Skip to main content
One switch on this tab decides whether everyone in your pharmacy has to prove who they are with a second factor before they can open a record. Beneath it sits the log of every time that requirement was bypassed.

What this tab controls

The card is headed Security Settings — “Manage your clinic’s security settings.” The switch is owner-only. A manager or an accountant sees it in its current position, greyed out, with no Save Changes button.
Passkeys and your own authenticator are set up on your personal account, not here — see Your account security. This tab decides the rule for everyone; that page is where each person satisfies it.

Turn it on

1

Set up your own second factor first

Do this before you switch the requirement on, so you are not locked out of your own pharmacy. See Two-factor authentication.
2

Tell your team it is coming

Everyone will be stopped at their next sign-in and asked to enrol. A cashier discovering this at 8am with a queue is avoidable — give them a day’s notice and let them enrol early.
3

Switch Require Two-Factor Authentication on

Then select Save Changes. You get “Security settings updated successfully”.

What changes once you save

It applies from each person’s next sign-in, not immediately. Anyone already signed in keeps working until their session ends. At that next sign-in, a colleague who has no second factor is stopped and walked through setting up an authenticator app before they can reach anything. After that, records only open from a session that has passed the second factor — a session that has not is refused, even though the password was right. A passkey counts as one factor and does not satisfy this. Signing in with a passkey is still a single-factor sign-in, so someone using one will still be asked to enrol an authenticator. This surprises people; say it out loud when you announce the change. Two doors stay open, and both are recorded. From Staff and teams an owner can Reset two-factor for someone who has lost their device, or Grant emergency access for a time-boxed window. Every use of either — plus any use of a recovery code — appears on the Security alerts card here, with a severity, and stays in the audit log permanently. Acknowledging an alert marks that you have seen it; it does not undo anything. Switching the requirement back off stops new people being asked to enrol. It does not remove the second factor from anyone who already has one, and they will keep being asked for it.

Check it worked

Sign out and back in yourself: you should be asked for your second factor. Then ask a colleague who has not enrolled to sign in — they should be stopped and taken through setup before they can reach a customer record. Anyone bypassing it later should appear on the Security alerts card within moments.

Common issues

You are a manager or an accountant. This is owner-only. Ask the pharmacy owner, or see Roles.
An owner can Reset two-factor from Staff and teams — it signs their sessions out and invalidates their recovery codes, and they enrol again on their next sign-in. The owner needs their own two-factor on to do it.
Use Grant emergency access on their staff row. It is time-boxed, needs a reason, expires by itself and is recorded on this tab.
That is correct. A passkey is one factor. It does not satisfy a two-factor requirement.
It only renders when there is something to show, and only to people allowed to see it. No card means no bypass events.
Everything is in the audit log, kept for seven years. See Audit log.