Restricted Team members full access to owner info

I currently have team members restricted access activated to not view owner information. When team members log in and access More ( 3 lines bottom right ) menu to the welcome back list screen, clicking on Marketplace grants them access to owners information through a web browser window, providing them with unrestricted access and bypass without 2 step verification. how do i stop this?

682 Views
Message 1 of 2
Report
1 Solution
Square Community Moderator

Solution

Hi @Stomco ! 

 

The behavior described of employees being able to access account information from the marketplace depends on several factors, such as whether credentials were saved in the browser on the device or other account-specific and device-specific conditions. The marketplace feature functions similarly to accessing a browser on the same device; it just uses a different redirect mechanism.
 
Here are some tips that can prevent this from happening:
  1. Avoid autofilled passwords: Users should disable password autofill on the device to prevent unintended access.
  2. Two-Factor Authentication (2FA): If you want 2FA to prompt consistently, you should avoid selecting the "Remember this device for 90 days" option during login. This setting is typically stored via cookies or cache.
  3. Clearing cookies and cache: To reset any saved preferences, including the 90-day login exemption, you can clear the cookies and cache on their device.
Additionally, if there’s a concern about an employee logging in with  your credentials, you should:
  • Ensure the employee doesn’t have dashboard access by adjusting their permission settings appropriately.
This approach helps secure access and ensures only authorized individuals can log in where necessary.
 
I hope this helps! 

View Solution >

576 Views
Message 2 of 2
Report
1 REPLY 1
Square Community Moderator

Solution

Hi @Stomco ! 

 

The behavior described of employees being able to access account information from the marketplace depends on several factors, such as whether credentials were saved in the browser on the device or other account-specific and device-specific conditions. The marketplace feature functions similarly to accessing a browser on the same device; it just uses a different redirect mechanism.
 
Here are some tips that can prevent this from happening:
  1. Avoid autofilled passwords: Users should disable password autofill on the device to prevent unintended access.
  2. Two-Factor Authentication (2FA): If you want 2FA to prompt consistently, you should avoid selecting the "Remember this device for 90 days" option during login. This setting is typically stored via cookies or cache.
  3. Clearing cookies and cache: To reset any saved preferences, including the 90-day login exemption, you can clear the cookies and cache on their device.
Additionally, if there’s a concern about an employee logging in with  your credentials, you should:
  • Ensure the employee doesn’t have dashboard access by adjusting their permission settings appropriately.
This approach helps secure access and ensures only authorized individuals can log in where necessary.
 
I hope this helps! 
577 Views
Message 2 of 2
Report