Introduction
In regulated environments, moving content or widgets to Production is a controlled and auditable action. Re-Authentication ensures that every publish or unpublish action is verified, intentional, and traceable. With the GxP Re-Authentication, Whatfix enforces an electronic signature step before any content can transition between stages.
For example, In a life sciences organization, high-risk content must be approved before going live. During testing, a dosage instruction in a Whatfix Flow was updated from 9 ml to 10 ml. If published without proper verification, this could lead to incorrect data capture or compliance issues. With the Re-Authentication, each publish or unpublish action is linked to a Change Request ID (such as Jira) and requires user verification. This ensures every change is reviewed, approved, and traceable.
Here’s a video of how to Publish and Unpublish content with Re-Authentication.
How Re-Authentication for Publish and Unpublish Works
Re-Authentication for Publish and Unpublish introduces a mandatory verification step during publishing and unpublishing content from Whatfix Guidance dashboard.
When a teammate attempts to publish or unpublish content:
The teammate must complete identity re-verification, even if already logged in through SSO.
The teammate must provide required change details.
The action is completed only after successful validation.
This ensures that all production changes are explicitly authorized at the moment they occur.
Use case
Use Re-Authentication to ensure that every content change in production is verified, intentional, and audit-ready.
Ensure that only authorized users can publish or unpublish content through mandatory re-authentication.
Prevent unauthorized or accidental updates to live content by enforcing a verification step at the point of action.
Associate each content change to a verified user identity for accountability.
Audit teams can review all content lifecycle changes with full traceability. You can trace your changes in Audit Logs, where the Change Request ID and Reason for Change are captured under Action Details.

Prerequisites
Note:
Re-Authentication for Publish and Unpublish is a Beta feature. To enable this feature, contact support@whatfix.com.
Only Teammates with permission to Publish or Unpublish content can perform this action. For more information, see Whatfix User roles and Use Custom Roles on Whatfix Dashboard.
Ensure you have a valid Change Request ID (for example JIRA) and specify a Reason for Change.
Publish and Unpublish content with Re-Authentication
Expand the following accordions for more details:
Publish Content with Re-Authentication
Use the following steps to Publish content and widgets with Re-Authentication:
On the Whatfix Guidance dashboard, go to the Ready stage.

Info:
Ensure all the content and widgets you want to go live are moved from the Draft stage to the Ready stage.
Select the content you want to move, and then click Send to ready.

Select the checkboxes next to the content you want to publish.

Click Publish.

On the Publish changes dialog box, review and select the content and other changes that you want to publish.

In the Change Request ID field, enter the ID.

In the Reason for change field, enter the reason.

Select By checking this box, I am applying my electronic signature to authorize this change as an Account Manager checkbox to confirm your authorization.

Click Authorize and Publish.

Click Sign in with SSO to publish your content or widgets.

You are redirected to your identity provider. Once the authentication is complete, your content or widgets are published.
Unpublish Content with Re-Authentication
Use the following steps to Unpublish content and widgets with Re-Authentication:
On the Whatfix Guidance dashboard, go to the Production stage.

Select the checkboxes next to the content you want to unpublish.

Click Unpublish.

On the Unpublish changes dialog box, review and select the content and other changes that you want to publish.

In the Change Request ID field, enter the ID.

In the Reason for change field, enter the reason.

Select the By checking this box, I am applying my electronic signature to authorize this change as an Account Manager checkbox to confirm your authorization.

Click Authorize and Unpublish.

Click Sign in with SSO to publish your content or widgets.

You are redirected to your identity provider. Once the authentication is complete, your content or widgets are unpublished.
Note:
After you publish or unpublish your changes, go to the Audit Logs page and view the captured events under Action detail tab.
Info:
Change Request ID: A unique identifier for the change, typically linked to your change management system (for example, Jira). It helps track and validate that the update is approved.
Reason for Change: A brief explanation of why the change is being made. This provides context for the update and helps during audits and reviews.
Action Detail: A record of the publish or unpublish action captured in Audit Logs. It includes key information such as the Change Request ID, Reason for Change, and the user who performed the action.