
System Selection
Part of POS security and controls
Protecting administrator accounts on shared counter devices
Separate POS administrator login from staff PIN use, protect account credentials and set a shared-counter handover.
Keep the account that sets up or administers a POS device separate from the staff identity used for daily sales. After an administrator finishes a task, return the shared device to its staff PIN or lock screen. The next cashier should use their own identity.
Administrator Task Workflow on Shared POS Devices
- Use administrator account to perform setup or changes
- Close sensitive screens after completing task
- Return device to staff PIN login screen
- Verify cashier can proceed with daily sales
Identify the access layers
Write down who can set up the POS app on each device, who can change its settings and who can unlock it during a shift. These may be different people and access steps.
Shopify POS has an initial device login by an authorised setup user, followed by staff PIN access. PIN actions are associated with the staff member who entered the PIN.
At Pro locations, a POS role controls that staff member's actions; those role restrictions do not apply at Lite locations. Shopify's setup requirements also depend on account roles, so confirm who is authorised to prepare each device.
Square distinguishes an owner passcode, a shared team passcode and personal staff passcodes. The owner passcode has the highest POS access. A shared team passcode does not attribute activity to an individual; personal passcodes can. Check which type is in use on each counter.
Secure the administrator login
Give administrators individual accounts where supported. Use unique credentials, controlled recovery and a second authentication step for the account. Square documents two-step verification for owners and team members.
Shopify allows individual users to set up two-step authentication; some requirements are set by the organisation. These account protections are separate from a staff PIN unlock and should not be described as a second factor on every sale.
Do not leave the administrator password at the counter or share a one-time code. After changing settings or approving an action, close the sensitive screen and return to the ordinary staff workflow. If the provider supports a manager-approval route, use that route rather than handing the manager's PIN to a cashier.
Key Security Practices for Shared Counter Devices
- Use unique credentials for admins
- Required
- Enable two-step verification
- Recommended (Shopify & Square)
- Do not leave passwords at counter
- Mandatory
- Revoke device access if lost or staff leave
- Supported by Shopify
Set a practical handover
Choose when staff must enter a PIN again, according to the available controls and service pace. Square documents a configurable passcode timeout. A timeout helps only if staff keep their personal passcodes private.
Keep the device screen lock active where compatible with checkout, limit who can install software or change settings, and apply supported updates.
Check each shared counter
Have an authorised person finish an administrator task, return the device to the staff screen and check that a cashier can complete routine work without reaching administrator settings. Check the configured idle lock as well.
Record the device, location, account type, plan and observed result. This is a proposed check until someone performs it.
If an administrator leaves or a device is lost, use the provider's supported account and device-access controls. Shopify lists revoking device permissions as a user-management action.



