Staff access overview, login, PIN, and permissions
Staff access management, PIN switching, and permissions
Staff Access Overview
Staff Access is a comprehensive system that lets you control how your team members access your business account. It includes PIN switching for quick account switching, detailed permission management, and security settings.
Key Features
PIN Switching
Allows team members to quickly switch between accounts using a 4-digit PIN code, ideal for shared devices or busy environments.
Custom Permissions
You can precisely control what each staff member can see and do, across 22 different permission categories and ~140 individual permission flags that cover every area of the business, from the calendar to the AI assistant.
Automatic Enforcement
Permissions are automatically enforced: the navigation menu only shows menu items the staff member has access to. API endpoints are also protected against unauthorized access.
Role Templates
Choose from four permission templates (No Access, Basic, Standard, Full) and apply them to all members of a given role with a single click.
Security Settings
Two-factor authentication and configurable session timeout to protect business data.
How to Access
Managing Permissions from the Staff Page
- Navigate to Team > Staff
- Select the Access & Permissions tab
- The Staff Permissions section appears with all active staff members
- Click the Manage button next to any staff member to open the detailed permissions page
Direct Access
You can also access the permissions page directly at: /t/[slug]/staff/[staffId]
Page Overview
The Access & Permissions tab displays:
- PIN Switching card: Enable/disable and configure PIN switching
- Two-Factor card: Enable/disable 2FA
- Access statistics: Active access, full access, PIN set up
- Staff Permissions: List of all active staff with "Manage" button
- Apply Template: Apply a permission template to an entire role
Quick Actions
From the staff list:
- Grant Access: Set basic permissions
- Full Access: Grant all permissions
- Manage: Open the detailed permissions page
Note: Owner permissions cannot be modified, they always have full access.
Use case scenarios
Scenario 1: Onboarding a new receptionist
You hire a new receptionist. Add her to Team with the Reception role, then on the Access & Permissions tab, apply the "Standard" template to the role. With one click she gets typical reception permissions: booking, customer management, payments. No reports access, no sensitive settings.
Scenario 2: Shared device at reception
A single tablet at the front desk, used by 4 people (Reception-1, Reception-2, Manager, Owner). Enable PIN switching. Each gets her own 4-digit PIN and switches accounts on the tablet quickly. The audit log records exactly who did what.
Scenario 3: Temporary manager fill-in
Your manager is on vacation, a senior stylist covers for 2 weeks. Instead of changing her role permanently to Manager, just toggle on specific permissions (reports, schedule editing) temporarily. Revoke after 2 weeks.
Scenario 4: 2FA on sensitive roles
Make two-factor authentication mandatory for Owner and Manager roles. If a password is leaked, the attacker can't get in. Staff role doesn't need it yet, they see less.
Scenario 5: Stylist sees only her own calendar
There's competition between stylists, you don't want them seeing each other's revenue or bookings. The Staff template defaults to "own only", but worth confirming: Calendar → "View other staff" permission is off.