# Protect your account and manage access

Use the security tools appropriate to your role.

Type: How-to guide

For: All users; owners managing academy permissions

Before you start: A signed-in account. Sensitive actions can require recent multifactor verification.

Reviewed: 2026-09-16

## Protect your sign-in

Open Academy → Security or your account settings. Use the available passkey or password and authenticator setup. Store recovery information securely outside shared academy documents.

1. Check your account email and enabled sign-in methods.
2. Review active sessions and end any you no longer recognise.
3. Complete a fresh verification when a sensitive action asks for it.
4. Contact the academy or Kelab support if account recovery is needed; never share an authentication code.

## Grant only the access needed

Owners use Roles & access to review memberships and role assignments. Coach scope, finance access, care permissions and family relationships have different effects.

Review access when a staff member changes responsibilities or leaves. A role selector changes presentation, not the underlying authorisation. Support access, where used, should follow the academy's explicit grant and audit workflow.

## Related guides

- [Roles, relationships and permissions](https://kelab.app/docs/roles-access.md)
- [Join, sign in and switch academies](https://kelab.app/docs/joining-signin.md)
- [Request an export or account deletion](https://kelab.app/docs/privacy-requests.md)
- [Why some actions need another review](https://kelab.app/docs/approvals.md)
