Profile & security
Update your personal information, change your password, and enable two-factor authentication to protect your account.
Profile settings
Your profile controls how your name and photo appear throughout Asan CRM — in team views, email signatures, and Cori's greetings.
- Go to Settings → Profile.
- Update your name, email, and phone number as needed.
- Upload a profile photo. Click the avatar area and select an image. Supported formats: JPG, PNG (max 2 MB).
- Click Save.
Changing your password
- Go to Settings → Password.
- Enter your current password to verify your identity.
- Enter and confirm your new password. Use at least 8 characters with a mix of letters, numbers, and symbols.
- Click Update Password.
Two-factor authentication (2FA)
Two-factor authentication adds a second layer of security. After entering your password, you must also provide a 6-digit code from an authenticator app.
- Go to Settings → Security.
- Click Enable Two-Factor Authentication.
- Scan the QR code with Google Authenticator, Authy, 1Password, or any TOTP-compatible app.
- Enter the 6-digit code from the app to confirm setup.
- Save your recovery codes (see below).
Once enabled, every login requires both your password and a fresh 6-digit code from your authenticator app.
Recovery codes
When you enable 2FA, Asan generates 8 one-time recovery codes. Each code can be used exactly once in place of your authenticator code if you lose access to your device.
- Store them securely — in a password manager, printed on paper in a safe location, or in an encrypted file. Do not store them in plain text on your device.
- Each code works once. After use, it is permanently invalidated.
- Regenerate codes at any time from Settings → Security. This invalidates all previous codes and generates a fresh set of 8.
Suspicious login protection
Asan monitors login activity for unusual patterns. When a login attempt comes from a new device or unfamiliar location, additional verification is required:
- Email verification. A one-time code is sent to your registered email address. Enter it to confirm the login.
- Login notifications. You receive an email alert whenever a new device or location is detected, even if the login succeeds.
- Session management. View all active sessions in Settings → Security. Revoke any session you do not recognize by clicking Log Out next to it.
Frequently asked
I lost my authenticator device. How do I log in?+
Can I disable 2FA after enabling it?+
Which authenticator apps are supported?+
How do I update my email address?+
Can my admin see my login history?+
Was this article helpful?