Skip to main content

Security Settings

Learn about Security Settings in Recollective, covering password best practices and advanced options like 2FA enforcement, password complexity, session duration, and account lockout.

Recollective includes a number of important settings and security capabilities, providing you with the granular control necessary to minimize risk and build participant trust.

Basic Recommendations

A number of security features can be controlled by site administrators. The two most basic considerations relate to users' passwords.

We recommend the following best practices:

  • Have participants choose their own passwords or at least force them to change the password provided upon their first visit.

    • Participants are more likely to remember their password if they created it themselves.

    • Assigning the same password to all participants can be a good backup for potential login issues at the outset of the study, but it can increase the risk of unauthorized user access. Make sure that participants are required to change their password after their first successful login to strengthen their account security.

  • Never include passwords in email, as emails are sent in plain text and will persist in the participant's inbox for quite some time.

    • If the passwords are not temporary, avoid sending participants their passwords over email.

Advanced Security Options

The following security options are also configurable for a site in the Site Administration area under Site Settings: Account Settings and Site Settings: Email Settings.

⚠️ Note: Due to usability concerns, we don't recommend enabling all security options at once.

Enforce use of two-factor authentication (by role)

Learn more about Two-Factor Authentication.

Two-Factor Authentication (2FA) adds an extra layer of security to an individual account by requiring a single-use code every login. Typically, a mobile phone app is used to generate a unique 6-digit code every 60 seconds, which can then confirm that the individual attempting to log in is indeed the account owner. Individuals using 2FA must have a Recollective account and a second device.

2FA is permitted for all Recollective accounts for additional security by navigating to one’s personal account settings. It can also be enforced for select user roles in Site Settings: Account Settings.

We do not recommend enforcing 2FA for participants unless they are all familiar with using two-factor authentication.

Enforce greater password complexity

You can configure Password Rules to define an acceptable password for Recollective accounts. Enabling more password rules can increase password complexity for higher account security. The following options are available:

  • Require a minimum length of password (e.g. at least 6 characters)

  • Require at least one uppercase (A-Z) and one lowercase letter (a-z)

  • Require at least one digit (0-9)

  • Require at least one symbol (!@#$%^&*()_+|~-=\`{}[]:";'<>?,./)

  • Force passwords to be changed periodically (password expiry)

Password rules are defined separately for Panelist accounts and Administrator accounts. Please note, newly added rules will only apply to new or updated passwords, not existing ones.

Block re-use of past passwords

Password Expiry can be enabled under Password Rules, and forces accounts to change their password periodically. If periodic password expiry is enabled, various additional options become available:

  • Period of time until password expiry (e.g. 'every 90 days')

  • Number of days before password expiry to send a warning email that a new password must be selected soon

  • A grace period for the number of days after password expiry that the current password can be used (after entering the current password, users will be immediately prompted to select a new one)

  • Period of time before previous account passwords can be reused (e.g. 'within the last 12 months')

Increasing the period of time before passwords can be reused can encourage password variety and reduce the risk of account security breaches

Reduce the idle time required before a session expires

The Session Duration controls when a user must log in again after a defined period of inactivity (in minutes). Decrease the number of minutes for a session to reduce the likelihood of unauthorized access to a user’s account if they forget to log out. Session duration is uniquely defined for Panelists and Administrators.

Lock accounts after fewer failed login attempts

Multiple failed login attempts in succession may signal that someone is trying to gain unauthorized access to an account. Under the Account Security section, you have the option of setting limits for the number of failed login attempts before the account is locked. The following options are available:

  • The number of failed login attempts before lockout

  • The period of time the lockout will last

  • Administrators to be notified when an account is locked

Reducing the number of failed login attempts can discourage unauthorized users from forcing access to the account.

Note: Locked accounts will be automatically unlocked after the defined lockout period has passed. If an account needs to be unlocked before the lockout period ends, Analysts have the ability to manually unlock accounts. Learn more about how to unlock an account after too many failed logins.

Notify multiple administrators when accounts get locked

Under the Account Security section, you have the option of selecting which (if any) administrators will be notified when an account has been locked after too many failed login attempts.

Select multiple Analysts to be notified of a locked account helps to inform administrators which accounts may be at risk so they can take action as soon as possible.

For at-risk accounts, you may consider notifying the account owner and asking them to change their password, or enforcing two-factor authentication.

Disable automatic login on emailed broadcasts

By default, all email broadcasts will contain a specialized link allowing recipients to automatically log in to the platform for up to 24 hours after being sent.

Note: Panelists using a valid automatic login link will immediately enter the platform. However, Admins who click an automatic login link will also be required to provide a verification code sent to their email.

To prevent unauthorized users from accessing the platform, you might consider disabling automatic login or decreasing the number of hours an automatic login link is valid for.

Disabling automatic login:

  • If you would like to disable automatic login for select broadcasts: This can be done while creating your email broadcast by simpy disabling the automatic login toggle next to the Login Button field.

  • If you would like to disable automatic login for all broadcasts: navigate to Site Settings: Email Settings and turn off the "Enable automatic login links in email broadcasts" toggle switch.

Decreasing the number of hours an automatic link is valid for:

  • Navigate to Site Settings: Email Settings and customize the "Only allow automatic login for x hours after a message is sent"

    • You can select any number up to 24 hours

  • If someone clicks on an expired automatic login link, they will have the option to either enter their username and password or provide a verification code sent to their email.

🗣️ Still have questions or want to leave feedback on how we can do better? Contact us at [email protected].

Did this answer your question?