely people who never saved theirs.
Should Everyone Use It?
At minimum, anyone with admin access - they can see and export everything. Realistically, anyone whose account would hurt if it were taken over, which in a CRM is most people.
Turning 2FA on for your own account doesn't affect anyone else's; each person enables it on their own account.