Two-factor authentication (2FA) adds a second lock on your account: after entering your password, sign-in also requires a 6-digit code from an authenticator app on your phone. Even if your password is stolen, your account stays closed.
Turn it on (about 2 minutes)
- Install an authenticator app if you don't have one — we recommend Google Authenticator (free on iPhone and Android). Any authenticator app works: Microsoft Authenticator, Authy, 1Password, and others.
- Go to Settings → Security and click Turn on 2FA.
- In your authenticator app, tap + and scan the QR code on screen (or enter the setup key manually).
- Type the 6-digit code the app shows and click Verify & turn on. Done.
Signing in with 2FA
Enter your email and password as usual (or continue with Google) — then you'll be asked for the current 6-digit code from your app. Codes rotate every 30 seconds.
Keep access to your authenticator
If you lose the phone with your authenticator app, you won't be able to sign in. Before wiping or replacing a phone, either move your authenticator to the new device first, or temporarily turn 2FA off in Settings → Security and re-enroll after. Locked out entirely? Email support@screenforgelabs.com from your account email and we'll verify your identity to restore access.
Also in Settings → Security
- Auto sign-out: the dashboard signs you out after a period of inactivity (default 60 minutes, adjustable from 15 minutes to 4 hours) with a 60-second warning first — protection for shared or unattended computers. Changes take effect on your next page load.
- Organization policy (owners & admins): a toggle to require 2FA for everyone on your team. After they sign in, members who haven't enrolled land on Settings → Security to set up an authenticator — they are not locked out of the account. Other dashboard pages stay closed until they finish. Turn on your own 2FA first, since the policy applies to you too.
- Google sign-in: attach Google to this account so Continue with Google opens the same dashboard. If that Google email is already a different VolunteerBadge login, invite it from Settings → Team instead of linking.
- Recent sign-in activity — when, from what IP, and on what device your account was accessed.
- Sign out of all devices — instantly ends every session everywhere, for a lost laptop or a suspected compromise.
We strongly recommend 2FA for every owner and admin — your account holds volunteer screening data, and this is the single most effective protection you can turn on.

