Before you start
Prerequisites and permissions
Have ready
- Access to the correct Staff or Customer Portal identity.
Access rules
- Only eligible Owners can manage team access.
- Support cannot view passwords or give someone access to another business or customer account.
Where to find it
Navigation map
- My profile
- Account menu → My profile
- Account security
- Account menu → Account security
- Team access
- Settings → Team
- Staff recovery
- Staff sign in → Forgot password
- Portal security
- Customer Portal → Account security
Walkthrough
Step by step
- 01
Keep your own profile current
Use My profile to update your display name, phone and private staff photo. Current-password verification protects every change. Your Company Owner still controls roles and permissions.
- 02
Verify a new sign-in email
Request the change in Account security, then use the single-use link delivered to the new inbox. The old address remains your sign-in address until confirmation succeeds. Confirmation signs out every web session.
- 03
Rotate credentials and sessions
Review newly issued web sessions in Account security. Revoke one exact session after current-password verification, or use Sign out everywhere to invalidate current and legacy web sessions.
- 04
Enrol a Staff authenticator
In Account security, confirm the current password, scan the one-time QR code (or enter its manual secret), then verify one six-digit code. MFA is inactive until verification succeeds. Save all ten one-time recovery codes when they are shown.
- 05
Complete MFA at sign-in
After a correct Staff password, enter a current authenticator code or one unused recovery code. No full browser session exists until this challenge succeeds; five invalid attempts lock that challenge.
- 06
Use one identity per person
Do not share Staff or Customer Portal credentials. Invite each person through the correct surface.
- 07
Grant minimum access
Choose the role and capabilities required for the person’s work. Financial, team, Website, and security actions need explicit access.
- 08
Use the correct recovery flow
Staff and Customer Portal recovery are separate. If a Staff user loses both authenticator and recovery codes, complete the official Staff password reset. Success invalidates the old MFA factor, every recovery code and existing sessions before re-enrolment.
- 09
Treat links as secrets
Invitation and password-reset links are single-purpose credentials. Do not paste them into tickets, chat, or screenshots.
- 10
Revoke access promptly
When someone leaves or no longer needs access, update membership and sessions through the authorised account controls.
Troubleshooting
If something does not look right
A recovery email did not arrive.
Confirm the correct identity surface and email address. Repeat only through the official Forgot password flow and do not disclose whether another account exists.
A user can sign in but cannot open a module.
Check selected business membership, role, capability, and module availability separately.
Keep going