To sign transactions, a device must be marked as a trusted device. Signing works only in the desktop or mobile app — never in the web version.
Use this guide when you have moved to a new device, want to grant signing to another workspace member, your trusted device is lost, reset, stolen, or compromised, or you have changed its biometrics.
1. How to get signing on a device
There are four ways, depending on what you still have access to:
Approval from another trusted device — if any trusted device still works (yours or a teammate’s), approve the request from it. No security delay, no recovery needed. Always prefer this option.
FaceScan recovery — no working trusted device left: verify your identity with a face scan and wait out a 48-hour security delay.
Guardian recovery — no working trusted device left: collect recovery codes from 2 of your Guardians and wait out a 48-hour security delay.
Self-recovery — no FaceScan or Guardians available: a 30-day security delay applies.
Only users with the appropriate role (e.g. Owner) can grant signing to a device.
⚠️ Changing biometrics removes trust. If you re-enrol or reset Face ID, Touch ID, or Windows Hello on a trusted device (for example, add or remove a fingerprint), the key shards stored on it are invalidated for your protection, and trust is removed for all accounts on that device. You can still sign in and use the device, but it can’t sign transactions until you trust it again — through approval from another trusted device (instant) or recovery.
⚠️ If your device has been stolen or compromised, do not approve any unknown trust requests. Remove the compromised device from the trusted list and restore signing via recovery.
2. Approval from another trusted device
2.1 Install and log in on the new device
Log in to Bron via the web version and install the desktop or mobile app on the device where you want to receive signing.
Sign in to the app.
Only trusted devices can sign transactions — this cannot be done from the web app. Both desktop and mobile apps can be trusted signing devices, and Device Management is available in both.
💡 Heads-up after the first sign-in. A fresh sign-in on a new device starts a security cool-down of up to 2 days: some sensitive actions are restricted until it ends, and you can lift it early by confirming the new session from a device where you are already signed in — see Log In to Bron. At the same time, your other signed-in sessions show a New device login detected alert: press Yes, it's me if it was you, or No, it is not me to get guided steps to sign the unknown device out and review your account security.
2.2 Attempt to sign or open Device Management
Open the account you need access for. Click Device Management in the top-right corner. In the pop-up, click Trust this device below the Device is not trusted indicator.
2.3. Create a trust request
The request pop-up will display a list of all devices that currently have signing.
Once your request is created, sign in to Bron from one of these devices and open the account for which you requested signing.
2.4 Validate the trust request
Carefully review the request details to ensure it is legitimate.
The request shows the details of the device asking for access — device model, operating system, and browser. If they don't match a device you own, decline the request.
Enabling signing on a new device means the device will be able to sign transactions from the account.
Only approve legitimate and secure requests.
2.5 Approve the trust request
If the request is legitimate, approve it from the device that already has signing.
2.6 Activate trust on the new device
Sign in again from the device that needs signing.
Activate the approved request.
The system will securely activate signing capability on the device — this process may take a few minutes.
Once complete, you will be able to sign transactions from this device.
3. Recovery (no trusted device available)
If no device with signing is left, start the same way: open Device Management → Trust this device, then click I can’t access any of these devices to see the recovery options. Recovery must be run for each affected account separately.
⚠️ Recovery removes all other trusted devices. After it completes, only this device will be trusted and able to sign — other devices will need to be trusted again manually.
⚠️ If your FaceScan or Guardians were added recently, the method is shown as unavailable with a countdown until its 30-day security delay ends. For a Guardian the 30 days start when that person accepts the invite; for FaceScan, when the enrolment is completed.
3.1 FaceScan recovery (48-hour security delay)
If FaceScan is set up, it appears as the recommended method. Click Start verification and complete the face scan — you will be asked to agree to the use of iProov and allow camera access.
A 48-hour security delay begins. Once it is over, return to Device Management and activate this device.
3.2 Guardian recovery (48-hour security delay)
Under Request approval from your guardians, click Request approval. Your Guardians receive recovery request emails, and all workspace members are notified for security purposes.
Contact your Guardians via your pre-agreed communication channel and ask them to share their recovery codes — they should first verify that it is really you. Share the guide for guardians with them.
Enter the two recovery codes and click Confirm. A 48-hour security delay begins.
Once the delay is over, return to Device Management and activate this device.
What Guardians are and how to set them up — see the Guardians article.
3.3 Self-recovery (30-day security delay)
If FaceScan and your Guardians are not available, click Recover next to Self-recovery. A 30-day security delay begins, and all workspace members are notified. Once the delay is over, return to Device Management and activate this device — no codes required.
On activation the system securely generates new key material using the MPC protocol — this takes a few minutes. The old signing data is removed and cannot be used again.
4. Removing a trusted device
If you want to revoke access from the original device:
Sign in to it again.
Disable signing in via Device Management by clicking “Remove" this device from the trusted list.
⚠️ Do this only if you are absolutely sure — removing a trusted device will immediately revoke its ability to sign.
If you have questions, contact our support team via messenger on the Bron platform or by email support@bron.org.




