Security
Security
Account security with 2FA and session control, SAML SSO for the workspace, and data controls.
Security in Asks lives at two levels: your personal account (password, 2FA, sessions) and the workspace (single sign-on, domains, deletion). Account settings apply to you everywhere; workspace settings apply to everyone in that workspace.
Your account
Password. Set or change your password under Settings → Account → Security. If you signed up with Google you may not have a password yet — use "Forgot password?" on the sign-in page to set one.
Social sign-in. You can sign in with Google. If Google is linked to your account, it appears on the same settings page.
Two-factor authentication. Asks supports TOTP two-factor authentication with any authenticator app (Google Authenticator, 1Password, Authy). Enable it under Settings → Account → Security by scanning the QR code and confirming a code. Enabling 2FA also generates a set of one-time recovery codes — download them and store them somewhere safe; you can regenerate the set later with your password. Disabling 2FA requires your password and signs out your other sessions.
Active sessions. Settings → Account → Sessions lists every device signed in to your account. Revoke any session you don't recognize — it signs that device out immediately — or use Revoke all other sessions to sign out everything except the device you're on.

SAML SSO
SAML SSO Premium lets a workspace require sign-in through your identity provider. Asks implements SP-initiated SAML 2.0 and works with any compliant IdP — Okta, Microsoft Entra, Google Workspace, and others.
Configure it at Settings → Workspace → Security:

Add Asks as a SAML application in your identity provider. The settings page shows the SP values (ACS URL and entity ID) to paste into the IdP.
Provide the IdP entity ID, the SSO URL, and the signing certificate. You can also map the email and name attributes if your IdP uses non-standard names, and choose the default role new users get.
Add your company domain and prove ownership with a DNS TXT record. Just-in-time provisioning is gated by verified domains: users signing in through your IdP with an email on a verified domain get a workspace seat automatically, with the default role you chose.
With Enforce SSO on, members must sign in through the IdP — password sign-in is rejected for this workspace.
Two safety valves apply when SSO is enforced. Owners and admins with 2FA enabled keep a break-glass password sign-in, and the sole owner is never locked out. Every break-glass sign-in and every SSO configuration change is recorded in an audit log and alerts the workspace owner and admins; contact support if you need a copy of the log.
Data controls
Workspace export. The Danger Zone at Settings → Workspace → Danger Zone offers a workspace data export as JSON — take one before any destructive change.
Leaving a workspace. Admins and members can leave a workspace from the same Danger Zone page. The owner can't leave — transfer ownership first (Team & roles).
Workspace deletion. The owner can delete a workspace from the Danger Zone. This permanently removes conversations, the knowledge base, channels, and settings for every member.
Email preferences. Every non-essential email Asks sends carries an unsubscribe link, and you can manage notification categories under Settings → Account → Notifications.