[{"question":{"category_id":1369274,"account_id":12867,"created_at":"2026-05-22T17:30:44.561Z","tag_names":["2fa","2fa setup","authenticator app","biller genie 2fa","mfa","pci compliance login","secure login","session timeout","totp","two factor authentication"],"answer_sample":"Multi-factor authentication (MFA) adds a second layer of security to your Biller ","long_answer_sample":"Multi-factor authentication (MFA) adds a second layer of security to your Biller Genie sign-in. The primary method is an authenticator app (Google Authenticator, Microsoft Authenticator, Authy, etc.) using a time-based one-time password, or TOTP. If you have not set up the authenticator app or you lose access to it, Biller Genie can fall back to an ","language_id":1,"id":3826870,"last_published_date":"May 26th, 2026","last_published_avatar":"\u003cimg class=\"avatar circle\" width=\"96\" height=\"96\" style=\"background: url(\u0026quot;/initials_avatars/TA?bg=e0633a\u0026amp;s=192\u0026amp;fg=fff\u0026quot;) 0% 0% / 96px 96px;\" src=\"https://secure.gravatar.com/avatar/841e7ea85ebda058cdd7ee30638e7bee.png?s=96\u0026amp;d=blank\" /\u003e","last_published_user_name":"Thomas Aronica","indexable_body":"multi-factor authentication (mfa) adds second layer security biller genie sign-in. primary method authenticator app (google authenticator, microsoft authy, etc.) using time-based one-time password, totp. set lose access it, can fall back email-based secure link. guide walks setting happens device, recovery codes keep locked out. matters account holds sensitive invoice records, customers' stored payment methods, reports use reconcile bank. someone got see it. mfa blocks path requiring proof — code device physically hold letting in. processes payment-card data follows standards required every business handles card payments (pci dss). view move money one standards. turning user simplest thing customers protected. two ways verifies (recommended) 6-digit generated phone 1password, etc.). refreshes 30 seconds. pci guidance considers strongest. email link (fallback) yet temporarily send profile. click instead entering code. fallback path, everyday path. save plus strongest setup. meant one-off recovery, daily sign-ins. sign genie. name top-right corner open profile (account settings → profile). find two-factor button details page. step 1 scan qr \"add account\" \"scan code\" function. point setup scan, page shows manual key type 2 enter verification will start displaying current submit. 3 codes. display 10 single-use (formatted xxxxx-xxxxx). copy download text file store somewhere safe. once. confirm next sign-in onward, ask authenticator-app password. close built-in way get reinstall app. treat like backup key. storage best-practices regenerate needed. signing show prompt. app, entry, signed rest session. new triggers fresh \"remember browser days\" option, design stolen able skip future login. unavailable common scenarios forward still phone, just working time-based, out-of-sync clock break them. make sure date time automatic (network time). wait 30-second tick try freshly displayed lost replaced saved prompt sign-in, switch \"use instead\" codes, works soon in, either intentional, since otherwise protecting anything. support@billergenie.com address. support verify identity (business information, recent numbers, call owner) resetting account. plan taking day. uses enabled admin reset sends asking sender subject mentions verification. validity valid minutes. delivery usually minute. slower providers (outlook particular) take 5 secure-link arrive work checks order. reason merchants reach login issues. three batch incoming mail deliveries several check spam, junk, promotions folder. automated senders sometimes land outside main inbox. correct. resend screen. profile, necessarily originally with. typo, need update (or contact support). provider blocking senders. allowlisting rules include sending domain. ips specific records add. old expires; sent. refresh request another. sent side and, needed, fallback. log 25 minutes signs automatically inactivity. platform level applies extended individual user. inactivity timer resets click, type, navigate inside actively application, logged timeout fires input alongside controls session starts, ends. together idle sessions misused shared unattended devices. more, logs (session security) . frequently asked questions apps standard totp google bitwarden, duo, password managers feature. require pick whichever trust. positioned fallback, gives faster, day-to-day flow comfortable email, today, recommend favors. turn technically yes, strongly leaving on. insurance, payments-industry compliance reviews, rely system data. causing workflow problem, often (email allowlisting, update, re-enrollment) solves without disabling protection. account-wide enforcement roadmap. today enables cleanest workaround part onboarding checklist add verifying identity. avoid future, best-practices. yes. section, \"regenerate codes\" option. replaces unused previous stop working. always ones immediately. full related articles changing completing annual editing company address,","name":"Setting Up Two-Factor Authentication on Your Biller Genie Account","votes":0,"is_published":true,"slug":"setting-up-two-factor-authentication","first_category":"Account \u0026 Billing","categories_display_for_views":"Account \u0026 Billing","parent_categories":[1369274],"is_internal":false,"is_private":false,"extra_categories":[],"url":"/account-and-billing/setting-up-two-factor-authentication?from_search=237965109","host":"https://helpcenter.billergenie.com","body_txt":"multi-factor authentication (mfa) adds second layer security biller genie sign-in. primary method authenticator app (google authenticator, microsoft authy, etc.) using time-based one-time password, totp. set lose access it, can fall back email-based secure link. guide walks setting happens device, recovery codes keep locked out. matters account holds sensitive invoice records, customers' stored payment methods, reports use reconcile bank. someone got see it. mfa blocks path requiring proof — code device physically hold letting in. processes payment-card data follows standards required every business handles card payments (pci dss). view move money one standards. turning user simplest thing customers protected. two ways verifies (recommended) 6-digit generated phone 1password, etc.). refreshes 30 seconds. pci guidance considers strongest. email link (fallback) yet temporarily send profile. click instead entering code. fallback path, everyday path. save plus strongest setup. meant one-off recovery, daily sign-ins. sign genie. name top-right corner open profile (account settings → profile). find two-factor button details page. step 1 scan qr \"add account\" \"scan code\" function. point setup scan, page shows manual key type 2 enter verification will start displaying current submit. 3 codes. display 10 single-use (formatted xxxxx-xxxxx). copy download text file store somewhere safe. once. confirm next sign-in onward, ask authenticator-app password. close built-in way get reinstall app. treat like backup key. storage best-practices regenerate needed. signing show prompt. app, entry, signed rest session. new triggers fresh \"remember browser days\" option, design stolen able skip future login. unavailable common scenarios forward still phone, just working time-based, out-of-sync clock break them. make sure date time automatic (network time). wait 30-second tick try freshly displayed lost replaced saved prompt sign-in, switch \"use instead\" codes, works soon in, either intentional, since otherwise protecting anything. support@billergenie.com address. support verify identity (business information, recent numbers, call owner) resetting account. plan taking day. uses enabled admin reset sends asking sender subject mentions verification. validity valid minutes. delivery usually minute. slower providers (outlook particular) take 5 secure-link arrive work checks order. reason merchants reach login issues. three batch incoming mail deliveries several check spam, junk, promotions folder. automated senders sometimes land outside main inbox. correct. resend screen. profile, necessarily originally with. typo, need update (or contact support). provider blocking senders. allowlisting rules include sending domain. ips specific records add. old expires; sent. refresh request another. sent side and, needed, fallback. log 25 minutes signs automatically inactivity. platform level applies extended individual user. inactivity timer resets click, type, navigate inside actively application, logged timeout fires input alongside controls session starts, ends. together idle sessions misused shared unattended devices. more, logs (session security) . frequently asked questions apps standard totp google bitwarden, duo, password managers feature. require pick whichever trust. positioned fallback, gives faster, day-to-day flow comfortable email, today, recommend favors. turn technically yes, strongly leaving on. insurance, payments-industry compliance reviews, rely system data. causing workflow problem, often (email allowlisting, update, re-enrollment) solves without disabling protection. account-wide enforcement roadmap. today enables cleanest workaround part onboarding checklist add verifying identity. avoid future, best-practices. yes. section, \"regenerate codes\" option. replaces unused previous stop working. always ones immediately. full related articles changing completing annual editing company address,","categories":{"current":{"id":1369274,"name":"Account \u0026 Billing","url":"/account-and-billing"}},"category_param":"account-and-billing"}},{"question":{"category_id":1368782,"account_id":12867,"created_at":"2023-05-16T15:19:43.000Z","tag_names":["add user","add user account","biller genie roles","control panel users","disable user","granular permissions","managing users","multi user account","reactivate user","remove user","settings manager","superuser","team members biller genie","user access","user permissions","user roles"],"answer_sample":"Biller Genie supports multiple users on one account. This article covers everythi","long_answer_sample":"Biller Genie supports multiple users on one account. This article covers everything you need: adding new users, editing them, disabling them when someone leaves, the seven granular permission roles Biller Genie offers, and the constraints around the SuperUser role. All user management happens at Control Panel \u0026gt; Users. To make changes, you need th","language_id":1,"id":1957844,"last_published_date":"June 22nd, 2026","last_published_avatar":"\u003cimg class=\"avatar circle\" width=\"96\" height=\"96\" style=\"background: url(\u0026quot;/initials_avatars/JT?bg=f1ba57\u0026amp;s=192\u0026amp;fg=fff\u0026quot;) 0% 0% / 96px 96px;\" src=\"https://secure.gravatar.com/avatar/fc4f4b69f7e4a4303f236ed2e8c96854.png?s=96\u0026amp;d=blank\" /\u003e","last_published_user_name":"Juan Tobon","indexable_body":"biller genie supports multiple users one account. article covers everything need adding new users, editing them, disabling someone leaves, seven granular permission roles offers, constraints around superuser role. user management happens control panel \u0026gt; users. make changes, step 1. go click add user. 2. enter user's first name, last email address. create 3. receives confirmation address entered. link verify set password. confirm, account created log in. arrive, can resend record. login will require setting password (recommended) enabling two-factor authentication. id open record, edit. edit disable toggle (on only), (if plan includes permissions). yourself, change totp / authentication setup. username (email address) read-only every user, including one. team member's changed, workflow old — way existing flow binds human. (when leaves) member leaves company, immediately revoke access. deleted kept record historical actions (invoices payments processed etc.) still attribute correctly. update disabled immediately. active session invalidated next request genie, longer re-enabling reactivate previously back off. reactivation done superuser. settings manager intentional, prevent non-superuser cause. permissions offers roles. assigned combination them. restrictive (a dashboardviewer see dashboard nothing else); others additive (you give reportviewer + addonsconfigurator without making superuser). role grants super full access automatically another roles, view settings, branding, customer defaults, invoice defaults manage (only can). add-ons installer install uninstall marketplace. include right configure install. configurator already-installed add-ons. ones. subscription editor billing settings. viewer main summary kpis (collections, a/r aging, recent payments). report reports section (pending transactions, rejected sync errors, etc.). none day-to-day work (view customers, send invoices, process payments) elevated capabilities, baseline availability page visible premium plan, (not yourself). like contact support@billergenie.com options. constraint remove logged superuser, blocks accidental lockouts. demote exists, promote teammate first, you. security best practices person shared accounts impossible actions, locks everyone once. use blanket people genuinely account-wide bookkeeper needs dashboardviewer, especially anyone manager. per-user org-wide enforcement today, ask up. departing employees day leave. wait monthly cleanup sessions disable. audit list quarterly. check works related articles recovery codes multi-factor changing general","name":"Managing Users in Biller Genie","votes":0,"is_published":true,"slug":"managing-users-in-biller-genie","first_category":"Control Panel \u0026 Settings","categories_display_for_views":"Control Panel \u0026 Settings","parent_categories":[1368782],"is_internal":false,"is_private":false,"extra_categories":[],"url":"/settings-and-account/managing-users-in-biller-genie?from_search=237965109","host":"https://helpcenter.billergenie.com","body_txt":"biller genie supports multiple users one account. article covers everything need adding new users, editing them, disabling someone leaves, seven granular permission roles offers, constraints around superuser role. user management happens control panel \u0026gt; users. make changes, step 1. go click add user. 2. enter user's first name, last email address. create 3. receives confirmation address entered. link verify set password. confirm, account created log in. arrive, can resend record. login will require setting password (recommended) enabling two-factor authentication. id open record, edit. edit disable toggle (on only), (if plan includes permissions). yourself, change totp / authentication setup. username (email address) read-only every user, including one. team member's changed, workflow old — way existing flow binds human. (when leaves) member leaves company, immediately revoke access. deleted kept record historical actions (invoices payments processed etc.) still attribute correctly. update disabled immediately. active session invalidated next request genie, longer re-enabling reactivate previously back off. reactivation done superuser. settings manager intentional, prevent non-superuser cause. permissions offers roles. assigned combination them. restrictive (a dashboardviewer see dashboard nothing else); others additive (you give reportviewer + addonsconfigurator without making superuser). role grants super full access automatically another roles, view settings, branding, customer defaults, invoice defaults manage (only can). add-ons installer install uninstall marketplace. include right configure install. configurator already-installed add-ons. ones. subscription editor billing settings. viewer main summary kpis (collections, a/r aging, recent payments). report reports section (pending transactions, rejected sync errors, etc.). none day-to-day work (view customers, send invoices, process payments) elevated capabilities, baseline availability page visible premium plan, (not yourself). like contact support@billergenie.com options. constraint remove logged superuser, blocks accidental lockouts. demote exists, promote teammate first, you. security best practices person shared accounts impossible actions, locks everyone once. use blanket people genuinely account-wide bookkeeper needs dashboardviewer, especially anyone manager. per-user org-wide enforcement today, ask up. departing employees day leave. wait monthly cleanup sessions disable. audit list quarterly. check works related articles recovery codes multi-factor changing general","categories":{"current":{"id":1368782,"name":"Control Panel \u0026 Settings","url":"/settings-and-account"}},"category_param":"settings-and-account"}},{"question":{"category_id":1368782,"account_id":12867,"created_at":"2026-05-22T17:31:29.491Z","tag_names":["azure ad","biller genie security","duo sso","enterprise authentication","entra id","federated identity","google workspace sso","jumpcloud sso","oidc","okta biller genie","openid connect","saml","single sign on","sso","sso not supported","sso roadmap"],"answer_sample":"A short, honest answer to one of the most common security-evaluation questions we","long_answer_sample":"A short, honest answer to one of the most common security-evaluation questions we get from larger and enterprise merchants: does Biller Genie support Single Sign-On (SSO) via SAML or OpenID Connect? Current status: SSO is not supported today Biller Genie does not currently support SAML, OpenID Connect, or other federated identity providers (Okta, Az","language_id":1,"id":3826929,"last_published_date":"May 30th, 2026","last_published_avatar":"\u003cimg class=\"avatar circle\" width=\"96\" height=\"96\" style=\"background: url(\u0026quot;/initials_avatars/TA?bg=e0633a\u0026amp;s=192\u0026amp;fg=fff\u0026quot;) 0% 0% / 96px 96px;\" src=\"https://secure.gravatar.com/avatar/841e7ea85ebda058cdd7ee30638e7bee.png?s=96\u0026amp;d=blank\" /\u003e","last_published_user_name":"Thomas Aronica","indexable_body":"short, honest answer one common security-evaluation questions get larger enterprise merchants biller genie support single sign-on (sso) via saml openid connect current status sso supported today currently saml, connect, federated identity providers (okta, azure ad / entra id, google workspace sso, duo jumpcloud, etc.). every user authenticates genie-managed username (email address) password, plus optional per-user two-factor authentication. applies plan tiers, including premium plans granular role permissions. authentication can enable time-based one-time password (totp) back recovery codes. totp works authenticator, microsoft authy, 1password, rfc 6238-compliant authenticator. see setting . limitation 2fa opt-in per user. org-level toggle require everyone. security policy mandates account, need walk enabling it. role-based permissions plans, offers seven (super user, settings manager, add-ons installer/configurator, subscription editor, dashboard viewer, report viewer) give fine-grained control system. managing users session controls auto-logout 25 minutes inactivity production. sessions persisted longer this. logs requirements enforced platform level — minimum length, complexity, check known breached passwords. immediate invalidation disabled user's next api call page request denied, browser tab open. requires practical options take team asking use manager (1password, dashlane, bitwarden business, lastpass business) centralize credential management. combined genie, gives operational benefits central rotation, revocation employee leaves, audit visibility credentials. disable departing employees immediately. revokes access invalidates equivalent scim deprovisioning surface area expose. list quarterly active roster. will future roadmap most-requested features customers. committed timeline. organization needs adopt expand contact support@billergenie.com customer ask gets logged feature weighed planning, let know if/when becomes available beta. related articles codes multi-factor (session security)","name":"Single Sign-On (SSO / SAML) — Current Status","votes":0,"is_published":true,"slug":"single-sign-on-sso-status","first_category":"Control Panel \u0026 Settings","categories_display_for_views":"Control Panel \u0026 Settings","parent_categories":[1368782],"is_internal":false,"is_private":false,"extra_categories":[],"url":"/settings-and-account/single-sign-on-sso-status?from_search=237965109","host":"https://helpcenter.billergenie.com","body_txt":"short, honest answer one common security-evaluation questions get larger enterprise merchants biller genie support single sign-on (sso) via saml openid connect current status sso supported today currently saml, connect, federated identity providers (okta, azure ad / entra id, google workspace sso, duo jumpcloud, etc.). every user authenticates genie-managed username (email address) password, plus optional per-user two-factor authentication. applies plan tiers, including premium plans granular role permissions. authentication can enable time-based one-time password (totp) back recovery codes. totp works authenticator, microsoft authy, 1password, rfc 6238-compliant authenticator. see setting . limitation 2fa opt-in per user. org-level toggle require everyone. security policy mandates account, need walk enabling it. role-based permissions plans, offers seven (super user, settings manager, add-ons installer/configurator, subscription editor, dashboard viewer, report viewer) give fine-grained control system. managing users session controls auto-logout 25 minutes inactivity production. sessions persisted longer this. logs requirements enforced platform level — minimum length, complexity, check known breached passwords. immediate invalidation disabled user's next api call page request denied, browser tab open. requires practical options take team asking use manager (1password, dashlane, bitwarden business, lastpass business) centralize credential management. combined genie, gives operational benefits central rotation, revocation employee leaves, audit visibility credentials. disable departing employees immediately. revokes access invalidates equivalent scim deprovisioning surface area expose. list quarterly active roster. will future roadmap most-requested features customers. committed timeline. organization needs adopt expand contact support@billergenie.com customer ask gets logged feature weighed planning, let know if/when becomes available beta. related articles codes multi-factor (session security)","categories":{"current":{"id":1368782,"name":"Control Panel \u0026 Settings","url":"/settings-and-account"}},"category_param":"settings-and-account"}}]