Unlocking a locked-out account

What this covers

Why an account locks itself, what the person sees, and how to let them back in immediately. Unlocking requires the manage-users permission — an Owner or a Manager.

Why accounts lock

Repeated failed sign-ins lock an account temporarily. It is brute-force protection: without it, somebody who knows your property code could try passwords indefinitely.

The account locks after ten failed attempts. The lock is on that account, not on your restaurant — everybody else carries on unaffected.

How long it lasts

Failed attemptsLocked for
1015 minutes
2030 minutes
30 or more60 minutes — the maximum

The lock lengthens for repeat episodes and never exceeds an hour, so an account is never locked indefinitely. Waiting always works eventually.

What the person sees

Their sign-in is refused and they are told the account is temporarily locked. Nothing is wrong with their account and nothing has been lost — but they cannot get in, and if it is Friday at 19:00 they cannot wait fifteen minutes either.

Unlocking someone immediately

  1. Go to Property Settings → Staff (/settings/users).
  2. Find the person.
  3. Choose Unlock.

They can sign in again at once. This exists precisely because a locked-out host during service is an operational problem, not a security one — so it is a deliberate release valve rather than something you have to wait out.

Check they know their password first. Unlocking does not change it, so someone who has genuinely forgotten it will simply lock themselves out again. If they cannot remember it, set a new one instead — which clears the lockout at the same time (link Editing and removing staff).

Other things that clear a lockout

  • Waiting for it to expire
  • A successful sign-in
  • Any password change — by them, by you, or through a password reset email

Forgotten password, or something worse?

Almost every lockout is somebody mistyping a password they half-remember. Occasionally it is not, and the difference is worth a moment's thought before you unlock.

Signs it is innocent

  • The person tells you they were locked out, and is standing in front of you
  • It is one account, once
  • They have recently changed their password, or a password manager is filling in an old one
  • They were on a new device or a phone keyboard

Signs worth investigating

  • An account locks while its owner is not working — they were not the one trying
  • Several accounts lock around the same time — someone is working through a list
  • It keeps happening to an account whose password is definitely known
  • The Owner account locks and nobody was using it

Check the audit log. It records sign-in failures and lockouts, so you can see how many attempts there were and when. A handful over a minute is a person; dozens in sequence, especially out of hours, is not.

If you suspect an attempt

  1. Do not unlock the account — the lock is doing its job.
  2. Change that account's password to something new and strong.
  3. Turn on two-factor authentication for it, which makes a stolen password insufficient on its own (link Two-factor authentication).
  4. Consider an IP allowlist if your staff only ever sign in from the restaurant (link The IP allowlist).
  5. Report it if it continues (link Reporting a problem).

If the only Owner is locked out

A Manager can unlock them, which is the easy answer and the reason to have one.

If there is no Manager either — a single-account restaurant, which is more common than it should be — the Owner has three routes:

  1. Wait. At most an hour, and usually fifteen minutes.
  2. Use the password reset email, which clears the lockout when the password changes (link Sign-in problems).
  3. Contact support if the Owner's email is also unreachable (link The Owner account).

The lesson worth taking from it: create a second account with the Manager role, even if you are a one-person operation and it never gets used. It converts a locked-out afternoon into a ten-second fix.

Good to know

Unlocking is recorded. The audit log notes who unlocked whom, so the release valve is itself accountable.

Locking is per account, not per device or address. Signing in from a different phone does not get round it.

It is unrelated to the IP allowlist. Being blocked by an allowlist looks different and has its own article (link Blocked by an IP rule).

Where to go next