# Security and administration (https://docs.akollo.com/en/trust/security)



This page covers the security settings of your own account and the tools administrators use to manage members, roles and usage. It also explains how Akollo limits support access, outbound connections and access between organisations.

## Your account [#your-account]

**Account → Security** holds your sign-in settings:

* e-mail and password;
* two-step verification with an authenticator app, with backup codes;
* passkeys, where enabled;
* trusted devices, which you can remove;
* connected accounts, which you can unlink.

**Preferences** sets the light or dark theme where it is offered. **Appearance** sets a background for the app; it is stored in the current browser only.

<Screenshot src="/screens/en/settings-security.webp" alt="Security settings with forms to update the e-mail address and the password" caption="Account → Security: change your e-mail address and password here." />

To change your password:

<Steps>
  <Step>
    ### Open the security settings [#open-the-security-settings]

    Go to **Account → Security**.
  </Step>

  <Step>
    ### Enter your current and new password [#enter-your-current-and-new-password]

    Under **Update your Password**, fill in **Current Password**, **New Password** and **Repeat New Password**.
  </Step>

  <Step>
    ### Save [#save]

    Select **Update Password**.
  </Step>
</Steps>

<Callout type="info" title="Note">
  When you change your e-mail address under 

  **Update your Email**

  , both the current and the new address must be verified.
</Callout>

## Members and roles [#members-and-roles]

**Admin → Users** lists the organisation’s members, with their role and joining date, and the pending invitations. Administrators invite people and cancel invitations there. **Admin → Roles** lists the roles; changing them needs the role-management permission. Permission sets and field policies are described in [Organisation and access](/en/product-guide/organisation-and-access).

<Screenshot src="/screens/en/settings-members.webp" alt="Users page with the members table showing each member’s role and joining date, and an Invite Members button" caption="Admin → Users: members, their roles and the Invite Members button." />

To invite a member:

<Steps>
  <Step>
    ### Open the user list [#open-the-user-list]

    Go to **Admin → Users**.
  </Step>

  <Step>
    ### Start the invitation [#start-the-invitation]

    Select **Invite Members** and enter the people you want to invite.
  </Step>

  <Step>
    ### Send the invitations [#send-the-invitations]

    Select **Send Invites**. The invitation appears in the list as pending until it is accepted or cancelled.
  </Step>
</Steps>

## Usage [#usage]

**Admin → Usage** shows your organisation’s usage per meter, day by day. Days follow the organisation’s time zone. The meters include:

* AI input tokens and AI output tokens;
* AI calls and API calls;
* webhook deliveries;
* storage;
* exported rows;
* automation runs;
* active users (each day’s value is that day’s snapshot, so a range total is read in user-days).

People with the export permission can download a meter’s usage as CSV with **Download CSV**.

The platform operator sets an upper limit per meter. Your organisation can set a lower monthly budget for any meter; it cannot be above the upper limit. At 80 % and at 100 % of the budget, the organisation’s owners and admins get a notice. Usage is never blocked.

<Screenshot src="/screens/en/settings-usage.webp" alt="Usage page with monthly limits, a budget field per meter, a date range and a Download CSV button" caption="Admin → Usage: daily usage per meter, monthly budgets and CSV download." />

## Support sessions [#support-sessions]

When Akollo support opens a session in your organisation, a **Support session** banner is shown. A support session can read the pages it is allowed to see. It cannot create, change, approve or delete anything, and sensitive fields stay hidden.

## Audit records [#audit-records]

Changes to privileges and configuration are written to the audit log. Administrators read it under **Admin → Audit records**.

## Outbound connections [#outbound-connections]

Connectors such as directory sync reach only the external hosts that your installation’s administrators have allowed. Each connector’s own settings in your organisation narrow this list further. When no allowed list has been set up, connectors cannot reach any external host.

<Mermaid
  title="When a connector may reach an external host"
  chart="`flowchart LR
A[Connector wants to reach a host] --> B{Allowed list set up?}
B -->|No| X[Blocked]
B -->|Yes| C{Host on the installation list?}
C -->|No| X
C -->|Yes| D{Allowed by the connector settings?}
D -->|No| X
D -->|Yes| E[Connection allowed]`"
/>

## Tenant isolation [#tenant-isolation]

Every page, list, export and API response contains only the data of the organisation you are working in. A record from another organisation is reported the same way as a record that does not exist.

## FAQ [#faq]

<Accordions type="single">
  <Accordion title="Can Akollo support change data in our organisation?">
    No. A support session can only read the pages it is allowed to see. It cannot create, change, approve or delete anything, and sensitive fields stay hidden. A **Support session** banner shows when one is open.
  </Accordion>

  <Accordion title="Is usage blocked when we reach our budget?">
    No. Owners and admins get a notice at 80 % and at 100 % of the budget, but usage is never blocked.
  </Accordion>

  <Accordion title="Where do I see who changed a role or a setting?">
    Changes to privileges and configuration are written to the audit log. Administrators read it under **Admin → Audit records**.
  </Accordion>

  <Accordion title="Why does my background disappear in another browser?">
    The background you set under **Appearance** is stored in the current browser only.
  </Accordion>

  <Accordion title="Can someone from another organisation see our records?">
    No. Every page, list, export and API response contains only the data of the organisation you are working in.
  </Accordion>
</Accordions>
