What this tab controls
The card is headed Security Settings — “Manage your clinic’s security settings.”
The switch is owner-only. A manager or an accountant sees it in its current position, greyed out, with no Save Changes button.
Passkeys and your own authenticator are set up on your personal account, not here — see Your account security. This tab decides the rule for everyone; that page is where each person satisfies it.
Turn it on
1
Set up your own second factor first
Do this before you switch the requirement on, so you are not locked out of your own pharmacy. See Two-factor authentication.
2
Tell your team it is coming
Everyone will be stopped at their next sign-in and asked to enrol. A cashier discovering this at 8am with a queue is avoidable — give them a day’s notice and let them enrol early.
3
Switch Require Two-Factor Authentication on
Then select Save Changes. You get “Security settings updated successfully”.
What changes once you save
It applies from each person’s next sign-in, not immediately. Anyone already signed in keeps working until their session ends. At that next sign-in, a colleague who has no second factor is stopped and walked through setting up an authenticator app before they can reach anything. After that, records only open from a session that has passed the second factor — a session that has not is refused, even though the password was right. A passkey counts as one factor and does not satisfy this. Signing in with a passkey is still a single-factor sign-in, so someone using one will still be asked to enrol an authenticator. This surprises people; say it out loud when you announce the change. Two doors stay open, and both are recorded. From Staff and teams an owner can Reset two-factor for someone who has lost their device, or Grant emergency access for a time-boxed window. Every use of either — plus any use of a recovery code — appears on the Security alerts card here, with a severity, and stays in the audit log permanently. Acknowledging an alert marks that you have seen it; it does not undo anything. Switching the requirement back off stops new people being asked to enrol. It does not remove the second factor from anyone who already has one, and they will keep being asked for it.Check it worked
Sign out and back in yourself: you should be asked for your second factor. Then ask a colleague who has not enrolled to sign in — they should be stopped and taken through setup before they can reach a customer record. Anyone bypassing it later should appear on the Security alerts card within moments.Common issues
Someone has lost their phone and cannot sign in
Someone has lost their phone and cannot sign in
An owner can Reset two-factor from Staff and teams — it signs their sessions out and invalidates their recovery codes, and they enrol again on their next sign-in. The owner needs their own two-factor on to do it.
Someone needs access right now, mid-shift
Someone needs access right now, mid-shift
Use Grant emergency access on their staff row. It is time-boxed, needs a reason, expires by itself and is recorded on this tab.
I signed in with a passkey and was still asked to enrol
I signed in with a passkey and was still asked to enrol
That is correct. A passkey is one factor. It does not satisfy a two-factor requirement.
The Security alerts card is not there
The Security alerts card is not there
It only renders when there is something to show, and only to people allowed to see it. No card means no bypass events.
I need the full history, not just recent alerts
I need the full history, not just recent alerts
Everything is in the audit log, kept for seven years. See Audit log.