Skip to main content
Account & securityAvailable

Manage your profile and protect account access

Use the correct identity surface, minimum access, safe recovery, and support boundaries.

Before you start

Prerequisites and permissions

Have ready

  • Access to the correct Staff or Customer Portal identity.

Access rules

  • Only eligible Owners can manage team access.
  • Support cannot view passwords or give someone access to another business or customer account.

Where to find it

Navigation map

My profile
Account menu → My profile
Account security
Account menu → Account security
Team access
Settings → Team
Staff recovery
Staff sign in → Forgot password
Portal security
Customer Portal → Account security

Walkthrough

Step by step

  1. 01

    Keep your own profile current

    Use My profile to update your display name, phone and private staff photo. Current-password verification protects every change. Your Company Owner still controls roles and permissions.

  2. 02

    Verify a new sign-in email

    Request the change in Account security, then use the single-use link delivered to the new inbox. The old address remains your sign-in address until confirmation succeeds. Confirmation signs out every web session.

  3. 03

    Rotate credentials and sessions

    Review newly issued web sessions in Account security. Revoke one exact session after current-password verification, or use Sign out everywhere to invalidate current and legacy web sessions.

  4. 04

    Enrol a Staff authenticator

    In Account security, confirm the current password, scan the one-time QR code (or enter its manual secret), then verify one six-digit code. MFA is inactive until verification succeeds. Save all ten one-time recovery codes when they are shown.

  5. 05

    Complete MFA at sign-in

    After a correct Staff password, enter a current authenticator code or one unused recovery code. No full browser session exists until this challenge succeeds; five invalid attempts lock that challenge.

  6. 06

    Use one identity per person

    Do not share Staff or Customer Portal credentials. Invite each person through the correct surface.

  7. 07

    Grant minimum access

    Choose the role and capabilities required for the person’s work. Financial, team, Website, and security actions need explicit access.

  8. 08

    Use the correct recovery flow

    Staff and Customer Portal recovery are separate. If a Staff user loses both authenticator and recovery codes, complete the official Staff password reset. Success invalidates the old MFA factor, every recovery code and existing sessions before re-enrolment.

  9. 09

    Treat links as secrets

    Invitation and password-reset links are single-purpose credentials. Do not paste them into tickets, chat, or screenshots.

  10. 10

    Revoke access promptly

    When someone leaves or no longer needs access, update membership and sessions through the authorised account controls.

Troubleshooting

If something does not look right

A recovery email did not arrive.

Confirm the correct identity surface and email address. Repeat only through the official Forgot password flow and do not disclose whether another account exists.

A user can sign in but cannot open a module.

Check selected business membership, role, capability, and module availability separately.

Keep going