Passkeys and security keys
Hardware-backed sign-in where the account and provider support it, with authenticator apps available when a rollout policy calls for them.
An AI workforce reaches your repositories, your production systems, and your credentials. The first control worth asking about is the oldest one, which is who your organization lets through the door and how hard that door is to force.
Hardware-backed sign-in where the account and provider support it, with authenticator apps available when a rollout policy calls for them.
Personal Settings lists the sessions on an account and ends any one of them, or every other one, without ending the session doing the review.
New logins, completed password resets, email changes, session revocations, recovery reviews, and account deletion each raise a notification.
Email verification, password reset, and signed-out access recovery are part of every account, and passkey-backed accounts keep their stronger posture instead of dropping to an email reset.
Sign-in and account events are written as records an organization admin can review beside the rest of the security activity.
Organization roles and project access levels decide who administers security settings and who can see a given project at all.
Codespeed connects to the identity provider your organization already runs, so sign-in follows the policy your security team set there.
Once your domain is verified and mapped to the organization, sign-in for that domain routes through your provider and can be enforced there.
Organization access can carry session controls set for higher assurance rather than the defaults a single account would use.
Configuration passes to your IT owner through a handoff that requires organization admin permission and a recent high-assurance sign-in. Codespeed records the handoff as organization activity and never stores, copies, or emails the setup link.
Recent password reauthentication satisfies sensitive actions on an email and password account, and a recent passkey-backed sign-in satisfies the higher bar. Plain SSO clears it once your organization runs a verified enterprise identity policy.
When a session cannot complete the stronger step, the page keeps a visible Sign In Again action instead of a warning that leads nowhere. The change waits until the sign-in finishes and then returns to the page that asked for it.
An account that has lost every strong sign-in method starts a recovery request rather than falling back to a weaker path. Codespeed provides no silent alternate login.
Organization owners and admins review recovery requests for their organization, and a different owner or admin has to review the request before the manual identity action completes.
Assisted recovery can hold a waiting period and raise security notifications while it runs, so an account takeover attempt has to survive time and attention rather than a single decision.
The review lands as an organization-visible security record without exposing factor secrets or recovery material.
Provisioning and deprovisioning run through your identity provider and your own joiner and leaver process. Settle the removed-member path with Codespeed before the first rollout.
Identity and security records are reviewable in the app. Delivery into a SIEM is agreed as contracted scope, so name the events your security review depends on early.
Codespeed keeps no bypass route around your provider, so making SSO the only sign-in path calls for a recovery plan written for your organization.