RentalTideRentalTideDocs
Dashboard

Security

Business-wide sign-in policy — requiring two-factor authentication, who it applies to, the grace period, and optional password rotation

Security

Admin > Security sets how your team signs in. The settings apply to your whole business, not to one person.

Owner only

Only an Owner can change these. Everyone else sees the current policy read-only, with "Only an Owner can change this." below the form.


Two-factor authentication

Require two-factor authentication makes your team add a second factor. Members add either an authenticator app or a passkey.

A passkey counts as two-factor. Face ID, Touch ID or a security key satisfies the requirement on its own, which is worth telling your staff, because it is faster than an authenticator app and harder to phish.

Two more settings appear once it is on:

Applies to

OptionWho must enrol
Everyone in the businessEvery staff account
Owners & Admins onlyJust the accounts that can change settings, move money or manage staff

Grace period (days), from 0 to 90. Existing members get this long to set a second factor before it is enforced. New members are covered from the start.

Owners and Admins only, with a real grace period

For most operators, Owners & Admins only is the right setting. Those are the accounts that can issue refunds, change pricing and export customer data, and there are few enough of them to chase personally.

Requiring it of every seasonal dock hand tends to produce shared logins, which is worse than what you started with.

Give a grace period of at least seven days. Zero means your staff discover the requirement at the counter with a customer waiting.

Enrolment happens at sign-in, not here. This page sets the requirement; the sign-in flow collects the factor.


Password rotation

Force periodic password changes makes members set a new password on a schedule, from 1 to 365 days.

It is off by default and should usually stay off. The helper text on the page explains why:

modern guidance (NIST 800-63B) advises against forced rotation, but some compliance regimes require it.

Forced rotation reliably produces Summer2026! becoming Summer2027!, and passwords on sticky notes. Turn it on when a contract or a certification requires it, not as a general precaution. If you want a genuine security improvement, require two-factor instead.

An expired password is enforced at sign-in: the member cannot get in until they set a new one, and there is no warning before the deadline. Tell your team before you turn this on.


What this page does not cover

  • IP allowlisting, session length and per-device controls are not configured here
  • Enrolling your own second factor happens on the sign-in screen, not here
  • Who can do what inside the product is staff roles and permissions

Before you turn anything on

Make sure a second Owner can get in

These settings apply to Owners too. If you are the only Owner, your own account is the one that locks you out.

Confirm at least one other Owner can sign in, or that you have your own second factor enrolled and its recovery method saved, before requiring two-factor with a short grace period.


👥Staff management
🔑Partner access
🔒Data privacy
🛡️Reliability
Was this page helpful?
Need help? Contact Support.See what’s new. Check out changelog.Questions? Book a video chat.
Ask AI
Responses are generated using AI and may contain mistakes.
Ask questions about RentalTide and get help with your integration.