Staff PIN gate
How PIN entry attributes each action to a staff member and which actions require it.
Sensitive actions can ask for a four-digit staff PIN — whether they do is a single tenant-wide setting. When they do, the prompt identifies who is authorising the action, and that name is what gets recorded against it.
PINs are a per-shop setting
Whether any of this happens at all is controlled by one switch, Require staff PINs, at Settings → Staff. It is admin-only, off by default, and applies tenant-wide — to every sensitive action in the shop, not just some of them.
Off, there is no PIN prompt anywhere — not for sales, refunds, voids, gift card and store credit issue, trade-in payouts, register open, close and break, staff management, or repair edits and price overrides. The signed-in staff member is recorded as having performed the action instead, and the prompt becomes a short confirmation panel naming the action and the signed-in person it will be recorded against, with just Cancel or Confirm.
On, every one of those actions requires the PIN and mints the single-use token described below.
Either way, this setting only changes how someone proves who they are — it never changes what they are allowed to do. A staff member who cannot refund without a supervisor is still refused and told to sign in as one (or to turn staff PINs on), PIN or no PIN; turning PINs off cannot promote anybody. Roles and Settings → Access are unaffected.
The PIN is checked, not just shown
When staff PINs are on, approving with a PIN issues a single-use token bound to the specific action being authorised. The endpoint performing that action demands the token, so a gated action cannot be carried out by skipping the prompt. Before version 0.46.0 the keypad appeared but nothing on the server required it to have been answered.
If you do not know your PIN
When staff PINs are on, the prompt offers a password fallback: sign the action off with your account password instead of the PIN.
Where your PIN comes from
A PIN is generated for you when your account is created and sent in the welcome email. PINs are stored hashed, never in plain text. See Staff.