Which security alert emails can I get?
Four security events can email the account owner — portal link rotated, portal disabled, a new IP signing in, and repeated failed PIN attempts.
ResoFlow can email the account owner when something security-sensitive happens — all four alerts are on by default and live in Settings → Security policy, under Security alerts & audit.
Only Owners and Admins can change these; other staff who reach the page can view but not change them.
- Go to Settings → Security policy and open Security alerts & audit.
- Portal link regenerated — emails you when the staff portal URL is rotated (by you or another owner).
- Portal disabled — emails you when the portal's emergency kill switch is flipped to disabled.
- New IP signed in to the portal — emails you when a staff PIN succeeds from an IP address not seen in the last 30 days. A new device on your venue Wi-Fi is normal; a sign-in from an unexpected location is worth investigating.
- Repeated failed PIN attempts — emails you when 10 failed PIN attempts lock a device or connection for 1 hour. You can clear any lock early from the Staff page (Clear lockouts).
- Each switch saves as soon as you flip it — there's no separate save step for these.
Checking what actually happened
Below the toggles, click View security activity — it opens the Activity Log filtered to security events, where every sign-in, portal change and security-policy update is recorded.
Related: How do I rotate the portal link, revoke a device or lock the portal? · How do I see who did what? · How do I restrict the staff portal to my venue's network?