Help Article
    Organisation Settings

    Setting Up MFA (Step-by-Step)

    Add a second layer of security to your account in under two minutes — here's the step-by-step

    3 min read
    Updated August 28, 2026

    You’ve secured your firm’s commercial data and protected your client contracts, but your individual login remains the single point of entry to your entire operation. A compromised password isn't just a personal inconvenience; it’s a direct threat to your firm’s commercial integrity and the sensitive financial data you manage every day.

    Multi-Factor Authentication (MFA) adds a vital layer of protection by requiring a secondary verification code from your mobile device. This simple step ensures that even if your credentials are leaked, your quotes, margins, and invoices remain under your control. By following this guide, you’ll move from a single-password vulnerability to a secure, professional-grade posture in less than five minutes.

    Protecting Your Commercial Truth

    In a professional services environment, your AtomicSam account holds the "commercial truth" of your business—your project rates, profit margins, and billing logic. If an unauthorized party gains access, they don't just see your tasks; they see the financial heartbeat of your firm. Enabling MFA is the most effective way to prevent revenue leakage through data theft or unauthorized billing changes. It provides you with the confidence that only authorized team members are steering the ship.

    💡 Tip: Before you begin, ensure you have an authenticator app installed on your smartphone. We recommend Google Authenticator, Microsoft Authenticator, or Authy.

    How to Enable MFA

    Follow these steps to link your AtomicSam account to your mobile authenticator app.

    1. Click on your Avatar in the bottom-left corner of the sidebar.
    2. Select My Profile from the menu.
    3. Navigate to the Security tab.
    4. Locate the Multi-Factor Authentication section and click Enable MFA.
    5. Open your authenticator app on your phone and select the option to "Add a new account" or "Scan a QR code."
    6. 📸 [Screenshot: The MFA setup modal showing the QR code and secret key field]
    7. Scan the QR code displayed on your screen. If your camera isn't working, you can manually enter the Secret Key provided in the setup window.
    8. Your app will generate a six-digit code. Enter this code into the Verification Code field in AtomicSam.
    9. Click Confirm & Activate.

    Securing Your Recovery Codes

    Once MFA is active, AtomicSam will generate a set of one-time recovery codes. If you lose your phone or delete your authenticator app, these codes are the only way to regain access to your account without a manual reset from our support team.

    ⚠️ Heads up: Do not store these codes on your computer in an unencrypted file. Print them out and put them in a physical safe, or store them in a secure password manager like 1Password or Bitwarden.

    Logging In with MFA

    After setup, your login flow will change slightly to maintain this higher level of security:

    Action When to use this...
    Standard MFA Code Your daily login. Enter the 6-digit code from your app after your email and password.
    Trust This Device Checking this box during login means you won't be prompted for a code on this specific browser for 30 days. Only use this on private, secure hardware.
    Recovery Code Use this when you don't have your phone or the authenticator app has been reset. Each code works only once.
    ✅ Did you know: If you are a firm owner or administrator, you can view which team members have enabled MFA from the Team Management settings. This allows you to verify that your entire organization is operating with the same level of commercial security.

    Pro Tips & Common Gotchas

    • Synchronize your clock: Authenticator codes are time-based. If your phone's clock is even a minute out of sync with your computer, the codes will fail. Set your phone to "Set Time Automatically" in your system settings.
    • The "New Phone" Trap: When you upgrade your smartphone, MFA does not always transfer automatically. Before you wipe your old phone, log in to AtomicSam, disable MFA, and then re-enable it using your new device.
    • Avoid SMS where possible: While some systems allow SMS-based codes, AtomicSam prioritizes app-based MFA. App-based authentication is significantly more secure against "SIM-swapping" attacks, ensuring your commercial data hasn't been intercepted in transit.
    📸 [Screenshot: The Team Management view showing the 'MFA Status' column for all users]