Security settings control how trusted shop terminals work and what gets captured in the audit log.
Go to Settings > Security. The page has four cards.
Fast-switch settings. The first two settings control how trusted-terminal sessions behave.
- Idle timeout (minutes): how long a trusted terminal can sit idle before the PIN lock appears. Allowed range 1 to 30 minutes. Lower for shared bay tablets, higher for dedicated workstations.
- Daily reset time: a clock time (your store's local time) at which every trusted terminal resets and all employees must sign in again with their full credentials. Typical value is about an hour after closing time so no one is left signed in overnight.
Click Save settings to apply.
Trusted terminals. Devices designated as trusted shop terminals. On a trusted terminal, employees can swap active user with a 4-digit PIN instead of full email/password sign-in.
The table lists each terminal with Name, Currently active user, Last seen, and a Revoke button. Your current device has a green "This device" pill next to its name.
To designate a new terminal, log in on that device, open your user-menu dropdown, and click "Trust this device." That terminal then appears here. Revoke any terminal that is retired, moved, or compromised; the next request from that machine will be forced back to full credentials.
Mobile devices. One toggle: Require passkey unlock for all phones. When on, every paired phone has to register a passkey (Face ID, Touch ID, iCloud Keychain, 1Password, or any platform credential). PIN-only unlock is no longer allowed; the lock screen forces passkey enrollment or sign-out. Use this when you want extra assurance that a lost or borrowed phone cannot be unlocked by anyone but the assigned employee.
Audit log. Click Open audit log to view the trail. The current audit log captures Credentials login, PIN swap success, Switch User clicked, Idle lock triggered, PIN lockout (5 wrong attempts), PIN reset (self and admin), Terminal trusted, and Terminal revoked events. Permission changes, refund overrides, and individual security-setting changes are not yet captured. Filter by event type or actor (employee).
The Support Access page has its own separate audit log specific to support sessions. See the article on Support Access.