Account and security

Passwords, two-factor authentication, sessions and what to do if something looks wrong.

Your account settings are separate from any project — find them under your name at the top of the page, not inside the sidebar. This covers what is there and why it works the way it does.

Changing your password

Go to Account settings › Password. Choose a strong, unique password of at least 8 characters that you do not reuse elsewhere. Changing your password does not sign out your other sessions automatically; sign out of a device separately if you believe it should no longer have access.

Two-factor authentication

Two-factor authentication (2FA) is optional per account, using a time-based one-time code (TOTP) from an authenticator app. Go to Account settings › Two-factor authentication and choose Enable. You will be asked to re-enter your password first, then:

  1. Scan the QR code with your authenticator app (or enter the secret key by hand if you cannot scan), and enter the six-digit code it produces to confirm the app is set up correctly.
  2. Save the backup codes shown once at setup. Each one signs you in a single time if you lose access to your authenticator app. They are not shown again, so store them somewhere safe before continuing.

Once enabled, every sign-in asks for a code after your password. The account settings page shows how many backup codes you have left; if you use one, it is marked used immediately and cannot be reused. Using a backup code triggers an alert on your account as a precaution.

To turn 2FA off, go to the same page and choose Disable, confirming with your password.

Note

CARDO holds commercially sensitive cost and programme data. If your account can approve mitigation assessments, run simulations, or publish rates, turning on 2FA is worth the two minutes it takes.

Sessions and signing out

Signing in creates a session that lasts up to 14 days, held in a cookie that cannot be read by page scripts and is only ever sent over HTTPS. Signing out ends that session immediately; closing the browser without signing out leaves it active until it expires on its own.

Signing in with Microsoft

If your company has set it up, Sign in with Microsoft on the sign-in page lets you authenticate with your organisation’s Microsoft account instead of a CARDO password. Your CARDO account must already exist — this signs you into it, it does not create one on its own.

If something looks wrong

If you see a project, a risk, or a figure that should not be visible to you, or your access seems wrong in either direction, contact your company’s administrator first — most of what looks like a bug is a role or an override set differently to what you expected (see Roles and permissions).

If you believe an account was accessed without authorisation, or you have found a genuine security issue rather than an access question, see reporting a vulnerability on the Trust Centre.

Still stuck?

Tell us what you were trying to do and what happened instead. A screenshot of the page helps more than a description of it.