Skip to content

Help centre · People and access

When Torqix support looks at your shop

Support can read the shape of your account and cannot change a thing in it — unless you hand them a code and a time limit yourself.

For owner · checked against the product on 2026-08-23

Somebody at Torqix answering your question can open a read-only view of your account. They cannot change anything in it. Not "are not supposed to" — cannot: the connection they read through is opened read-only at the database, so a write is refused by Postgres before any code of ours gets a say, and there is no shop session anywhere for them to be signed into.

What they see is the shape of the account rather than its contents. Customer names, phone numbers, email addresses, VINs, plates, unit numbers, the amounts on your invoices and the free text of your orders, inspections and messages are all withheld from that view, and the screen they are on lists what it is not showing them rather than leaving blanks.

Every view is logged before it opens, with a reason they had to type, and it expires by itself after fifteen minutes.

When they need to change something

Then they have to ask you, out loud, and you have to say yes on your own screen. Torqix cannot create a request in your product — the platform's own database account has no permission to write to the consent table at all. There is no notification for you to click through, and there never will be a pre-ticked box.

  1. Step 1: They read you a code

    It is long, and it is safe to read down the phone — holding it grants nothing. It carries who is asking, what for, and how long they want, and it stops working after twenty minutes.

  2. Step 2: You open Support access

    It is under settings, owner-only, and also linked from the audit trail. Paste the code into The code they gave you and press Review and grant — you see exactly who is asking and what for before you agree.

  3. Step 3: You choose the time

    Fifteen, thirty or sixty minutes, and the hint is the point: You choose. If they asked for longer than this, they get this. You can always give less than they asked for and never more.

It is live from that moment and ends on its own: It is live now and ends by itself when the time runs out. Everything they do with it appears below and on your audit trail, with their name on it. To end it early, press End this now on the live card.

There is exactly one thing you can consent to today, and it is the one people actually ring about: Reset a staff member's two-factor enrolment — clearing the setup on one of your staff accounts so that person can enrol a new authenticator. Their password is not changed, not read and not reset. If support asks for anything else, there is no way to grant it.

Seeing what happened

The Support access screen has two lists. Live right now is anybody who can currently change something, with the minutes counting down; when nobody can, it says Nobody can change anything and explains that support can see the account's shape and that the database refuses any change they attempt. What support has done is every consent you have ever granted and everything done under each one — Nothing here can be deleted — not by you, and not by us.

On the audit trail a support action never reads like a colleague's. The actor column says Torqix support with their name after it and a badge reading Not your staff, and owners get a line under the header pointing at this screen.

A consent you end stays on the record — it is marked You ended it rather than removed, because a granted permission is evidence. There is no un-revoking; a new grant is the only way back.

When a code will not work

  • That code did not verify. It may have been mistyped, or altered on its way to you — either way it grants nothing, and nothing was changed. Ask them to send a fresh one.
  • That code has expired. Codes last twenty minutes; ask support for a new one.
  • That code was issued for a different Torqix account, so it cannot be used here.

And on their side, once you have ended it or it has lapsed, everything they try is refused by name — the consent is checked against who they are and what it was for, so a permission granted for one task cannot be spent on another. The write itself then runs on your ordinary tenant connection, with all the same fences your own staff work behind: less access than their read-only view had, not more.