Protect individual accounts
Use a unique password, enable available multi-factor protection, and never share credentials. Sign out of shared devices and avoid saving passwords in public browsers.
Apply least privilege
Grant access based on current responsibilities and separate sensitive actions such as refunds, payroll, user administration, and data exports where practical.
Respond to suspicious activity
- Change the affected password immediately.
- Revoke unknown sessions and review recent activity.
- Notify a workspace administrator and P-Biz support.
- Preserve relevant timestamps, screenshots, and transaction references.
Review routinely
Remove dormant accounts, check administrator membership, review integrations, and confirm recovery contact details on a regular schedule.