Staff
Creating staff accounts, resetting passwords and issuing or changing PINs.
Staff holds one account per person. Each has a name, an email address they sign in with, a role, and a PIN for the counter.
Roles
A staff member is staff, supervisor or admin. What each role can do is set in Access Levels — see Roles and permissions.
PINs
PINs are four digits and are stored hashed, never in readable form. They identify who authorised an action at the counter. See Staff PIN gate.
Staff PINs
The Require staff PINs toggle at Settings → Staff is tenant-wide, admin-only, and off by default. It is not specific to sales — it governs every PIN prompt in the suite.
Off, there is no PIN prompt anywhere. The signed-in staff member is recorded as having performed the action, and the prompt becomes a short confirmation panel naming the action and the person it will be recorded against, with just Cancel or Confirm. On, a four-digit staff PIN is required for sales, refunds, voids, gift cards, store credit, trade-in payouts, opening, closing and pausing the till, staff changes, and repair edits and price overrides. See Staff PIN gate.
Turning PINs off removes a second factor, never a permission. Roles and Settings → Access are unchanged either way — a staff member who cannot refund without a supervisor is still told to sign in as one, PIN or no PIN.
Two-factor and trusted devices
Editing a staff member shows an Email two-factor authentication checkbox, and — where the person has trusted a browser — a Revoke trusted devices button with the count on it. New staff always start with two-factor on; the checkbox only appears once the account exists. See Two-factor authentication.
Temporary passwords
A password issued to a staff member by an admin is temporary: the staff member is forced to change it at first login, and it stops working once it expires. If that happens, issue a new one.
How many staff you can have
Staff numbers are capped by plan — 1 on Free, 2 on Growth, 10 on Multi Store by default. See Plan limits.