Guide
Settings
Manage your own account and sign-in security, your notifications, and (for owners and admins) your team, workspaces, tags and people — all from one place, organised into sections.
What it does
The Settings hub groups everything you can configure into two areas, each with its own sections:
- Account & security — Profile, Security, Communications, Billing & plan.
- Team & organisation — Team, Workspace, Tags, People.
Personal sections (Profile, Security, Communications, Billing) are available to everyone. Team and Tags are owner/admin-only.
Where to find it
Open your account menu (top-right avatar) and choose Settings, or go to /dashboard/settings. It opens on Profile.
- On a wide screen, the sections are a left-hand menu grouped under the two headings.
- On a phone, the menu collapses into a dropdown at the top — pick a section to jump to it.
Step by step
Edit your profile
- Go to Account & security → Profile.
- Change your Name and Job title. (Your email and role are shown read-only here.)
- Click Save changes.
Set or change your password
- Go to Account & security → Security.
- If you signed in with a magic link, a social account or a passkey and have no password yet, you'll see Set a password — choose one, confirm it and click Set password. A password is a new way into your account, so you're first asked to Confirm it's you: unless you signed in within the last ten minutes, click Sign in again, sign in, and you come back here to set it (type it again). We then email you to say a password was added. You can now also sign in with your email and password.
- If you already have a password, you'll see Change password — enter your current password, then your new one twice. Changing it signs you out on every other device, every time; you stay signed in on this one.
- A password can be anything from 8 to 128 characters. The bars under New password show how easy it would be to guess, and why; they are advice, not a rule. Click the eye at the end of any password field (Show password) to see what you've typed.
Turn on two-factor authentication
- Go to Account & security → Security and find Two-factor authentication.
- Click Set up. (It is greyed out until you have a password — set one first, above.)
- Enter your password and click Continue.
- Scan the QR code with an authenticator app (Google Authenticator, 1Password, Bitwarden — any TOTP app), or click Can't scan it? and type the key. Enter the 6-digit code and click Turn on.
- Save your ten backup codes (Copy codes) somewhere safe, then click I've saved them. They are shown only once.
From then on, signing in asks for a code whichever way you sign in — your password, an email sign-in link or Google/Microsoft/Apple. Signing in with a passkey stays one step. To turn it off, click Turn off, enter your password and click Turn off again.
Change your email
- Go to Account & security → Security.
- Under Email address, type the new address and click Change email.
- If your current email is verified, we email a confirmation link to your current address; approve it, then confirm from the link sent to the new address. If your current email is unverified, the change applies immediately.
Add or remove a passkey
- Go to Account & security → Security → Passkeys.
- Optionally give it a name (e.g. MacBook Touch ID), then click Add a passkey.
- Confirm it's you. A passkey is a new way into your account, so Threadwork first checks it's really you — unless you already confirmed in the last ten minutes:
- Two-factor on: enter the 6-digit code from your authenticator app, or click Use a backup code, then Confirm.
- A password but no two-factor: enter your password, then Confirm.
- Neither (you sign in by email link or Google/Microsoft/Apple only): click Sign in again. You're signed out, and after signing in you come back to this page — then click Add a passkey again within ten minutes.
- Follow your device's prompt (Touch ID, Face ID, Windows Hello or a security key).
- We email you to say a passkey was added — its name and when. If you ever get that email and it wasn't you, remove the passkey here and change your password.
- To remove one, click the bin icon next to it. Removing doesn't ask you to confirm.
Connect or disconnect a social login
- Go to Account & security → Security → Connected accounts (shown only if social logins are enabled for your site).
- Click Connect to link a provider (Google / Microsoft / Apple), or Disconnect to unlink one. You can't unlink your only remaining way to sign in.
Choose your notifications
- Go to Account & security → Communications and untick any type you don't want reaching your bell (mentions, assignments, replies, kudos, flags, room messages, and so on). Changes save instantly and apply only to you.
Manage your team (owners/admins)
- Team & organisation → Team — edit the Team name, Default post visibility, the Edit window (minutes) (how long after posting a member may still edit), and the Default hourly rate (£) (values logged time and powers cost budgets on Reports; set to 0 to turn costing off). There's also a Report note field for an optional line of text (max 280 characters) shown at the top of Reports and included in the CSV export (leave blank for none); under it, a note links to Automations, where Clear tags when a record is resolved now lives as an organisation rule (see the Automations guide). The form is in steps you can jump between; Save changes checks every step and, if one needs fixing (an empty team name, or an edit window over 1440 minutes), opens it with the reason shown.
- Workspace — see all your workspaces and create a new one; click any to open it.
- Tags — manage tag categories and tags (owners/admins only).
- People — view everyone in your team and invite new members.
What each screen shows
- Left menu / mobile dropdown — the two groups and their sections; the current section is highlighted.
- Profile — your name and job title (editable), plus your email and role (read-only).
- Security — your email and verification status, set/change password, two-factor authentication, your passkeys, and connected social accounts. If you're a Threadwork administrator sent here from the admin panel, a note at the top says what the panel needs.
- Communications — a checklist of notification types.
- Billing & plan — a placeholder; your team is currently on the free plan.
- Team / Workspace / Tags / People — the team defaults form, the workspace list, the tag manager, and the people directory.
Tips and good to know
- The post edit window controls how long edits are allowed; set it to 0 to always allow editing.
- Members who aren't owners or admins don't see Team or Tags, and see team defaults read-only.
- Passkeys need a supporting browser/device; if yours doesn't support them you'll see a short note instead of the button.
- Adding a passkey, or setting your first password, asks you to confirm it's you (your code, your password, or signing in again) and then emails you. That way someone who finds you signed in on a shared computer can't quietly add a way in of their own.
Troubleshooting
| Problem | What to try |
|---|---|
| Can't see Team or Tags | They're owner/admin-only — ask an admin. |
| "Change password" rejects my current password | Re-enter it carefully; if you've forgotten it, sign out and use the password-reset link on the sign-in page. |
| Can't disconnect a social account | You can't remove your only sign-in method — set a password or add another method first. |
| Email change didn't take effect | If your current email is verified you must approve the change from your current inbox, then confirm from the new address. |
| Two-factor Set up is greyed out | Two-factor protects a password — set one under Set a password first. |
| "That code didn't match" | Codes last 30 seconds. Check your device's clock is right and try the next code. |
| Asked to Sign in again even after confirming, when adding a passkey | A passkey can only be added within a day of signing in. Click Sign in again; you come back to Security to add it. |
| "Too many wrong attempts — sign in again to continue" when adding a passkey | Five wrong codes or passwords lock that sign-in. Click Sign in again, then add the passkey from Security. |
| An email says a password was added, but it wasn't you | Reset your password from the sign-in page (Forgot password) straight away — that signs out every device — then check Security → Passkeys. |
| An email says a passkey was added, but it wasn't you | Go to Security → Passkeys, remove the one you don't recognise, and change your password. |