Team, two-factor authentication and branding
Roles, requiring 2FA for everyone, and white-label reports and status pages.
Two-factor authentication
Turn it on under Account > Two-factor authentication: scan the QR code with an authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, Authy and others) and enter the code it shows. Save the 10 recovery codes. Each authenticator code can be used once. Regenerating recovery codes needs a current code.
Require 2FA for your whole team
An owner can require two-factor authentication for every member (Team > Security policy). The owner must have it on first. Members without it are taken to the setup page before they can use the organization; the Members list shows who has it on. API keys are machine credentials and are not affected. Removing or demoting an admin revokes the API keys they created.
White-label reports and status pages
On Pro, set your brand name, accent colour and logo (PNG, JPEG, WebP or SVG up to 40 KB) under Team > Branding. Downloadable client reports and public status pages then carry your brand ("Prepared by <your brand> with Webforta"). On Business you can also remove the Webforta credit entirely. Accent colours must be dark enough to read on white.