Internal reference — super-admin and partner functions. Not for end customers.
User-level security (User Settings > Security)
Two-factor authentication — enabled/disabled per user. When active, shows "Show recovery codes" and "Disable".
Recovery codes — one-time backup codes if the 2FA device is lost.
Browser sessions — audit log of every active login session (browser/user-agent + IP). A trash icon revokes any individual session.
Company-level password policy
Path: Companies > [Company] > Employee Settings > Password Policy. Three sections:
Rules — minimum length; require letters / numbers / uppercase / special characters.
Expiration — enable expiration, require admin reset of expired passwords, expiration period in days.
Extra security — allow users to change their own password; require company-wide 2FA; block passwords found in known data breaches (breach-check).
SSO / OAuth
SSO is configured per white-label brand via the Branding feature-toggle system. The OAuth section has a Microsoft Azure toggle — when enabled, that brand's users can sign in via Azure AD / Entra ID instead of username and password. Accounts are not auto-synced from Azure; each user still exists in Vemcount.
GDPR compliance tool
Path: Companies > [Company] > Location Management > GDPR. Surfaces users with no or inactive locations connected — an orphaned-user cleanup tool. Columns include User, ID, Location, Opening/Active/Closing/Deactivate dates, and Contract Termination. Used to identify and deactivate users whose locations have closed, per data-retention rules.
API key
Path: Avatar > User Settings > API key. Shows the user's personal API key (masked) with a "Generate new key" button. Used for external integrations and data export via the Vemcount REST API.