Everything about you as a person lives under Account, reached from the bottom of the sidebar. It has five pages: Profile, Security, Sessions, API tokens, and Preferences. These settings belong to your login and follow you across every workspace you belong to.
Profile
- Name: how you appear in every workspace (up to 120 characters).
- Email: read-only. "Your email address is your login. Changing it is a follow-up."
Preferences
"Language, time zone, and notifications follow you across workspaces."
| Field | Meaning |
|---|---|
| Language | Workspace default, English, or Norwegian (Bokmål). Leave it on the workspace default to follow each workspace's setting. |
| Time zone | An IANA time zone or Workspace default. "Used for dates and the weekly grid." Time entries record the time zone you logged them in. |
| Theme | System, Light, or Dark. Stored in this browser only. |
| Email notifications | One of three modes, below. |
| Expected minutes per week | 0 to 10 080. "Optional. The pre-close checklist flags weeks below this total." The weekly grid shows your total against it. |
The three notification modes
SAQ notifies by email only; there is no in-app notification centre. Every mail is checked at send time against what you can see then, so losing access to a ticket means no mail about it.
| Mode | What you receive |
|---|---|
| Everything I can see | New comments, assignee changes, state changes, and mentions on tickets where you are the assignee, the reporter, or a viewer. Workspace users also get a mail for each new Inbox ticket and each restricted review item. |
| Mentions and assignments only | Mails when you are mentioned (added as a viewer), when a ticket is assigned to you, and new comments on tickets you are assigned to. Nothing else. |
| None | No email at all. |
Regular client users receive only shared comments and state changes on tickets they started or view, whatever the mode. See Email notifications.
Security
- Password: enter Current password and New password and select Change password. Tick Log out all other sessions to end every other session at the same time. A client user without a password sees "This account has no password yet; set one to get a full login." Passwords need at least 8 characters; passwords seen in known breaches are refused.
- Two-factor authentication: select Enable two-factor, add SAQ to your authenticator app (Open in authenticator app, or enter the key manually), save the recovery codes, enter a code, and select Finish setup. Afterwards every password login asks for a code. Disable two-factor and New recovery codes ask for your current password. Owners and Admins must have two-factor authentication (TOTP or a passkey) to enter their workspace.
- Recovery codes: "Store these somewhere safe. Each code logs you in once if you lose your authenticator."
- Passkeys: give it a Passkey name and select Add a passkey. "A passkey logs you in with your device's unlock and counts as a second factor." Remove a passkey with Remove. Adding a passkey needs a recent full login.
- Delete account: select Delete my account…, type your email address, and confirm your identity. This is permanent and applies to every workspace. Your memberships, client access, invitations, and API tokens end; on the tickets, comments, and time you leave behind your name becomes a placeholder such as "Former member 3"; records that billing and accounting require are kept under that placeholder.
Deletion is refused when:
- you are the only Owner of a workspace ("You are the only owner of these workspaces. Hand ownership to someone else or delete the workspace first"), or
- your session is a magic-link session ("A magic-link session cannot delete the account. Set a password or add a passkey, log in with it, then come back here.").
Sessions
"Everywhere you are logged in. Revoke anything you do not recognise." Each row shows when you logged in, when it expires, and this session for the current one. Revoke ends one session; Log out other sessions ends all but this one; Log out ends this one.
API tokens
Personal API tokens act on your behalf with the same permissions you have, for integrations and AI assistants. Creating one asks you to confirm your password, and the secret is shown once. Regular client users cannot create tokens; elevated client users must name at least one project. For the full rules see API tokens and agents and, for using a token, Authentication for integrations.