Staff and security

A shop with one owner needs none of this. A shop with a Saturday casual on the till needs all of it, and needs it before the first thing goes missing rather than after.

Adding a staff member

Invite someone by email and they get their own login. They are not sharing yours, which matters for two reasons: you can take their access away when they leave without changing anybody else's password, and everything they do is attributable to them rather than to "the shop".

What they can touch

Access is granted per area, and per shop. The areas are:

AreaCovers
CatalogProducts, variants, collections, categories
OrdersThe orders inbox, fulfilment, returns
InventoryStock levels, adjustments, transfers, purchase orders
DiscountsCodes and automatic discounts
CustomersCustomer records and segments
FinanceReports, payouts, the accounting export
SettingsShop profile, payments, domains, integrations
POSThe counter

Each is granted as read or write. Someone who can look at stock without changing it is a normal thing to want, and it is one setting rather than a workaround.

If you run more than one shop, a grant belongs to a shop. A manager at the Fitzroy store does not get Carlton's numbers by logging in.

The restriction is on the action, not on the menu. A staff member without a Finance grant does not see Reports in the sidebar — but if they type the address in, the answer is the same: not found. Menus are for convenience; the check is done where the work happens.

You will also notice that access to something in another shop reads as "not found" rather than "not allowed". That is deliberate: "not allowed" tells whoever is trying that the thing exists.

Two-factor authentication

Anyone can turn on a second factor from their own account, and an owner can require it for everyone in the company. Once it is required, a staff member who has not enrolled is walked through it at their next sign-in rather than being locked out.

The challenge is raised on email and password sign-in. If your company requires a second factor, switch off social sign-in for staff and have them use a password, so that the second factor is the only way in rather than one of two.

A code is spent the moment it is accepted. The same six digits will not work twice, so a code read over somebody's shoulder at the counter is worth nothing thirty seconds later.

Enrolling gives you a set of single-use recovery codes, shown once. Each works exactly once. Print them or put them in a password manager at the moment they are shown — there is no screen that will show them to you again, because a screen that could would be a way around the second factor.

If you lose the phone, use a recovery code. If you have lost both the phone and the codes, another owner can clear the factor from Security. A sole owner who has lost both has no self-service path back in, and the challenge screen says so plainly rather than letting you find out at the worst possible moment — contact us and we will work through it with you.

Enrolment needs your account password, so an account that has only ever signed in with Google or Apple has to set a password first. The screen tells you that instead of failing on an empty password.

The activity log

Every change a staff member makes is written to an activity log: who, what, when, and the address they were at. Read it under Manage → Staff → Activity.

It is written after the fact and never blocks the work — a refund is not held up while the log is written, and a log that cannot be written does not fail the refund. The address and the browser are taken from the request rather than supplied by the action, so nothing has to remember to record them and nothing can record a false pair.

Sensitive values are redacted before they are stored. The log is a record of what happened, not a second copy of your customers' details.

Where to find it

Manage → Staff, with the activity log under Staff → Activity. Two-factor enrolment and the company-wide requirement live under Reports & settings → Security.