# Profile, preferences, and security

> Maintain personal identity, timezone, passkeys, password recovery, and safe session access.

Canonical: https://help.spacebrain.ai/account/profile-preferences-and-security/

## General profile

Open **Settings → General** to update your profile photo, full name, and username. Usernames accept lowercase letters and numbers and must be 2–20 characters. The page displays your sign-in email as read-only; it cannot be changed from Settings. Changing a display name or username does not change connected sender addresses, workspace identity, or billing contacts.

## Preferences and timezone

Open **Settings → Preferences** to manage appearance, a timezone selection, and email-notification selections. The timezone and notification selections currently save to the signed-in user’s browser storage. They may not follow you to another browser, browser profile, or device, and they should not be treated as confirmation that a server-side schedule or notification subscription changed.

Set operational timezones in the module that owns the schedule. For example, campaigns and webinar sessions have their own scheduling context. Document whether a customer-facing time follows a campaign, webinar, workflow, contact, or provider timezone, and verify it in that module before launch. See [workspace and team setup](/getting-started/workspace-and-team) and [feature availability](/reference/feature-availability).

## Passkeys

Where the Passkey settings card is available, choose **Add passkey** and complete the prompt on a device or password manager you control. Spacebrain creates the displayed name automatically from the detected device or platform; the current screen does not ask for a custom label or provide a rename action. The list shows when each passkey was added and, when available, last used.

Add more than one passkey where your authentication policy allows, and maintain a separate working recovery path so the loss of one device does not lock out the account.

Before deleting a passkey, confirm another sign-in and recovery method works. Biometrics generally unlock a device-held credential; Spacebrain does not receive your fingerprint or face scan.

## Password and recovery

Use the sign-in page’s password-reset path and complete email verification. Do not share reset links or one-time codes. If a reset email is missing, check the entered address, spam and quarantine, organization mail rules, and system status before requesting repeatedly.

## Session safety

* Use a unique account for each person.
* Sign out on shared or unmanaged devices.
* Do not approve provider OAuth prompts initiated by someone else.
* Review unexpected invitations, login messages, or reset requests as a security event.
* Report suspected account compromise immediately and rotate affected provider credentials.

## Access changed but the UI did not

Save work, refresh, or sign out and back in after a role change. Confirm the active workspace. Access can also depend on agency tier, plan, or staged feature availability.

If a read-only sign-in email is wrong or you cannot complete recovery, gather the workspace name and exact error, then follow [contact support](/troubleshooting/contact-support).

