Add a second factor to your sign-in
Pick an authenticator app or a text message under Profile, Security. Practor then asks for a code as well as the emailed link.
Practor has no password. You give it your email address, it emails you a one-time link, and opening that link signs you in.
So your mailbox is the thing worth protecting. Anyone who can open it can open your account, and every patient record your practice holds sits behind it. A second factor means an email on its own isn't enough.
Choose a method
Open your own profile settings and pick Security, under Account.
| Method | What it is |
|---|---|
| Authenticator app | An app on your phone makes the code. It works with no signal, and Practor marks it Recommended |
| Text message | The code arrives by SMS. Marked Weaker, because whoever takes over your number receives it |
Pick the app and Practor shows you a square to scan, then asks for the code the app gives back.
Two more methods can answer a prompt without being set up first: a code emailed to your sign-in address, and a recovery code.
When your practice requires a second factor
A practice can make one compulsory for its team. Until you have one, the emailed link puts you on Set up multi-factor authentication instead of into Practor.
Set this up later gets you past that screen a few times, and the line under it counts down: You can skip this so many more times, then This is the last time you can skip. After that the button is gone and the screen is the only way through.
Platform administration is stricter still. It always asks, with no skips, because those tools reach across every practice on Practor rather than just yours.
Locked out between patients
A flat battery at the wrong moment is the common way this bites. Use a different method under the code box lists what else will work, and a recovery code is one of them.
Those only work if they already exist. Generate codes on the Security page makes the first ten, Regenerate replaces them all, and both offer a copy or a download before you confirm you have kept them. Each is eight characters, shown with a dash in the middle, and each works once.
Keep them somewhere that survives losing the phone, and not in the practice's shared drive. Spend the last one and support becomes the only route back in.
Being asked for a code every time
Trust this device for 30 days sits under the code box at sign-in. Tick it and that machine stops asking for a month.
Leave it alone on a machine you share with the practice. Trusted devices on the Security page lists every one you have, and revoking anything you don't recognise puts it back to asking.
Removing a sign-in method resets the lot too. Neither touches your recovery codes.