Managing Access and Recovering Your Workspace
Saved in this browser.
Your devices will change over time. You'll replace a computer, add an AI agent, or lose a phone. You need to keep access to your workspace while making sure the clients you no longer trust lose theirs.
For the design behind these steps, read How We Encrypt Your Data.
A client is an installation of People Work that accesses your workspace. For example, the macOS app or the Terminal/MCP client your agent uses. Each has its own access, even when several run on the same computer.
Check which client you are approving or removing.
Approve a New Client
- Install People Work on the new device, or set up the terminal/MCP client.
- Sign in with your account email and enter the verification code we send you.
In the terminal, start with
people auth login. - Open an existing approved client and review the pending request. In the
terminal, run
people auth admitto open the approval process. - Check that you recognize the requesting client, then choose Approve. Choose Reject if you did not request it.
- Keep both clients open and online while People Work secures the workspace. When the approval finishes, return to the new client.
Email verification alone does not let the new client read your workspace. Approval does. If you no longer have an approved client you can use, follow Recover Your Workspace below.
The free plan supports one physical device, including multiple clients on it. Adding another physical device requires a paid plan.
Revoke a Lost or Untrusted Client
- Open your account's client list from another approved client. In the
terminal, run
people auth revoke. - Select the lost or untrusted client. Check its name and app details.
- Choose Revoke Client and confirm the request. In the terminal, follow the confirmation prompt.
- If several clients on a lost device have access, revoke each one.
The revoked client stops receiving future workspace changes. When it next connects, People Work invalidates it and removes its local account data. Revoking access cannot take back information already decrypted on an offline client. Use your operating system's lock or remote-erase tools too.
If no approved client is available, recover on a new client instead. Recovery revokes all previous clients.
Recover Your Workspace
Have access to your account email and your current recovery key before you start. Your local passphrase cannot replace the recovery key.
- On a new client, choose Recover Account on the sign-in screen where you
enter your email address. In the terminal, run
people auth recover. - Enter your account email and the verification code we send you.
- Enter your current recovery key in People Work.
- Wait for recovery to finish. The new client gains access, and all previous clients are revoked.
- Save the replacement recovery key in your password manager, then confirm that you have saved it. The previous key no longer works.
As you set up People Work on additional devices, approve their clients from the one you just recovered.
Never share your recovery key with anyone, including us. Enter it only in People Work when recovering your workspace or replacing the key.
If you lose both your recovery key and access to every approved client, we cannot restore your workspace. Keep that recovery key somewhere you can reach without relying on this one device.
Replace Your Recovery Key
Replace the key if you suspect someone else has obtained it. You need your current recovery key and access to your account email to do this.
- From an unlocked, approved client, open your account and choose
Rotate Recovery Key. In the terminal, run
people auth rotate. - Enter the verification code sent to your account email.
- Enter your current recovery key.
- Save the replacement key in your password manager and confirm that it is saved. People Work shows it only once.
- Keep the client open while it finishes updating the workspace encryption.
The old key no longer works for recovery. Your approved clients continue using the same workspace. If you also need to remove a client's access, revoke that client separately.
If You Get Stuck
Contact support with the step you reached and any error message. Do not send recovery keys, passphrases, verification codes, or private workspace content. We can help with the process, but we cannot bypass the protections that make your workspace yours.