Security Best Practices
- Enable two-factor authentication for all admin and finance-related accounts, at minimum.
- Review API key scopes regularly — see API Keys & Webhooks — and revoke any keys no longer in use.
- Set a password policy under Company Settings → Security (minimum length, expiration, reuse rules).
- Limit admin roles to only the people who need them — most day-to-day users shouldn’t need admin access.
- Monitor login activity — GEMS logs sign-ins per user; review this periodically for anything unexpected.