Product updates

Password sign-in with multi-factor authentication

Teams without single sign-on can now use password sign-in protected by authenticator-app MFA, account lockout, and breached-password checks.

Organizations that don’t use single sign-on can now sign in to Timberline with a password, protected by the same controls you’d expect from an SSO provider.

  • Multi-factor authentication with any standard authenticator app. It is recommended by default, and administrators can require it.
  • Accounts lock after repeated failed attempts.
  • Passwords known to have appeared in public breaches are refused. The check never sends your full password anywhere.
  • New users set their password through a one-time setup link, and administrators can reset a user’s MFA from the Access panel.
  • “Forgot password” responds the same way for every address, so it can’t be used to discover who has an account.

SSO remains available and recommended for organizations that have it.

  1. Invitation-only access and an Access panel for administrators

    Accounts now require an invitation, and administrators can manage members and invitations without any access to conversations.

  2. Security hardening across the platform

    Per-tenant model isolation, short-lived credentials, cleaner logs, and automatic security patching strengthen how Timberline runs.

  3. Governed web search

    Timberline can now search the public web when an administrator enables it, with identifying details removed from queries first.

See Timberline in practice.

Talk with Timberline