August 6, 2026 · All agencies
Authenticator App MFA, Applicant Routing, PDF Export & CA POST Dispatcher Template
This release adds optional authenticator app MFA for agency personnel, improves applicant onboarding routing for returning accounts, a PDF export option to hide empty section headers, and a new CA POST Dispatcher narrative template.
Here's what's included:
Authenticator App MFA
Guardian now offers an optional Multi-Factor Authenticator App Login setting that agencies can enable for stronger account protection. Unlike Guardian's existing two-factor authentication options, which send one-time codes by email, this new method uses a time-based code generated by a standard authenticator app, such as Google Authenticator or Microsoft Authenticator.
Once enabled, all agency personnel must complete a one-time enrollment process and use an authenticator code when signing in. This feature applies to agency personnel accounts and does not affect applicant access.
How to set it up
The first time a user signs in after the agency enables the setting, Guardian will guide them through a short setup process:
- Install a standard authenticator app, such as Google Authenticator or Microsoft Authenticator. Other compatible authenticator apps may also be used.
- Scan the QR code displayed by Guardian to connect the app to the user's account. A manual entry code is also available when the QR code cannot be scanned.
- Enter the current code generated by the authenticator app to confirm enrollment.
Setup is completed once for each user. After enrollment, the authenticator app remains connected to the user's Guardian account unless an administrator resets it.
How users sign in after setup
After enrollment, users will sign in by:
- Entering their Guardian username and password.
- Entering the code currently displayed in their authenticator app.
Authenticator codes refresh every 30 seconds, so users should enter whichever code is currently visible. If a code is not accepted after five attempts, the account will be temporarily locked as a security measure.
Session behavior
Guardian uses two session timers for agencies with authenticator app login enabled:
- 30-minute inactivity lock: If a user is inactive for 30 minutes, Guardian locks the screen. Because the session is still active, the user only needs to re-enter their password to resume. An authenticator code is not required.
- 12-hour session timeout: Every 12 hours, the Guardian session ends completely, regardless of activity. The user must then sign in again using both their password and a current authenticator code.
Administrator management
Agency Admins can manage authenticator enrollment and account access through Personnel Management — but only after the agency has enabled the Multi-Factor Authenticator App setting in Agency Settings, and only for admins or users who've specifically been granted the MFA Device Setting permission.
If an agency wants to use this feature and doesn't see the option available to the right users, they should reach out to Guardian and we'll make sure the appropriate permissions are in place.
Applicant Onboarding: Smart Routing
When an applicant's email is recognized as an existing Guardian account, Guardian now checks whether they have actually finished setting up their account the first time they were invited and will route them accordingly:
- Applicants who have already set a password go straight to the login page.
- Applicants who haven't are routed to the new account setup flow instead.
This replaces the old behavior where all returning applicants landed on the same generic login page regardless if they had completed their account setup or not, which confused some applicants as to why they were being asked to login when they never set up a password to access their account.
PDF Export: Hide Empty Section Headers
Investigators, Supervisors
ID report PDF exports now include a "Hide headers/titles for sections without content" checkbox in export settings. When checked, sections with no content are omitted from the PDF, matching what users already see in the online view. The checkbox defaults to off, so existing export workflows are unaffected.
CA POST Dispatcher Narrative Template
CA POST agencies only
Guardian's new dispatcher background narrative template aligns with applicable CA POST dispatcher requirements. The dispatcher template now reflects only the areas of investigation required for dispatchers, and tabs and narrative sections that do not apply to dispatchers have been removed. Section titles also use the regulation heading as determined by CA POST.
Position/Permit Manager now offers a CA POST Dispatcher narrative template option alongside the existing Guardian Default and CA POST Sworn templates. Agencies can view and compare the differences between all three before choosing one for a position.
Agencies have two ways to move a position onto the Dispatcher template:
Option 1: Switch an existing position.
Change the position's narrative template from CA POST Sworn to CA POST Dispatcher, and the investigation structure (tabs and narrative output) updates any existing investigations immediately to match.
One thing to be aware of: the Sworn template includes a few narrative entry areas that the Dispatcher template doesn't have. If a position is switched to Dispatcher, any content already entered in those areas isn't deleted, it's just hidden while the Dispatcher template is active. Switching the position back to Sworn makes that content visible again.
Option 2: Create a new position.
Set up a new position using the existing Dispatcher POST 2-255 questionnaire (aligned to dispatcher requirements) and assign it the CA POST Dispatcher narrative template. New applicants get assigned to the new dispatcher-configured position going forward.
Investigations already underway on the old position continue to completion under the current template. Once the last applicant on the old position finishes, the agency can archive it.
Applicant routing and PDF export changes apply automatically. Authenticator App MFA and the CA POST Dispatcher narrative template are optional — enable or configure them in Agency Settings and Position/Permit Manager when your agency is ready.
Thanks for reading — and thanks, as always, for partnering with us.
Questions? Reach our support team at support@guardianalliancetechnologies.com
