Trusted Devices & Restricted Permissions
What it does
Some actions in your point-of-sale are sensitive enough that you don't want them available on every till in the building — for example, on a tablet at the front counter that any staff member (or, in a pinch, a customer) could pick up. Trusted Devices lets an admin mark a chosen set of permissions as "restricted," meaning staff who hold those permissions by their role can still only use them on a device an admin has personally approved. Everywhere else, those actions are simply hidden — nothing to fumble with, nothing to accidentally tap.
Trust is granted per physical device (a till, a tablet, a phone), not per person. Once a device is approved, anyone who logs into that device — with their normal login or PIN — gets the restricted permissions they're already entitled to by their role. You don't need to approve the device separately for every staff member who uses it.
Getting started
- Go to Settings → Feature access. This page is reachable by everyone who's logged in, but the management sections only appear for people with the right permissions.
- As an admin, open Device-restricted permissions and turn on the specific actions you want to lock down to approved devices only (for example, managing users, approving payroll, or issuing refunds). Turning nothing on means nothing is restricted, and the rest of this page won't appear for anyone.
- Save. As soon as you save a non-empty selection, the Trusted devices section appears, and any device that isn't yet approved will have those actions hidden for everyone using it.
- On the device you want to trust (the actual till, tablet, or phone), open Settings → Feature access while logged in, find This device, type a name for it (e.g. "Front counter tablet"), and tap Request authorization. You'll be asked to confirm with the device's built-in unlock — fingerprint, face recognition, PIN, or Windows Hello, whatever the device supports. This proves the request is coming from a real, physical device and not a spoofed browser.
- A short one-time code appears on the device's screen. Give it to an admin, or have the admin approve it directly if they're standing at the till.
- An admin opens Feature access → Trusted devices → Pending requests, either taps the matching request in the list or types the code, then picks exactly which of the restricted actions this device should be allowed to run. It doesn't have to be all of them — a delivery tablet might only need order-related permissions, while the back-office PC gets everything.
- Once approved, the device unlocks those actions immediately for whoever is logged into it — no restart or re-login needed.
Key things to know
- Restrictions are set once, org-wide. An admin decides which actions require an approved device; that list applies to the whole venue, not per person.
- Each device gets its own subset. Approving a device doesn't automatically grant it every restricted action — an admin picks exactly which ones, and can change that selection later from the trusted device list ("Edit grants").
- Trust follows the device, not the login. Once a till is approved, every staff member who logs into it — whether by password or PIN — gets the restricted permissions their role already allows. There's no need to re-approve the device for each new employee.
- The unlock prompt only proves the device is real (fingerprint, face recognition, or device PIN) — it does not identify which staff member is using it. Staff still log in normally to identify themselves; the device approval just decides whether restricted actions are even available on that screen.
- You can revoke a device at any time. Removing a device from the trusted list immediately blocks the restricted actions on it going forward.
- Turning off all restrictions clears every trusted device automatically. If an admin later decides no permissions need this extra lock, saving an empty selection removes trust from every device at once — there's nothing left to manage.
- Trust doesn't transfer between browsers or apps on the same physical gadget. If the same tablet is used both as an installed app and as a regular browser tab, each needs to be approved separately.
- Clearing the device's storage, reinstalling the app, or switching browsers can un-recognize it. If that happens, someone just needs to tap a "verify this device" prompt and confirm with the device unlock again — no admin involved, unless the device credential itself was lost, in which case it needs to go through approval again.
- Owners and top-level admins are never affected by these restrictions — they can always use every permission their role grants, on any device.
- The permission that lets someone manage trusted devices itself can never be restricted — there's always at least one way to reach this page and fix things.
- Changes can take a short moment to apply. If you just approved or revoked a device, the affected staff member's screen updates automatically on their next background refresh, which happens periodically — you generally don't need to ask them to log out and back in, but a manual refresh will always show the current state immediately.
FAQ
Q: What's the difference between "restricted permissions" and "trusted devices"?
A: Restricted permissions is the list of sensitive actions an admin has decided should only work on approved equipment. Trusted devices is the list of specific tills, tablets, or phones that have been approved to use some or all of that restricted list.
Q: If I approve a device, does that mean anyone can use it for sensitive actions?
A: No. The device only unlocks actions for staff who already have those permissions through their role. Approving a device removes the extra device-level lock — it doesn't hand out new permissions to people who wouldn't otherwise have them.
Q: Do I need to approve a device separately for every employee?
A: No. Approval is per device, not per person. Once a till is trusted, every staff member who logs into it (with their own login or PIN) gets whatever restricted permissions their role already includes.
Q: What happens if I move the app to a different phone or tablet?
A: The new device isn't trusted yet — it needs to go through the same request-and-approve process. Trust doesn't travel with an account between physical devices.
Q: The device says "not recognized" even though it was approved before — why?
A: This usually happens after clearing browser storage, reinstalling the app, or switching between the browser and an installed app version on the same device. Tap the verify prompt and confirm with the device unlock again to fix it — no admin approval needed for this step. If it still doesn't work, a manager will need to approve it again as a new device.
Q: Can I limit what a specific device is allowed to do, even within the restricted list?
A: Yes. When approving a device — or any time afterward via "Edit grants" — an admin picks exactly which restricted actions that device gets. A front-counter tablet and the back-office computer can have completely different permissions unlocked.
Q: What happens if I turn off all restrictions?
A: Saving an empty selection removes the restriction org-wide and automatically clears every device's trust — there's nothing left to approve or manage, and the Trusted Devices section disappears until restrictions are turned on again.
Q: My device doesn't support fingerprint or face unlock — can it still be trusted?
A: A device needs some form of built-in unlock (fingerprint, face recognition, or a device PIN/passcode) to complete the approval process. Older or very basic devices without any of these may not be able to participate, and restricted actions will simply stay unavailable on them.