How do I rotate the portal link, revoke a device or lock the portal?
Regenerate the staff portal link with a grace period, disable the portal in an emergency, revoke paired devices and clear PIN lockouts.
All the portal lockdown tools live in Settings → Security — rotate the link if it leaks, flip the kill switch in an emergency, and revoke any single device. Only Owners and Admins can use them; other staff see the page read-only, and every action asks you to confirm your password.
Regenerate the portal link
Rotating creates a brand-new link; you choose how long the old one keeps working so staff have time to switch.
- Open Settings → Security → Staff portal access. Your Current staff portal link is shown with a Copy button.
- Click Regenerate link.
- In the pop-up, choose How long should the old link keep working? — Immediately, 1 hour, 6 hours, 24 hours (the default), 48 hours or 7 days.
- Tick Sign out all current staff sessions immediately if you also want to force every signed-in staff member out now (it ticks itself when you choose Immediately). Otherwise, signed-in staff keep working until they next sign out.
- Click Regenerate link and confirm your password.
While a grace period is running, an amber note shows "Previous link still works until …". Paired devices move themselves onto the new link automatically the next time they open the portal during the grace period — you only need to share the new link (from this page or the Staff page) with new or unpaired devices, and with anyone who doesn't open the portal before the grace period ends.
Disable the portal (kill switch)
Flip the Disable staff portal switch, confirm Disable portal in the warning, and confirm your password. Every staff sign-in attempt is refused until you re-enable it — the link itself still exists, only access is blocked. Re-enabling is one flip of the same switch, with no warning step. Use this when you suspect a leak and need to lock things down fast.
Revoke one device
Under Paired devices, click Revoke next to the device and confirm your password. It loses access immediately and drops back to the pairing screen on its next page load — staff on it see "This device was removed by the account owner."
Clear a PIN lockout
Ten wrong PINs lock a device for an hour. To clear it early, go to the Staff page: an amber "A device is locked out from too many wrong PINs" banner offers Clear lockouts, and there's a Clear all lockouts button at the top. Both clear every device lockout at once (device locks aren't tied to one person) and ask for your password.
Keeping an eye on things. The Rotation history table lists your last 10 link rotations (who, when, and the grace chosen) with View all in Activity Log → for more, and email alerts for rotations, the kill switch and repeated PIN failures are covered in the security alerts guide.
Related: How do I set up a device for the staff portal? · Which security alert emails can I get? · Why did my staff portal link stop working?