- Is multi-factor authentication supported?
- Yes. Time-based one-time password (TOTP) two-factor authentication works with any standard authenticator app, is available to every user on every plan at no additional cost, and is backed by single-use recovery codes stored as keyed hashes.
- Can MFA be enforced for all users in an organization?
- Yes. An administrator can require two-factor authentication workspace-wide; users without it are required to enroll before they can continue working. Administrators can see how many users have not yet enrolled.
- Is single sign-on supported?
- Google and Microsoft sign-in are supported. SAML-based enterprise SSO is not currently offered.
- How granular is the permission model?
- Over 110 individually-controlled permissions, assembled into roles that each organization defines. Access checks test for a specific permission rather than a role name, so renaming or adding a role cannot inadvertently widen access.
- How quickly is access revoked when someone leaves?
- Immediately. Removing a member blocks sign-in and invalidates sessions already open; the database-level policies stop returning that user any workspace data at the same moment.
- What is the password policy?
- Passwords are handled by the managed authentication platform, stored using industry-standard one-way hashing, with a minimum length requirement and rate limiting on failed sign-in attempts. Coastline staff cannot read user passwords.