Manage account and security
Update your profile and workspace, change credentials, manage preferences, export data, or delete the account.
Profile and workspace
- Update full name and timezone. Email is read-only; your workspace role is shown beside it.
- Upload a square PNG, JPG, or WebP profile image up to 2 MB; 256 × 256 px is recommended. Initials appear when no image is available.
- Owners and administrators can update workspace name, company website, and default language.
- Use the plus button beside the sidebar workspace selector to create another workspace. New workspaces start on Free with separate knowledge, widget, conversations, team, and billing.
- The highest plan among workspaces you own determines your ownership allowance. Invited workspaces never consume it.
- Switch between every workspace you belong to from the workspace selector in the sidebar.
Team members and roles
Owners and workspace administrators can invite teammates by email, assign Member or Admin access, suspend access, revoke pending invitations, or remove a teammate. Members can use the workspace but cannot change its team, identity-provider, billing, or workspace-level settings.
Ownership transfer: Only the current owner can transfer ownership, and the new owner must already be an active workspace member. The previous owner remains an administrator.
Enterprise SSO
Enterprise workspace owners and administrators can verify company domains and configure either SAML 2.0 metadata or an OpenID Connect issuer and client credentials. Credentials are stored by Supabase Auth rather than in AskBrew workspace tables.
Test sign-in is required before enabling the connection. Just-in-time provisioning can add verified employees as Members on first sign-in. Optional enforcement blocks password and social sign-in for verified company domains.
- Publish the displayed TXT value at _askbrew.your-domain and verify it.
- Configure SAML metadata or OIDC issuer, client ID, and client secret.
- Complete Test sign-in with the identity provider.
- Enable Company SSO, choose JIT provisioning, then optionally require SSO.
Workspace audit log
Owners and administrators can review recent membership, invitation, ownership, domain, JIT provisioning, and SSO-policy changes in Settings. Export CSV downloads up to the latest 10,000 events for the active workspace. Audit details intentionally exclude client secrets and SAML metadata.
Password, two-factor and sessions
Changing the password requires the current password, a new password of at least 10 characters, and matching confirmation. Sign out all ends sessions on every connected browser and device.
Two-factor authentication adds an authenticator-app code as a second sign-in step. Enable it under Settings → Security by scanning the QR code with an app such as Google Authenticator or 1Password and confirming a 6-digit code. Once enabled, every sign-in — including Google sign-in — requires a current code before the dashboard opens.
Lost your authenticator?: Turning two-factor off requires a signed-in, fully verified session. If you lose access to your authenticator app, contact support to regain access to your account.
Notification preferences
Performance reports can be delivered weekly, monthly, or turned off. The knowledge-gap preference controls whether open unanswered questions are included in that report. Product updates and tips records marketing preference. Low-confidence alerts and widget sound remain disabled until their delivery and live-monitoring systems are available.
Export or delete data
Export data downloads the active workspace settings, conversations, messages, and knowledge metadata as JSON. A member deleting their account leaves shared workspaces intact. An owner must transfer ownership when teammates remain; deleting the last owner also removes that workspace and its data.
Active subscription: Cancel an active Paddle subscription from Billing before deleting its owner account. Deletion cannot be undone.
Was this page helpful?