How do approvals with a manager's PIN work?
Money actions like refunds can be approved at the venue with a manager's PIN instead of a password — including a special approval-only PIN for the owner.
When a money action needs an identity check on a shared front-of-house device, a staff member who's allowed to do that action can approve it by typing their own PIN — no password needed.
When the prompt appears. Actions that move a customer's money or value need a confirmation. That covers bookings (refunding a deposit, charging or refunding a no-show fee, cancelling a booking, refunding a payment-link payment), events (cancelling or refunding a ticket — including tickets on an event that's been cancelled — and cancelling a whole event with refunds), gift cards (refunding a purchase, voiding a card or correcting its balance, and resending a card's email — selling, activating and extending a card's expiry deliberately need no approval), Order & Pay (refunding a table order, whether rejecting it or refunding after the event) and loyalty (adjusting a member's balance). A PIN approval is also offered for bigger operational actions when the staff member holds that action's permission: messaging all of an event's attendees or your loyalty members, sending a marketing campaign to 10 or more people, replacing the whole menu with an import, deleting images from the image library, and staff management (removing a staff member, changing someone's role, clearing all sign-in lockouts). Where a PIN approval is offered, a pop-up titled Approve this action opens instead of (or alongside) the password prompt.
- When the Approve this action pop-up appears, hand the device to (or call over) someone whose role allows that action — for example, refunds need the refund permission, which is off for Managers and Hosts unless you've granted it.
- They type their staff PIN and click Approve.
- The pop-up shows "Approved — applying now…" while the action lands, then closes — and the activity log records exactly who approved it.
A few rules keep this safe:
- A PIN can never approve more than its owner could do themselves. The PIN holder's own role, plan and overrides are re-checked at the moment of approval.
- One approval, one action. Each PIN approval covers a single action and expires within two minutes if unused.
- Wrong PINs lock the approval prompt, not the portal. Five wrong PINs within 30 minutes locks approvals for 30 minutes ("Too many attempts — try again shortly") — staff sign-in on the device is unaffected.
- Customer data never accepts a PIN. Customer data exports, erasure and other privacy tools always require the account password.
- If the signed-in user could confirm with a password instead, the pop-up offers Use your account password instead.
The owner's approval PIN. You sign in with a password, so you have no login PIN — but you can set an approval-only one. On the Staff page, click Approval PIN on your own row, enter a New PIN and Confirm PIN, then Save PIN. As the pop-up notes, "This PIN can't be used to sign into the staff portal — it only approves or overrides restricted actions." Remove it any time with Remove PIN. Only Owners and Admins see the Approval PIN button.
Related: How do I reset or change PINs? · What can each role do? · How do I cancel a booking (and what happens to the deposit)?