Skip to content
Office-X
Partners Pricing Add-ons FAQ Help Center
Sign in Start free trial →
Features & Solutions

Everything You Need to
Make Your Workplace Smarter

Office-X brings your people, payroll, clients, and daily operations together in one secure workspace.

Employee Management
Onboarding & Performance Manage and track growth
Attendance & OT IP-locked check in + overtime
Time off / Leave Requests, balances & approvals
Internal Support Tickets & helpdesk
Payroll Paystubs & Tax statements
Work Shifts Schedule Create and manage rosters
Business Management
CRM Manage leads, clients & sales
Estimate & Agreements Quotation + e-sign docs.
Web & AI Phone Bookings Automated scheduling
Activity Log Who did what, when & where
Permissions & Approvals Multi-level approval flows
Business Management
Task Management Assign & track work
Asset & Incident Tracking Track assets & report incidents
Bill, Travel & Purchase Approve & manage expenses
Holiday Calendar Company-wide holidays
Email Templates & SMTP Branded emails & delivery
Employee Management
Onboarding & Performance Attendance & OT Time off / Leave Internal Support Payroll Work Shifts Schedule
Business Management
CRM Estimate & Agreements Web & AI Phone Bookings Activity Log Permissions & Approval Flow Task Management Asset & Incident Tracking Bill, Travel & Purchase Holiday Calendar Email Templates & SMTP
Partners Pricing Add-ons FAQ Help Center
Sign in Start free trial

Getting Started

1
  • Getting Started with Office-X

Subscription & Billing

1
  • How Seats Work in Office-X

Features & Modules

80
  • Overview
  • Business Management
    • Company
    • Billing & Payment
    • Payroll Configuration
    • Business Support
  • Employees Module
    • Employee List
    • Adding a New Employee
    • View Employee Details
    • Edit an Employee
    • Reset Password
    • Work Hours/Shift Hours
    • Change Status
    • Assign/Unassign Seat
    • Opening Balance
    • Assign Work Days
    • Visual Guide
  • Privacy & Security
    • Security
  • Performance Management
    • Performance Management
  • Work Shifts
    • Work Shifts
  • Tasks
    • Schedule
    • History
    • Customers
  • Holidays Calendar
    • Calendar
  • Attendance Management
    • Attendance Records
    • Individual Attendance Summary
    • Overall Attendance Summary
    • Visual Guide
  • Leave Management
    • Create Leave
    • Approve & Reject Leave
    • Cancel Approved Leave
    • View All Leaves
    • Visual Guide
  • Bill Management
    • Create Bill
    • Approve & Reject Bill
    • View All Bills
    • Visual Guide
  • Travel Requests
    • Create Travel Request
    • Approve & Reject Travel Request
    • View All Travel Requests
    • Visual Guide
  • Purchase Requests
    • Create Purchase Request
    • Approve & Reject Purchase Requests
    • View All Purchase Requests
    • Visual Guide
  • Payroll (Bangladesh)
    • Business → Payroll Configuration
    • Payroll Management
    • Income and Tax Statement
    • Visual Guide
  • Incident Report
    • Incident Report
  • Asset Tracking
    • Asset Tracking
  • Admin Module
    • Department
    • Designation
    • Pay Type
    • Employment Status
    • Leave Types
    • Benefits
    • Expense Category
    • Teams
    • Forms
    • Events & Announcements
    • Incident Configuration
    • IP Configuration
    • Currency
    • Support Categories
    • Integrations
  • CRM
    • Clients
    • Items
    • Estimates
    • Docs
    • Agreements
    • Bookings
  • Support
    • Create Support Request
    • Resolve Support Requests
    • View All Support
    • Visual Guide
  • Activity Logs
    • Activity Logs
  • Permissions & Approval Flows
    • Permissions Management
    • Approval Flows
  • SMTP & Email Templates
    • SMTP Config
    • Email Templates
View Categories
  • Home
  • Docs
  • Features & Modules
  • Privacy & Security
  • Security

Security

On Settings → Security, manage account protection features including password updates and two-factor authentication requirements for employees.

The Security section allows you to update your account password and enables administrators to enforce Two-Factor Authentication (2FA) for employee logins. These features help ensure that only authorized users can access the system and that accounts remain protected.

Who Can Use This Feature #

Subscriber Admin can always access the Security tab and use both cards on it.

Employees can access the Security tab only if they hold the permission below — without it, the entire Security tab (both the Change Password and Two-Factor Authentication cards) doesn’t appear in their Settings at all.

Permission Behavior

  • Employee Forgot & Change Password (For Own) — View
    Lets you see the Security tab in your own Settings.
  • Employee Forgot & Change Password (For Own) — Update
    Lets you change your own password and turn your personal Two-Factor Authentication on or off.

Good to know: despite its name, this one permission covers your whole personal Security tab — there’s no separate permission for the 2FA toggle; it’s controlled by the same one as Change Password.

This permission can be assigned directly to an employee, or to an entire team at once. See the Permissions Management guide for how to assign permissions.

Change Password #

This card works the same way for everyone — Subscriber Admins and employees alike — since it only ever changes your own password.

Provide your current password, enter a new password, and confirm it. The system updates your password only after your current password is verified and the new password and confirmation match.

Your new password must:

  • Be at least 8 characters long.
  • Include at least one uppercase letter, one lowercase letter, one number, and one special character (such as @ $ ! % * ? &).

Once your password is updated successfully, you’ll be signed out immediately and need to log back in using your new password.

Two-Factor Authentication (2FA) #

Unlike Change Password, this card looks and behaves differently depending on who’s logged in — a Subscriber Admin sees a company-wide switch, while an employee sees a personal one.

For Subscriber Admins #

Your card is titled “Two-Factor Authentication for Employees.” Its toggle doesn’t control your own login — it controls whether every employee in your company is required to complete 2FA verification during login.

  • When enabled, all employees are required to complete 2FA verification during login, and they no longer see a personal 2FA toggle at all — the whole card disappears from their own Security settings entirely rather than just being greyed out.
  • When disabled, employees who have permission to manage their own Security settings can choose to enable or disable 2FA individually. In that case, whether a given employee is asked for an OTP at login depends entirely on their own personal setting.

Good to know: your own Subscriber Admin account always requires OTP verification at every login, regardless of this toggle — this setting only controls whether the same requirement also applies to your employees.

For Employees #

Your card is simply titled “Two-Factor Authentication” and only ever controls your own account — not anyone else’s.

  • If your company admin has enforced 2FA for all employees, you won’t see this card at all — 2FA is already required for you at every login, and there’s nothing to configure.
  • If your admin hasn’t enforced it, and you have permission to manage your own Security settings, you’ll see this card and can turn 2FA on or off for your own account whenever you like.

How Turning 2FA On or Off Works #

This part works the same for both audiences. Flipping the toggle — whether you’re a Subscriber Admin turning it on for the whole company, or an employee turning it on/off for yourself — doesn’t apply immediately. It first needs to be verified:

  1. Flip the switch. A one-time password (OTP) is emailed to you.
  2. Enter the 6-digit OTP in the popup within 3 minutes before it expires. You get 3 attempts to enter it correctly — if you run out, request a new code with Resend rather than continuing to retry the old one.
  3. If it expires or you need another one, you can resend the OTP up to 3 times; after that, you’ll need to wait 10 minutes before requesting more.
  4. Once verified, the 2FA setting is updated and you’ll see a confirmation.

This verification step exists so that no one can silently turn 2FA off on an account (yours or, for admins, the whole company’s) without proving access to that inbox first.

What Happens at Login #

This part also works the same for both audiences. When 2FA is required for an account — always for Subscriber Admins, and for employees only when it applies per the rules above — every login sends a fresh 6-digit OTP to that person’s email, valid for 3 minutes, which must be entered before access is granted. The same resend rules apply — up to 3 resends, then a 10-minute wait.

Summary #

The Security tab covers two things: changing your own password, and controlling Two-Factor Authentication. Subscriber Admin always has full access; an employee needs the Employee Forgot & Change Password (For Own) permission just to see the tab at all. The 2FA card adapts to who’s looking at it — a company-wide switch for the Subscriber Admin, a personal one for everyone else — and any change to a 2FA setting has to be confirmed with an emailed OTP first, the same verification used at login whenever 2FA is required.

Updated on July 21, 2026
Table of Contents
  • Who Can Use This Feature
  • Change Password
  • Two-Factor Authentication (2FA)
    • For Subscriber Admins
    • For Employees
    • How Turning 2FA On or Off Works
    • What Happens at Login
  • Summary

Office-X brings your people, payroll, clients, and daily operations together in one secure workspace.

Facebook Linkedin Youtube

Company

  • Partner Programme
  • Pricing
  • Trust & Security
  • Free Migration

EMPLOYEE MANAGEMENT

  • Onboarding & Performance
  • Attendance & OT
  • Time off / Leave
  • Work Shifts Schedule
  • Payroll
  • Internal Support

BUSINESS MANAGEMENT

  • CRM, Estimate & Agreement
  • Tasks Management
  • Web & AI Phone Bookings
  • Activity log
  • Permissions & Approval Flow
  • Asset & Incident Tracking

Resources

  • Help Center
  • See how it works
  • FAQs
© Office-X. All rights reserved.
  • Terms of Service
  • Cookie Policy
  • Privacy Policy