> ## Documentation Index
> Fetch the complete documentation index at: https://docs.yorlet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Team and security

> Invite people onto the account, and require two-step authentication when they sign in.

Anyone who uses this account needs an invite and a role. You can also require two-step authentication before they can continue.

Manage the team from [Team members](https://dashboard.yorlet.com/settings/team).

## Invite a team member

To invite someone, follow these steps:

1. Go to [Team members](https://dashboard.yorlet.com/settings/team).
2. Click **New member**.
3. Under **Email**, type an address and press Enter. Add as many as you need.
4. Choose a **Role**: **Admin**, **Developer**, **Finance Plus**, **Finance**, **Operations Plus**, **Operations**, or **View Only**.
5. Click **Invite**.

**Members** lists people who have joined. **Invites** lists invitations still waiting.

From the organization view, you also choose which **Accounts** they can access.

## Change a role or remove someone

Open the overflow menu (•••) on their row.

* **Update** changes their **Role**. Click **Update** to save it.
* **Remove** takes away their access straight away.

<Warning>
  Removing a team member cannot be undone. They lose access as soon as you click **Remove**.
</Warning>

## Require two-step authentication

Two-step authentication is a second check at sign-in. Some actions, such as [approving an owner payout](/owners/owner-payouts#approve-a-payout), already require it on your own user.

To require it for everyone, follow these steps:

1. Go to [Two-step authentication](https://dashboard.yorlet.com/settings/security/authentication).
2. Turn on **Require two-factor authentication**. Anyone without it is asked to set it up the next time they sign in.
3. Click **Save**.

This change, and other settings changes, are recorded in the [activity log](/account/audit-logs).
