Your Octal HR account contains sensitive employee data — salaries, CNICs, bank accounts, and personal records. The most impactful thing you can do to protect it is enable two-factor authentication (2FA). This guide covers 2FA setup, login lockout, and the audit log.

Why 2FA matters

An unprotected HR system is a high-value target: salary data can be used for identity theft, CNIC numbers for fraud, and bank account details for financial crimes. 2FA adds a second verification step at login, so an attacker who has the password still cannot get in without the code from your phone.

Enabling two-factor authentication (2FA)

Octal HR uses time-based one-time password (TOTP) 2FA — the same standard used by common authenticator apps.

1
Open your account Security settings.
2
Click Enable 2FA. A QR code is displayed.
3
Open an authenticator app on your phone (Google Authenticator, Microsoft Authenticator, or Authy) and scan the QR code.
4
Enter the 6-digit code from the app to confirm setup. 2FA is now active on your account.
Save your recovery codes! When you enable 2FA, Octal HR gives you a set of one-time recovery codes (8 codes). Store them in a safe place (password manager, or printed and locked away). If you lose your phone, you'll need these to regain access. You can regenerate a fresh set from your Security settings at any time.

Remember this device

At the 2FA prompt you can choose to remember this device, so you are not asked for a code again on that trusted device for a set period. Leave it unchecked on shared or public computers.

Login lockout

To block password-guessing, Octal HR limits failed login attempts:

  • After 5 failed login attempts, the account is temporarily locked for 30 minutes.
  • This is enforced automatically for both admin/HR users and employee self-service logins.
  • The lock clears automatically once the 30-minute window passes.

Audit log

Security-relevant events are recorded in the audit log, each entry stamped with the user, action, IP address, and timestamp. Logged events include 2FA being enabled, disabled, verified, or failed, recovery codes being regenerated, and logins. Open it from Audit Log to review activity on your account.

Security recommendation: Enable 2FA on every Admin and HR Manager account and keep your recovery codes somewhere safe. It is the single biggest reduction in your risk exposure.