ALLMSP Blog

Housecall Pro Access Security: Roles, 2FA, and Offboarding

A vendor-specific access lifecycle for Housecall Pro teams, from individual onboarding and permission design through two-factor authentication, remote logout, and archival.

Housecall Pro user-permissions-security-offboarding support for a Georgia business

A Housecall Pro account can expose more than a schedule. Depending on role and permissions, a user may see customer contact details, pricing, payment functions, reports, employee pay information, company settings, or the ability to delete and cancel work. Access therefore needs the same lifecycle discipline as a company phone, vehicle key, or building badge.

Housecall Pro currently organizes team members as Admin or Owner, Office Staff, and Field Tech, with individual permissions beneath those roles. Its documentation says Admins have broad account access, while Field Techs use the mobile app rather than the web portal. The platform also supports SMS-based two-factor authentication, remote logout, and archiving that prevents a former team member from signing back in unless access is restored.

The secure pattern is straightforward: issue an individual identity, grant only the duties required, protect the login, review changes, and close every access path promptly at separation. The details matter because an incomplete offboarding can leave mobile access active, while an overly aggressive deletion process can make historical schedules and time records harder to interpret.

Key decisions at a glance

  • Give every Housecall Pro user an individual profile; shared credentials defeat permission design, offboarding, and accountability.
  • Reserve Admin access for owners and primary administrators because Housecall Pro describes that role as having broad account control.
  • Review the specific permissions beneath Office Staff and Field Tech roles, especially customer data, payments, deletion, company settings, and employee pay details.
  • Enable Housecall Pro two-factor authentication and confirm the registered mobile number before a worker depends on the account in the field.
  • Use remote logout and profile archival during offboarding, then reassign future work and verify any connected devices or external tools separately.

Translate Job Duties Into Housecall Pro Roles

Housecall Pro support workflow: Translate Job Duties Into Housecall Pro Roles
Housecall Pro support workflow: Translate Job Duties Into Housecall Pro Roles

Begin with the three documented role families, then decide which specific permissions each job function needs. An owner who controls billing and configuration may need Admin access; a dispatcher may fit Office Staff; a technician who works only assigned jobs may fit Field Tech. Do not use a higher role merely to bypass one missing checkbox without reviewing everything else it unlocks.

Housecall Pro describes Admin access as broad, including employee management, reporting, schedules, and company information, and recommends limiting it to owners or primary administrators. Field Tech permissions can separately govern adding or editing jobs, deleting or canceling work, taking payments and seeing prices, depositing checks, viewing customer contact details, accessing the customer database, and changing company settings. Those distinctions should map to written duties, not seniority or convenience.

Pay special attention to compound permissions. Mobile check deposit depends on payment capability, customer chat relates to contact visibility, and company-account access can reach sensitive settings. Record why each elevated permission exists, its approver, and the date it should be reviewed; that turns a checkbox into an accountable business decision.

  • Create a short role matrix for owners, dispatchers, bookkeepers, supervisors, estimators, and field technicians.
  • Limit Admin or Owner status to the smallest practical group and retain at least one recoverable primary administrator.
  • Review customer database, payment, delete or cancel, company settings, reports, and employee-pay access individually.
  • Document temporary elevation with an expiry date instead of leaving a permanent broad role in place.

Onboard Individual Users and Protect Their Sign-In

Housecall Pro support workflow: Onboard Individual Users and Protect Their Sign-In
Housecall Pro support workflow: Onboard Individual Users and Protect Their Sign-In

Create a separate Housecall Pro team-member profile for each person using their current email address and mobile number. Housecall Pro sends an invite link by email and SMS, and its role and permission controls belong to that profile. An individual account lets the company change one person's access without disrupting the rest of the crew.

Enable Housecall Pro two-factor authentication through the Login Authentication settings. The current help article describes an SMS one-time password sent to the registered mobile device and says the challenge applies on web, iOS, and Android when enabled. Verify the phone number before field deployment and make the support path clear for a technician who loses or replaces the device.

Use a strong, unique password and never store it in job notes, dispatch messages, or a shared clipboard. Housecall Pro's password-reset flow sends a reset link to the email address associated with the profile, so the company should also control the lifecycle of work email and recovery access. Test login, 2FA, and the assigned role before the employee's first solo shift.

  • Use one profile per human and one company-managed email or approved individual email per profile.
  • Confirm the employee's current mobile number before enabling SMS-based two-factor authentication.
  • Complete detailed permission edits in the web portal and have the user log out and back in after changes so they apply.
  • Record the company phone, tablet, card reader, keys, and badge issued alongside the software account.

Offboard Without Losing the Operational Record

Housecall Pro support workflow: Offboard Without Losing the Operational Record
Housecall Pro support workflow: Offboard Without Losing the Operational Record

When employment or contract access ends, start with Housecall Pro's remote logout function if the session must be terminated immediately. The profile-management documentation says remote logout signs the team member out of both the web portal, when applicable, and the mobile app. Change the associated email when required by the documented archival workflow, then archive the user so the former worker cannot sign back in.

Archiving does not erase every operational relationship. Housecall Pro notes that archived employees can remain associated with past or future jobs and that historical time visibility may change for a deleted Field Tech. Before archival, export or review any timekeeping evidence the company must retain, identify future assignments, and reassign the schedule to active staff.

Software access is only one line of the separation checklist. Recover phones, tablets, card readers, keys, and badges; disable work email and mobile service; review password-manager entries; and remove access to accounting, maps, messaging, cloud storage, and vendor portals. Confirm completion with two people for high-risk departures rather than relying on an informal message.

  • Use remote logout first when immediate session termination is required.
  • Archive the profile according to Housecall Pro's current procedure and verify that sign-in is no longer possible.
  • Reassign future jobs, the Dispatch or Messaging point of contact, and any pending tasks before the next service day.
  • Capture required time and assignment history, then recover every company device and physical access item.

Audit Access as the Team and Workflow Change

Review Housecall Pro roles on a schedule tied to business change, not only to an annual compliance date. Promotions, new payment duties, seasonal hiring, acquisitions, and dispatch reorganizations can all make an old permission set inappropriate. Compare the role matrix to the current team list, device inventory, and actual responsibilities at least quarterly.

Inspect high-impact exceptions first: multiple Admins, Office Staff with company-setting access, field users who can delete jobs, employees who can see the full customer database, payment and check-deposit permissions, and visibility into employee pay. Ask the manager to justify the business need and remove access that is no longer used. A permission that has never caused an incident can still be excessive.

Build a small incident runbook for a lost phone, suspicious login, compromised email, or unexpected account change. Remote logout, password reset, device recovery, 2FA support, permission review, and evidence preservation belong in a known order. After containment, verify scheduled jobs and customer communications so a security response does not quietly break field operations.

  • Reconcile active Housecall Pro profiles to payroll, contractor, and device inventories each quarter.
  • Review privileged permissions after organizational changes and immediately after any access incident.
  • Test the remote-logout and password-reset procedures with a noncritical account before an emergency.
  • Keep an approval record for access changes and an offboarding record for every archived user.

Frequently Asked Questions

What Housecall Pro roles are available for team members?

Housecall Pro documents Admin or Owner, Office Staff, and Field Tech roles, with additional permissions beneath them. Choose the lowest role and permission combination that supports the person's actual duties.

Should every Housecall Pro user have an individual login?

Yes. Individual profiles make permissions, 2FA, remote logout, and offboarding specific to one person. Shared credentials remove accountability and make prompt access removal much harder.

Who should receive Housecall Pro Admin access?

Housecall Pro describes Admin access as broad and recommends limiting it to owners or primary administrators. Keep the group small, document the need, and retain a recoverable administration path.

Can Housecall Pro Field Tech users sign in to the web portal?

Housecall Pro's current roles documentation says Field Techs use the mobile app and do not have web-portal access. If a worker needs office-style visibility, review whether an Office Staff role with carefully limited permissions is appropriate.

Does Housecall Pro support two-factor authentication?

Yes. Housecall Pro documents an SMS one-time password sent to the mobile number registered on the user's profile. Verify the number and the recovery process before the account becomes operationally critical.

Who can enable 2FA in Housecall Pro?

The current help article says an Admin or Owner, or a user with the required company-information permission, can enable it for team members. Keep that authority limited and record configuration changes.

Do Housecall Pro permission changes apply immediately?

Housecall Pro instructs users to log out and back in after role or permission changes. Include that step in the change ticket and verify the expected behavior from the user's actual device.

What does Housecall Pro remote logout do?

The profile-management guide says it immediately logs the team member out of the web portal, when applicable, and the mobile app. Use it for urgent containment, then change or archive the account so the person cannot simply sign in again.

What happens when a Housecall Pro team member is archived?

The former team member loses access, but job associations can remain and some historical time display can change for deleted Field Techs. Review records and reassign future work before completing the process.

What belongs on a Housecall Pro offboarding checklist?

Include remote logout, profile archival, future-job reassignment, point-of-contact transfer, required record capture, and recovery of phones, tablets, keys, badges, and card readers. Also remove access to connected email, accounting, storage, and messaging systems.

Facebook
LinkedIn
WhatsApp
X
Email
Print
Threads
Reddit

Related Articles