Skip to main content

Securing your organizer account

Admin
Securing your organizer account

An organizer account controls other people's money and other people's personal data. It deserves more than a password, and it is worth knowing exactly what protects it — including the protections we deliberately removed.

Two-factor authentication

Turn on two-factor authentication and a stolen password stops being enough on its own. This is the single highest-value thing on this page and it takes about two minutes.

Recovery codes are issued when you enable it. Save them somewhere that is not the phone running the authenticator app — losing a phone should not mean losing the account, and the recovery codes are the whole of that plan.

If you have a team with financial access, this is worth requiring of them rather than suggesting. The account that gets compromised is rarely the careful one.

You are told when your payout destination changes

If the Stripe account your money goes to is connected or disconnected, you get an email about it — including the IP address the change came from.

Two details make this a real control rather than a notification. It is unconditional: it is not subject to a notification preference, and it cannot be muted. A security alert somebody has switched off is not a security alert. And it names the payout destination specifically, because redirecting an organizer's payouts is the single most valuable thing an attacker can do with this kind of account.

Only you know whether that change was you. If an email like that arrives and it was not, that is the moment to act — reset your password, check your Stripe account, and look at who has access to your team.

Team access is scoped

Team members get permissions per event rather than blanket access. Somebody helping with the door does not get your finances, and somebody handling marketing does not get your payouts.

Removing a person removes their access. That sounds obvious and is the part most often done badly elsewhere, where the practical alternative is a shared login nobody can revoke, or an unlisted link that keeps working forever. Relying on a former volunteer forgetting a URL is not a security control.

Review this occasionally. The accounts that cause trouble are usually the ones granted for one weekend eighteen months ago.

Idle sessions sign out

A session left unattended is signed out automatically after a period of inactivity. This is the control that covers the laptop left open at a venue, in a shared office, or on a train — the realistic way an organizer account gets used by somebody else.

It is worth knowing that this is a security setting rather than a convenience one, because the instinct when it interrupts you is to want it longer.

New device notifications

Signing in from an unrecognised device notifies you. In practice this is usually the first sign that something is wrong, and it arrives before any damage is done rather than after — a login from a country you have never visited is a much earlier signal than a payout that went somewhere unexpected.

What we deliberately do not do

We used to challenge you again — a second confirmation prompt, even while logged in — before certain sensitive actions. That has been removed, and it is worth saying why rather than quietly dropping it.

Re-authentication prompts have a well-documented failure mode: people stop reading them. A prompt that appears often enough to be routine is answered reflexively, which means it stops being a decision point and becomes a keystroke. At that point it provides very little protection while making the product tiring to use, and the usual next step is that somebody finds the setting that turns it off.

What covers those actions instead is the combination above: two-factor authentication at login, a session that does not stay open indefinitely, and an unconditional alert the moment a payout destination changes. The alert is the important one — it does not try to prevent the action, it guarantees you find out about it immediately, which is the property that actually limits the damage.

A short checklist

  • Enable two-factor authentication, and store the recovery codes somewhere else.
  • Use a password that is not used anywhere else. A password manager makes this free.
  • Review your team list after every event and remove people who are done.
  • Do not ignore a payout-destination email. It is the one alert that is always worth reading.
  • Keep the email address on the account current — it is where every one of these alerts goes.

Related articles

We use cookies

We use cookies and similar technologies to personalise content, analyse traffic, and improve your experience. You can accept all, reject non-essential, or customise your preferences.