Log out & security
How to sign out and simple steps to keep your account safe.
Signing out ends your session only on the device you press it from. Mountify has no “sign out of all devices” button and no list of active sessions — so it matters that you know what actually happens, and what stays open.
This article is the practical checklist: how to sign out, which action genuinely ends your other sessions, how to change a password (not where you’d look for it), and what to do if you’re worried someone has been in your account.
1. How to sign out
- Click your avatar at the bottom of the narrow icon rail on the left (on a phone, near the bottom of the slide-out panel).
- At the bottom of the menu press Sign out.
- You’re returned to the sign-in screen.
Your data is untouched — bookings, clients and settings are all there when you come back. Signing out only ends the session.
Don’t mix up the menus. Your avatar is at the bottom left and leads to User settings and Sign out. The monogram tile at the top left is about the business — see Switch workspace.
2. Signing out is for this device only
That’s the most important sentence here.
| If you’re signed in on… | After Sign out on the computer |
|---|---|
| the same computer, same browser | You’re signed out |
| a different browser on the same computer | You stay signed in |
| your phone | You stay signed in |
| the front-desk tablet | You stay signed in |
There is no screen that shows you where else you’re signed in, and no button that ends them all. If you left your account open on someone else’s computer, the only reliable way to close it remotely is the one in §3.
3. The one thing that ends your other sessions
Turning two-factor authentication on ends your other active sessions. The reason is technical: those sessions were opened before the protection existed and never cleared the second step.
If you left your account open somewhere and want it closed:
- Sign in from a device that is yours.
- Open User settings → Personal.
- If 2FA is off — turn it on (you’ll need an authenticator app; the full flow is in Two-factor authentication).
- If 2FA is already on — turn it off and on again. The second enable ends the other sessions once more.
Bonus: from then on every new sign-in asks for a code from your phone, so the reason you were worried goes away.
4. Passwords only change through “Forgot password?”
User settings → Personal has no new-password field. It isn’t hidden and it isn’t a permissions matter — it simply doesn’t exist. Changing it happens on the sign-in screen:
- Sign out, or open the sign-in screen in a new tab.
- Press Forgot password?.
- Type your email and press Send code.
- Fetch the 6-digit code from your inbox and type it in.
- Set a new password twice and press Reset password.
The whole flow, with screens and error messages, is in Sign in & password.
Careful: changing your password does not end your other sessions. If that’s what you’re after, do §3 as well.
5. The security checklist
| Action | Why | Where |
|---|---|---|
| Turn on two-factor authentication | A password alone stops being enough to get in | User settings → Personal |
| Save the backup codes somewhere safe | They’re shown once only; without them a lost phone means lost access | At the moment you enable 2FA |
| Give every colleague their own login | A shared account means nobody knows who did what, and you can’t revoke one person | Members in the workspace settings |
| Sign out on shared devices | Signing out is per-device — nobody will do it for you | Avatar → Sign out |
| Use a password unique to Mountify | A password leaked from another site is the most common way into an account | Sign-in screen → Forgot password? |
| Don’t forward emails containing codes | Sign-in, email-change and 2FA codes are one-time keys | — |
| Review members when somebody leaves | A deactivated account can’t get in; an active one can | Members |
More about the team: Roles & permissions, Give staff a login and Build a custom role.
6. If you think someone has been in your account
Do it in this order:
- Change your password — via Forgot password? (§4). Pick one you use nowhere else.
- Turn on 2FA — this both adds a second step and ends every other session at once (§3).
- Save the backup codes somewhere safe.
- Check your email address in User settings → Personal. If it’s an address that isn’t yours, change it immediately — Change your sign-in email.
- Check your inbox for a message titled “Your account email was changed”. If one is there and you changed nothing, tell support.
- Check the team — in Members, look for an unfamiliar member or a freshly sent invitation. Cancel anything that isn’t yours: Pending invitations.
- Check the money — bookings, payments and refunds for the last few days: Money: where everything about money lives.
7. At the front desk and on shared devices
If one device is used by several people:
- Don’t share one account. Every extra login is free — you pay for bookable spots, not for users. See Does adding a teammate cost extra?.
- Sign out at the end of the shift. Especially if the device stays in an area clients can reach.
- Don’t let the browser save the password on a shared device.
- Remember that 2FA can be turned off without a code — an open account is enough. That’s why an account left open on the counter is a real risk, not a theoretical one.
- If the device is a tablet read from a distance, set it up for comfort: Text size, motion and tours.
8. What Mountify does NOT do
Stated plainly, so you don’t rely on something that isn’t there:
- No list of active sessions, and no “sign out everywhere” button.
- No notification on a new sign-in — not by email, not in the app.
- No email when a password changes. The only security email is the notice to the old address when you change your email.
- No IP or device restrictions.
- No automatic sign-out after X minutes that we’d promise you.
- No passkeys, fingerprint or face — the second step is a code from an authenticator app.
- An administrator cannot see, change or remove your password or your 2FA. They can only deactivate or remove your access to the workspace — see Invite & manage members.
Troubleshooting
I pressed Sign out but opening the address takes me straight back in. Close every tab of the app and try again. If the device isn’t yours, clear the browser’s data for the site.
I can’t find Sign out. It’s in your avatar’s menu, at the bottom of the narrow rail on the left — not in the business menu at the top.
I signed out and now I can’t get back in. Check you aren’t typing an old email (if you changed it) and that Caps Lock is off. If the password is forgotten — §4.
I let someone go and they say they can still sign in. Check Members: are they actually deactivated? If their role was merely changed, access remains.
Common questions
Do I lose data by signing out? No. Nothing is deleted.
Can I sign out my phone remotely? Not directly. Do §3 — enabling (or disabling and re-enabling) 2FA ends the other sessions.
Will it sign me out automatically if I don’t touch the app? There’s no such period we’d promise. Sign out yourself when it matters.
If I change the password, will the colleague I share it with be signed out? They’ll stop being able to sign in with it — which is exactly why you shouldn’t share an account. Give them their own login.
Does signing out sign me out of all workspaces? Yes — the session belongs to the account, not to an individual workspace.
What’s next
- Two-factor authentication — the single most useful thing for account security.
- Sign in & password — signing in and changing a password.
- Give staff a login — how everyone gets their own account.
- Roles & permissions — who can do what.