Team policies

Updated 3 October 2026

A policy is a rule the team sets for everyone on it. Policies are on the Policies tab of People & Team. Only the Owner and Admins can switch them on or off. If the words Managed and Sponsored are new, read Team members: Owner, Admin, Managed and Sponsored first.

What policies are for

A team that keeps company calendars safe usually wants a few simple things to be true for everyone: people sign in strongly, work calendars go only where the company wants them, and nobody has a side account the team cannot account for. There are four policies, and each one is off until you switch it on:

  • Require 2FA to sign in
  • Allowed calendar providers
  • Allowed destinations
  • No secondaries

Policies switch on only once the team's trial has started. While a team is closing, nothing changes.

Preview first

Before you switch a policy on, GetCalendario shows who it would affect: names and counts only. Nobody's calendars, events or connections are shown to you. You can look at the preview even when switching is not allowed yet.

Now or in 14 days

When you switch a policy on, you choose when it takes effect:

  • In 14 days (the default). Everyone it affects is emailed on days 1, 7 and 13, so they know what to change and by when. During those days they can fix things themselves, and people who already comply are not bothered.
  • Now. It takes effect straight away, and the people it affects are told.

You can also choose Apply now at any time while anyone is still counting down. It brings everyone's date forward to now.

Someone who joins the team later gets their own 14 days. They are not caught out by a rule that started before they arrived. Changing a policy gives the new cut-off only to people the change newly catches, so choosing Now for a change does not hurry anyone already counting down. Use Apply now for them. Everyone else keeps the state they were already in.

Require 2FA to sign in

You choose a level:

  • Any of an emailed code, an authenticator app or a passkey. Every GetCalendario sign-in already asks for one of these, so this level changes nothing today.
  • An authenticator app or a passkey.
  • A passkey only.

A stronger method always counts. Someone who signs in with a passkey passes every level.

Someone who loses their way of signing in after their date, for example because support reset their authenticator app, is asked for it again at their next sign-in, and their AI assistants are disconnected straight away. They do not get another 14 days.

Everyone on the team is asked, the Owner included. The rule is checked each time you sign in, starting at each person's next sign-in after their cut-off. Nobody is thrown out of a session they are already in.

Nobody is locked out. If someone cannot meet the level, an emailed code still gets them to a page where they confirm a method or set one up. Setting one up there is emailed to them and logged in the team's activity log, so the team and the person both know.

AI assistants are disconnected at the cut-off. An AI assistant never signs in again, so it would otherwise keep reading calendars for someone who never set up the method. When a person's date passes and they still haven't set it up, every AI assistant they have connected is disconnected, and none can be connected until they set it up. Their warning emails and Home card say so. Setting up the method later doesn't bring the old connections back: they connect each assistant again from Settings → AI & MCP, which then works as usual. Someone who already meets the level is not affected, and turning the policy off doesn't reconnect anything.

Allowed calendar providers

You choose which kinds of calendar Managed members may connect. It does not apply to Sponsored members, whose accounts belong to them.

  • During the 14 days, a member can still repair or re-authorize an account they already have, even if its kind is no longer allowed.
  • New accounts of a disallowed kind are refused.
  • The choices are Google, Microsoft, Apple (iCloud), Calendar feeds (subscribed .ics addresses) and Older connections through Cronofy.
  • A policy you set before Apple and calendar feeds were on the list allows both, until you edit it.
  • At the cut-off, accounts of other kinds are disconnected. Their copies stay, unless you also chose remove copies: then the events GetCalendario copied from and into those accounts are taken back first, and each account is disconnected once that is done.

Allowed destinations

This policy is about the data. Calendars at your team's domains may sync only to calendars at your domains, plus any partner domains you list.

It covers syncs owned by anyone on the team, and any sync that reads a team member's calendar, whoever owns the sync.

A sync that breaks the rule is dealt with in one of two ways, your choice when you switch it on:

  • Remove copies. The sync is deleted, and the copies it made come off. (A sync that breaks the rule only through a "send to a different calendar" rule is paused instead.)
  • Without it, the sync is paused and keeps its copies.

What a member can do about a paused sync:

  • If it breaks the rule only through a "send to a different calendar" rule, they can remove that rule and resume the sync.
  • If the sync's own destination is outside the allowed domains, it can't run again. They can delete it, or make a new sync to an allowed calendar.

If a member tries to move an old Cronofy account and a running sync would break the rule afterwards, the move is refused up front and says what to change. Syncs that are already paused are moved as paused.

No secondaries

Members and Admins cannot have secondary accounts, unless one of their groups gives Have secondary accounts (see Team groups and permissions). The Owner is not affected, and nobody is deleted.

  • A secondary that lives inside the member's account gets an account of its own on the Free plan.
  • A secondary that already has its own account is unlinked from the member.
  • Syncs between them stop. The copies they made stay.
  • Invitations to become a secondary are withdrawn.
  • Accounts that are frozen are skipped.

What GetCalendario cannot promise

Policies change what happens from now on. They cannot take back:

  • Copies someone already exported or backed up. A file on someone's computer or in a backup destination is theirs.
  • Calendars GetCalendario can no longer reach, for example because the provider has cut the connection. Copies there cannot be removed until the connection works again.

Coming later

Single sign-on is coming. Policies will work alongside it when it arrives.