Skip to content
d3 Wiki
07.03

Password manager and MFA

No reused passwords, no accounts without a second factor.

Updated
Oct 3, 2026
On this page

Purpose

No reused passwords, no accounts without a second factor.

The standard

  • Team password manager [TEAM: name] is mandatory; shared credentials live in shared vaults, never in personal notes.

  • MFA required on: GitHub, Vercel, Supabase, Anthropic, Autodesk, McNeel, email, password manager. Authenticator app or hardware key; SMS only as fallback.

  • Recovery codes stored in the vault.

  • Generated passwords ≥ 20 characters for service accounts.

Procedure — new service account

Create in the vault first → generate password → sign up → enable MFA → store recovery codes → share the vault item with the owning group.

Owner: [TEAM] · Last reviewed: 2026-09