How do I restrict the staff portal to my venue's network?
Limit staff PIN sign-ins to specific IP addresses so the portal only works from inside your restaurant.
You can restrict staff PIN sign-ins to a list of approved internet addresses, so the portal only works from your venue's own connection.
Only Owners and Admins can change this. One big caveat before you start: only turn this on if your restaurant has a STATIC IP address. Most home and small-business broadband uses a dynamic IP that changes without warning — if yours changes, you and every member of staff are locked out of the portal until you add the new address. Check with your internet provider first.
- Open Settings → Security, expand Staff portal access, and scroll to Staff portal IP allowlist.
- Switch on Restrict portal to specific IP addresses.
- Under Allowed IPs / CIDR ranges (one per line), type each allowed address on its own line. Single IPv4/IPv6 addresses and CIDR ranges (e.g. 10.0.0.0/24) are accepted; invalid lines are flagged before you can save.
- Use Add your current IP: find your public IP (the panel links to whatismyipaddress.com — ResoFlow doesn't look it up for you), paste it in, and click Add. Always include your own current IP.
- Click Save changes.
If ResoFlow can't confirm your own IP is on the list, it double-checks before saving — "Lock yourself out?" when it knows your pasted IP is missing, or "Is your current IP on the list?" when it can't tell. Read those carefully: saving anyway can lock your whole team out until you sign in from an allowlisted address or turn the restriction off again.
Once on, PIN sign-ins from any address not on the list are refused. It only affects the staff portal — your own dashboard sign-in, the customer portal and your public booking page are untouched.
Related: How do staff sign in with a PIN? · How do I rotate the portal link, revoke a device or lock the portal?