Who can use this?
- Access to account security features depends on the specific feature.
- Roles: Owners and Admins
Gallabox provides multiple layers of account security — activity logging to track who did what, two-factor authentication (2FA) to prevent unauthorized access, and Allowed IPs to limit access to known networks.
Available Security Features
Activity Log
Tracks every significant action taken in your Gallabox account — who did it, when, and from where. Access it at Settings → Developer → Activity Log. For what’s logged, filters, and audit use cases, see Activity Log.Two-Factor Authentication (2FA)
Adds a second verification step when logging in — even if someone has your password, they can’t access your account without the second factor. 2FA is mandatory for Owners and Admins. For setup steps, team-wide enforcement, and recovery codes, see Two Factor Authentication.Allowed IPs
Restrict access to your Gallabox account to specific IP addresses — useful for enterprise teams that work from known office networks or VPN tunnels. Example use cases:- “Only our office IP range (103.x.x.x) can access Gallabox”
- “Our agency works from specific IPs — only those should be allowed”
How to configure Allowed IPs
1
Open Allowed IPs
Go to Settings → Developer → Allowed IPs.
2
Add an IP address
Click Add IP Address.
3
Choose the address type
Choose Static IP address or IP address range.
4
Enter the address
For a static address, enter Enter IP address. For a range, enter Enter IP range from and Enter IP range to.
5
Name the address
Enter an IP Name, such as “Office — Mumbai”.
6
Save
Click Save.
What happens after you configure Allowed IPs?
- Team members accessing from outside the allowed IP range will see an “Access denied” message
- API calls from outside the allowed range will return a 403 error
- If you need to access from a new IP, ask a team member with access to add the new IP to the allowed list
Plan availability: The Allowed IPs feature requires the Advanced plan.
Session Management
Gallabox does not currently offer a screen to view or revoke individual sessions. When changing your password, select Logout from all devices to sign out your other sessions.In this section
- Two Factor Authentication — add a second login factor beyond your password
- Activity Log — track who did what, and when, across your workspace