Skip to content

Security settings

Require two-factor sign-in for your team, and set the sign-off, safety, photo and clock-in rules for everyone in your workspace.

For ownersLast reviewed
On this pageBefore you start

Settings → Security holds your own password and the rules that apply to everyone in your workspace: two-factor sign-in, customer sign-off, the pre-work safety checks, photo flagging and clock-in location.

Before you start

  • Only the owner and admins can open Settings. Both can change every rule on this page except Owner approves safety documents before a job is scheduled, which only an owner can change.
  • Each rule has its own save button. Turning a switch on or off does nothing until you select the button under it. ONYX1 then shows Saved.

Change a rule

  1. Open Settings → Security.
  2. Turn the switch for the rule on or off.
  3. Select Save policy or Save under that switch.

Every change is recorded in the audit log with who made it.

Your password and two-factor

Your password is the same form everyone has on My account. The line under it shows Two-factor: enabled or not enabled. If it isn't enabled, select Set up 2FA. Your account, password and two-factor authentication walks through both.

Team policy

Require two-factor for everyone in your team is off until you turn it on. Once it's on, anyone in your workspace who hasn't set up two-factor authentication is sent to set it up before they can open any page, and that includes you. Set up your own first.

Job policy

Require a customer sign-off before a job can be marked ready to invoice is off until you turn it on. With it on, a job can't move to Ready to invoice until a customer sign-off is captured on the job. ONYX1 shows Capture the customer sign-off below before marking this job ready to invoice.

You can still exempt (or require) sign-off on a single job: on the job page, choose Required for this job or Not required for this job instead of Company default.

Pre-work safety pack

This group has three rules. All three are off until you turn them on.

  • Require the pre-work safety pack on new jobs. A new job can't be saved until its SSSP and rescue plan are uploaded and the WorkSafe notification question is answered. It can't be scheduled or started until the client has accepted its quote, and a job with no quote is blocked too. Jobs already under way aren't affected, and recurring jobs made from an existing job are exempt.
  • Owner approves safety documents before a job is scheduled. A job can't be scheduled, reach its crew, or show its SSSP and Rescue Plan on the client portal until an owner approves them or marks that none are needed. While it's off, the owner sees how many jobs switching it on would send to Awaiting approval. An admin sees the switch but can't change it, with Only an owner can change this. Job safety documents and owner approval explains what happens to existing jobs.
  • Flag photos that carry no camera information. A photo whose file can't be tied to a camera gets a badge and goes into Approvals → Photos for someone to look at. Screenshots, photos forwarded through a messaging app and photos cropped in the phone gallery all lose that information, so most flagged photos are honest work. With the rule off, a photo carrying a real AI-generation marker is still refused when it's uploaded.

Time and clock-in

Record where staff clock in and flag off-site clock-ins is on unless you turn it off. It uses the phone's location to note when someone clocks in away from the job's site. It never blocks a clock-in; it only flags it. Turn it off to stop ONYX1 capturing location at clock-in.