ALLMSP Blog

Square Team Access Security: Permissions, 2FA, and Offboarding

A Square access-control runbook for owners, managers, employees, representatives, and support partners across locations and business transitions.

Square team-permissions-2fa-access-lifecycle support for a Georgia business

Square access is not one switch. An account owner, full-access manager, location-limited employee, personal passcode user, authorized representative, developer, and connected application can each reach different parts of the business. If those paths are not inventoried separately, removing a name from the team roster can leave support authority, app access, a remembered device, or an operational dependency behind.

Square's current permission model applies across Dashboard, the Dashboard app, Square Team, and points of sale, with location assignment further limiting data and features. Its documentation also distinguishes a shared team passcode from personal passcodes: the shared path does not identify an individual's sales, time, or activity. That makes identity design an operations and audit decision, not merely a faster way to unlock checkout.

This guide focuses on Square software identity and access for Georgia retailers and restaurants. It covers role design, two-step verification, recovery, authorized representatives, reviews, and offboarding. Physical device security and hardware replacement remain part of the separate Square hardware plan.

Key decisions at a glance

  • Map each job to the minimum Square permission set, access point, and location scope required instead of cloning a manager profile.
  • Use named team members and personal passcodes where accountability matters; a shared passcode cannot attribute activity to one employee.
  • Enable business two-step verification for team members and maintain an approved recovery path that does not depend on a departed person's phone.
  • Track authorized representatives and application connections separately from ordinary team membership because each can preserve meaningful access after a role changes.
  • Make offboarding a verified sequence covering Square, email, devices, credentials, representatives, apps, exports, open work, and ownership handoff.

Translate Jobs Into Permission Sets, Access Points, and Locations

Square support workflow: Translate Jobs Into Permission Sets, Access Points, and Locations
Square support workflow: Translate Jobs Into Permission Sets, Access Points, and Locations

Build a role matrix from real tasks: taking payments, issuing refunds, changing items, viewing reports, counting stock, managing team members, editing business settings, handling bank information, exporting customer data, or contacting support. For each task, identify the minimum Square permission, the access point where it is needed, the locations in scope, the approving owner, and any separation of duties. Avoid labels such as manager or admin unless the underlying permissions are recorded.

Square permission sets can affect Dashboard, applications, and shared points of sale. Current guidance offers predefined levels and customizable permissions, while plan entitlements influence how many custom sets are available. Treat subscription capability as a design constraint and document it. Never solve a missing custom role by granting full access without a risk decision, expiry date, and owner.

Use location assignment to contain ordinary work. A team member assigned only to one location should not need unrelated menus, reports, or operational data from another. Test the role from the employee's actual login and device: verify the required action succeeds, a prohibited action fails, the intended locations appear, and the employee does not fall back to a shared owner credential when something is inconvenient.

  • List every Square task by role and identify whether it changes money, customer data, catalog, inventory, team access, reports, or business settings.
  • Separate daily operations from rare administrative work and require a controlled elevation path for exceptional tasks.
  • Test permission changes in a representative workflow because changing a set applies to all team members assigned to it.
  • Record the plan entitlement, permission-set name, access points, locations, members, approver, review date, and business justification.

Harden Sign-In, Two-Step Verification, Passcodes, and Recovery

Square support workflow: Harden Sign-In, Two-Step Verification, Passcodes, and Recovery
Square support workflow: Harden Sign-In, Two-Step Verification, Passcodes, and Recovery

Require each Dashboard-capable user to use an individual identity. Enable Square's business two-step verification requirement for team members, then confirm enrollment rather than assuming the policy toggle completed the work. Square currently supports authentication apps, SMS, and voice methods and allows backup methods. Prefer a managed authenticator where the organization can support it, and document the approved fallback without collecting verification codes or authenticator secrets in tickets.

Treat remembered devices and shared points of sale as distinct risks. Square documents a remember-this-device interval for sign-in verification, while point-of-sale access may rely on personal passcodes, a shared team passcode, or badges depending on configuration. Name shared devices, limit physical access, prevent password-manager autofill for owner credentials, and make the cashier workflow work with the intended identity so staff have no reason to borrow a manager's passcode.

Design recovery before an incident. Record the owner identity, verified contact paths, backup verification method, authorized support contacts, organization-controlled email, and escalation documentation. Do not make one employee's personal phone the only way to reach the account. Test how a lost phone, changed number, locked mailbox, unavailable owner, or departing administrator would be handled without bypassing Square's verification process.

  • Require individual Dashboard sign-ins and prohibit shared owner credentials in browsers, notes, chat, or generic store mailboxes.
  • Track two-step enrollment and backup readiness without storing codes, recovery secrets, or full phone numbers in ordinary documentation.
  • Rotate personal and shared passcodes after suspected disclosure and whenever a departing user could still know a shared value.
  • Review remembered browsers, shared tablets, remote-support tools, password managers, and mailbox sessions during security events and departures.

Control Joiners, Movers, Representatives, and Departures

Square support workflow: Control Joiners, Movers, Representatives, and Departures
Square support workflow: Control Joiners, Movers, Representatives, and Departures

For a new team member, create the profile from an approved request, assign the validated permission set and locations, generate the intended personal passcode, require two-step verification where applicable, and verify the invitation is accepted by the correct person. Tie access to a start date and manager. Training should use the employee's own path so missing permissions are discovered before a busy shift.

A role change deserves a fresh access decision. Remove locations and high-risk permissions that no longer apply; do not only add the new role. Square notes that editing a permission set changes access for every member assigned to it, so decide whether the employee belongs in another set or whether the set itself should change. Re-run prohibited-action tests after a mover event and update support authority, reports, integrations, and data exports.

Offboarding should deactivate the team member and separately remove authorized-representative status, disconnect or transfer apps they owned, revoke developer or vendor access, rotate shared passcodes, recover organization devices, close browser and remote-support sessions, transfer scheduled reports and operational queues, and preserve required business records. Square says a deactivated profile is retained and can be reactivated, so verification must check effective access rather than treating deactivation as deletion.

  • Use one accountable request for start date, manager, role, locations, access points, elevated exceptions, and two-step enrollment.
  • For movers, compare old and new access side by side and explicitly remove privileges, locations, support authority, and reports no longer needed.
  • For leavers, execute Square, identity provider, email, devices, browser sessions, apps, developer credentials, representatives, exports, and shared secrets together.
  • Capture a completion check from a second person, including a denied login or prohibited-action test where safe and appropriate.

Review Access as Operational Evidence, Not a One-Time Setup

Run a periodic review from the team roster, permission sets, locations, representatives, connected apps, developer owners, scheduled report recipients, and the organization's employment record. Ask managers to attest to tasks, not titles. Investigate dormant identities, broad access, shared passcodes, unaccepted invitations, former locations, owner-level dependencies, and vendor accounts without an expiry or named sponsor.

Treat high-risk changes as security events. An owner email or phone change, new full-access role, business two-step policy change, representative addition, app authorization, bank-setting change, or unexplained passcode reset should produce a reviewable record. Preserve who requested and approved it, the affected scope, verification method, time, reason, and validation result without storing authentication secrets.

ALLMSP can help Georgia retailers and restaurants inventory Square access paths, design location-aware permission sets, roll out two-step verification, document recovery, test roles, coordinate joiner-mover-leaver workflows, and conduct access reviews. The result is a business that can identify who has access, why they need it, how they recover it, and how it is removed.

  • Review owner and full-access dependencies more frequently than ordinary cashier roles and require a named remediation owner.
  • Reconcile Square access to employment, contractor, franchise, and vendor records rather than relying on the team list alone.
  • Sample real role behavior at each location so permission drift and shared-credential workarounds are visible.
  • Track findings through closure and retain evidence that access was removed, narrowed, transferred, or explicitly accepted.

Frequently Asked Questions

What is the safest way to give a Square manager access?

Map the manager's real tasks to the minimum permission set, access points, and locations. Test both required and prohibited actions from the manager's identity. Do not default to owner or full access merely because the role sometimes needs an exception.

What is the difference between a Square team passcode and a personal passcode?

A shared team passcode gives members of that shared path access but does not attribute sales, time, or activity to one person. Personal passcodes support individual accountability. Use the path that matches the audit and operational requirement.

Can Square require two-step verification for team members?

Yes. Square documents a business setting that requires two-step verification for team members. Enable it, confirm individual enrollment and a supported backup method, and define recovery before a phone or employee becomes unavailable.

Should employees share the Square account owner's login?

No. The owner identity has exceptional authority and creates a recovery dependency. Give each person a named team identity with the required role and location scope, and keep owner credentials out of shared browsers, notes, and store mailboxes.

How do Square locations affect team access?

Square states that assigned locations determine which location-specific data, menus, reports, and features a team member can access. Include location scope in every joiner and mover request and verify it from the user's actual sign-in.

What should happen when a Square team member changes jobs?

Compare old and new tasks, remove obsolete permissions and locations, assign the approved set, re-test access, update representatives and reports, and check apps or exports. A mover review must subtract access as well as add it.

Does deactivating a Square team member delete the profile?

No. Square says deactivation retains the team member's information and permits later reactivation. Use deactivation as one offboarding step, then remove other access paths, shared secrets, representatives, devices, applications, and sessions.

What is an authorized representative in Square?

It is a team member or associate granted authority to contact Square Support for defined account matters. Track that status separately, approve it deliberately, and remove it when the business relationship or responsibility ends.

How often should Square permissions be reviewed?

Set a risk-based cadence and also review after role changes, location openings or closures, ownership changes, incidents, new integrations, and departures. Reconcile team, representatives, apps, reports, and developer ownership to current business records.

How can ALLMSP improve Square access security for a Georgia business?

ALLMSP can inventory identities, design permission and location matrices, deploy two-step verification, document recovery, test roles, coordinate offboarding, review connected access, and retain practical evidence for Georgia retail and restaurant operators.

Facebook
LinkedIn
WhatsApp
X
Email
Print
Threads
Reddit

Related Articles