Both live in Settings → Vault:
Change Vault key — confirm it's you (with your password, or with a code we e-mail you if you sign in without one), then enter your current Vault key and the new one (minimum 10 characters). Your forms are re-secured under the new key in your browser; nothing is re-uploaded or lost, and your team memberships survive the change. You'll immediately receive a new recovery code — the old one stops working, so store the new one right away.
Regenerate recovery code — creates a fresh recovery code without changing your Vault key. Use it if you're unsure whether the old code still exists somewhere safe (moved offices, cleaned out the folder, offboarded an assistant). The old code becomes invalid the moment the new one is shown.
Warning
After either action, exactly one recovery code is valid: the newest. Destroy old printouts to avoid future confusion.
Tip
A good yearly ritual — rotate the recovery code and re-file it, the same way you'd test a backup.