Turning on passkey elevation
Turn on passkey elevation from Settings → Passkey elevation by choosing the categories of sensitive action to protect, setting the verification window, and making sure everyone with dashboard access has registered a passkey before you enable. Once any category is protected, performing one of those actions requires re-verifying with a passkey.
Passkey elevation is step-up verification, not a sign-in method and not login multi-factor authentication. People still sign in exactly as they do today; the passkey is only asked for at the point of a protected action. See What passkey elevation is for the full picture.
Choose which categories to protect
Protection applies per category, so you decide which sensitive actions require a passkey. Select the categories you want to protect from the list on the settings page:
Resource access configuration — creating and updating the access config for a resource.
Access catalog configuration — creating and updating access catalogs.
Direct access changes — granting someone access to a resource directly, and revoking access they already have.
Access approvals — approving or rejecting an access request as an admin, and approving, rejecting or rolling back a provisioning batch.
Offboarding — creating, starting or deleting an offboarding, and changing the offboarding configuration.
API key management — creating, updating or revoking API keys.
Team management — inviting someone to the dashboard, changing a team member's role, and removing a team member.
Security settings — SSO and SAML configuration, the dashboard and employee-portal IP allowlists, revoking a dashboard session, and revoking member portal tokens.
Only the categories you select are protected. Actions outside them never prompt for a passkey.
Set the verification window
Set how long a single verification keeps a session elevated. The window defaults to 15 minutes and can be set anywhere from 1 minute to 8 hours.
On Settings → Passkey elevation, set the verification window.
Save the settings.
One verification covers the whole window: repeated protected actions inside it do not re-prompt. Changing the window does not affect anyone who has already verified — the new value applies from the next verification.
What happens when you save
Turning the very first category on is not gated — that is what starts protection. After that, changing the passkey elevation settings requires a step-up whenever any category is enabled, regardless of which. This stops the protection being switched off from a hijacked session: whoever edits the settings must verify with a passkey first.