Help centre · People and access
Making somebody set a new password
Three controls on a person's card: send them a link, end their sessions, or stop their password working until they choose a new one.
For owner, manager · checked against the product on 2026-08-23
Three separate controls sit on each person's card on Team, and they escalate. Picking the right one matters, because the loud one cannot be undone from inside the product.
- Send a password reset link
- The polite ask. Nothing about their account changes until they use it. Good for somebody who has forgotten theirs while standing at the counter — the link works for an hour and once only.
- Sign them out everywhere
- Ends every session they have open, including the bay tablet. It changes no password of theirs, so unless they are already required to set a new one they can sign in again immediately. The screen calls this the small answer, not the loud one.
- Require a new password
- Their current password stops working immediately, every open session ends, and a link to set a new one goes to their own email. You never see it.
Requiring a new password
Above the button is a box labelled Why (they will read this), and it is worth filling in. It is optional, it goes on the sign-in screen the person meets, and somebody refused with no explanation assumes the software is broken. Three hundred characters. The placeholder is a fair example of the register: We think the counter tablet was looked over on Saturday. Never type a password into it.
Pressing it takes effect on their very next page load. The confirmation reads Dana Reyes must set a new password before they can sign in again, and every session they had open has ended. If the email did not go out, the requirement still stands and you are told so — send them to Forgot your password? on the sign-in screen instead.
The machine they were using also loses its two-factor exemption, so it will ask for a code again. Ending sessions on its own deliberately does not do that — a trusted device stays trusted when all you did was sign somebody out.
What they see
They type their password and it is correct, and they still do not get in. The check happens after the password is verified and before anything else, so it also catches a phone that would otherwise have skipped the two-factor step.
The sign-in screen tells them who and why: Pat Owner has asked you to set a new password before signing in again. Your current password is correct — it just cannot be used any more. Then your reason in quotes, then Use “Forgot your password?” below and open the link we send to your own email. With no name on record it says Your shop has instead; with no reason, that sentence is simply left out.
That notice is carried to the login page by the server rather than by the address bar, on purpose — otherwise anybody could send one of your people a link that printed whatever they liked on your sign-in screen.
It clears itself the moment they set the password. Nobody has to remember to switch it off — and nothing else clears it either. Switching their access off and back on does not: access and credentials are two different decisions, and turning one back on is not a way to quietly undo the other. Until they use a link, the requirement stands.
Seeing who is still outstanding
Their card says so while it stands: Dana Reyes already has to set a new password before signing in again with your reason quoted, and a note that pressing it again sends a fresh link and retires the old one. The whole shop's list is on the Who can see costs? screen under Outstanding password requirements — It clears itself the moment they do. Where nobody wrote a reason, that screen says so and calls it worth fixing next time.
Every one of the three controls is on the audit trail with your name on it, and a person who signs in correctly and is turned away writes a line too — as a refusal, not as a failed attempt, so it does not eat into their lock-out allowance.