Set up authenticators, company SSO, session limits, and recovery.
Email/password users can enable two-factor verification or add a backup authenticator in Settings → Account security. Each new password session then requires a six-digit code. Removing the final authenticator disables two-factor verification. If all authenticators are lost, contact support@embrasure.ai; recovery verifies account ownership and signs out existing sessions.
Company SSO uses SAML for allowed email domains. Enforce MFA in your identity provider; Embrasure does not add an authenticator prompt to SSO sessions. The workspace session limit measures time from sign-in, not inactivity.
Databricks and Snowflake can run interactive queries as the requesting member after a source sign-in verifies their provider identity. Query tokens are short-lived and kept in memory.
For Databricks, choose an Embrasure-managed issuer with a tenant-isolated AWS KMS keyring, or a customer-controlled broker that revalidates the native identity and signs with your own key. Your administrator installs the account-wide trust policy using generated instructions; Embrasure does not receive account-admin credentials. Choose customer-controlled mode if your organization prohibits partner-managed issuers.
Removing trust or a member mapping, disconnecting a member, or deactivating them through SCIM blocks the next query before schema release or model execution.