Account & security

Your profile & security

Edit your name, change your password, set up two-factor authentication.

Last updated 20 June 2026

Your account settings live separately from the dealership settings — they follow you across dealerships if you have access to more than one.

Profile

Settings → Profile.

Edit:

  • Full name — what your team sees.
  • Phone (optional).
  • Avatar — uploaded image, shown next to your name across the app.

Things you can't edit directly:

  • Email address — it's your login. Changing it requires a separate flow (contact us to start it).
  • Role — that's set per dealership by an owner or manager.

Your full name needs a first and last name. Autopilot uses real names across invites, the sales log, approvals, and audit history, so initials or single-word display names are not accepted.

Password

Settings → Security → Change password.

You'll need your current password to change it. Choose something with at least 12 characters, mix of letters/numbers/symbols. We don't enforce particular character classes but the longer it is, the better — passphrases beat password rules.

Two-factor authentication (MFA)

We strongly recommend turning on MFA. Especially for managers and owners — if your account is compromised, the attacker can drain financial data, hide deals, or worse.

Settings → Security → Two-factor authentication.

  1. Click Enable.
  2. Scan the QR code with an authenticator app (Google Authenticator, 1Password, Authy, Bitwarden — any TOTP app works).
  3. Enter the 6-digit code your app shows to confirm setup.
  4. Save your recovery codes somewhere safe (a password manager). These are your backup if you lose access to your authenticator.

From the next login onward, you'll need to enter your password + a 6-digit code from your authenticator.

If you lose your phone

Use one of your recovery codes. They're one-shot — each can only be used once. If you've used most of them, regenerate the set from the security page.

If you've also lost your recovery codes, contact us — we can manually disable MFA on your account after verifying you're the account owner. It's a slow process on purpose; the whole point is that an attacker can't bypass it easily.

Sessions

We don't have a "log me out of every device" button yet. If you suspect someone has access to your account, change your password — that invalidates every active session except the one where you changed it.

Notifications

Settings → Notifications.

Toggle which events trigger notifications and how they're delivered:

  • Deal events — created, approved, sent back, delivered.
  • Target events — milestone reached, falling behind.
  • Team events — invited, role changed.

Each has separate toggles for email and in-app push (browser notification — you'll get a permission prompt the first time).

You can also set quiet hours — times of day when notifications go silent. Useful if you don't want push notifications at 9pm on a Sunday.

Switching dealerships

If you belong to multiple dealerships (you work at two yards, or you're transitioning between them), use the dealership switcher at the top of the sidebar. Switch instantly without logging out — your role can be different at each one.

Logging out

Click your avatar (top-right) → Sign out. Logs you out of this device only.