> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wifipadi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Team and security

> Invite people to your workspace, choose what they can do, and turn on two-factor authentication.

## Invite someone

Only the workspace owner can invite people or change roles.

1. Go to **Settings → Team**.
2. Select **Invite someone**.
3. Enter their email address and choose a role.
4. Send the invitation.

They receive an email with a link to accept. Pending invitations appear under the member list, where you can resend or cancel them. An invitation expires after a set number of days — resend it if someone misses the window.

## Roles

Choose the smallest role that lets someone do their job. Payment keys and billing are owner-only for a reason: they are the two things that can cost you money.

| Role     | Can do                                                                                                       |
| -------- | ------------------------------------------------------------------------------------------------------------ |
| Owner    | Full control, including billing, team and payment keys.                                                      |
| Manager  | Runs the business day-to-day: locations, plans, gateways, customers and branding. No team or billing access. |
| Operator | Floor staff: sees everything, records cash sales and manages vouchers. Cannot change setup.                  |
| Viewer   | Read-only access to every page. Cannot change anything.                                                      |

<Note>
  Recording a cash sale needs **Operator** or higher. Rebooting a gateway or downloading its config backup needs **Manager** or higher, because a backup can contain your WiFi credentials.
</Note>

## Two-factor authentication

Two-factor authentication asks for a 6-digit code from an authenticator app in addition to your password. Turn it on if your account can move money or change payment keys.

1. Go to **Settings → Security**.
2. Enter your current password to begin setup.
3. Scan the QR code with an authenticator app.
4. Enter the 6-digit code from the app to confirm.
5. **Save your recovery codes.** They are shown once.

<Warning>
  Recovery codes are the only way back into your account if you lose your phone. Store them somewhere other than the phone running the authenticator app.
</Warning>

To turn two-factor off, go to the same page and enter your password along with a code from your app or a recovery code.
