Security Best Practices

Updated August 6, 2026 1 min read
  1. Enable two-factor authentication for all admin and finance-related accounts, at minimum.
  2. Review API key scopes regularly — see API Keys & Webhooks — and revoke any keys no longer in use.
  3. Set a password policy under Company Settings → Security (minimum length, expiration, reuse rules).
  4. Limit admin roles to only the people who need them — most day-to-day users shouldn’t need admin access.
  5. Monitor login activity — GEMS logs sign-ins per user; review this periodically for anything unexpected.

Leave a Reply

Your email address will not be published. Required fields are marked *

Scroll to Top