---
title: "Authentication"
canonical: "https://red-ant-documentation.refined.site/space/RET/33488897/Authentication"
format: markdown
---
> Macro (toc)

## Overview

As standard, retailers can utilise RetailOS' internal authentication system to create users and manage access to the platform. If the retailer has Enterprise SSO in place we can utilise this to provision users onto RetailOS, which avoids the need to create separate accounts for their employees.

> 📝 Read our guide on how to get started with SSO [here.](https://redantdigital.atlassian.net/wiki/spaces/RET/pages/362250241)

> ℹ️ RetailOS authentication and SSO can be used in parallel if required. This approach is typically taken if there are a sub-set of employees who aren’t set-up or managed within the retailers existing IT systems (e.g. temporary workers).

## Access Control

RetailOS uses a role-based mechanism for controlling access to the platform. Access is also store based, as users can be assigned to a specific store or set of stores which limits their access to other store data.

## Roles

As standard, RetailOS supports 6 role types;

- Temporary Worker
- Sales Assistant
- Store Manager
- Area Manager
- Admin
- Super Admin

The full permissions matrix can be found [here](https://redantdigital.atlassian.net/wiki/spaces/RET/pages/edit-v2/79593517).

> ℹ️ Out-of-the-box RetailOS has its own authentication method, however, it also supports single-sign-on (SSO) via the SAML protocol. Read our guide on how to get started with SSO [here.](https://redantdigital.atlassian.net/wiki/spaces/RET/pages/362250241) The user names, role type, store association etc. of an SSO user is typically derived from the SAML attributes.

> ⚠️ The following functionality is not applicable / available for users who have logged in with SSO:
> ⚠️ 
> ⚠️ - Resetting Your Password
> ⚠️   - Forced Password Update
> ⚠️ - Recent Users
> ⚠️ - Account Lock
> ⚠️   - Forced Account Lock
> ⚠️   - Screen Lock

## Logging In

Every RetailOS user will have their own login credentials. RetailOS users can be configured so that they can log in either with a unique username or email address and password. 

![image](media://3d914657-c158-4369-aeac-60ec5f73cf59)

> ⚠️ Users are typically set up in advance - in this instance, users must reset their password before logging into the platform for the first time.

### Store Selection

Users associated with multiple stores will be asked to select which store they wish to log in to after entering their username/email address and password. 

Once logged in, the name of the selected store will be displayed within the global menu for reference.

> ℹ️ If the user account is only assigned to a single store this step will be automatically bypassed.

### Department Selection

Users can be associated with one or many departments. Users who are associated with multiple departments will be asked to select which department they wish to associate their session with as part of login.

Once logged in, the name of the selected department will be displayed within the global menu for reference.

> ℹ️ The department that a user is logged in to can be used to configure department specific notifications. For example, if the user is logged into the ‘Stock Room’ department, they will automatically receive notifications of a stock room picking requests. See ‘[Pick from Store](https://redantdigital.atlassian.net/wiki/spaces/RET/pages/34275329)’ for more details.

## Resetting Your Password

Users have the option to request a password reset in the event they have forgotten their password. The user must enter the username/email address associated with their account before submitting this information to trigger the reset password email.

Users who have submitted a forgotten password request will receive a branded reset password email that details the name of the person who submitted the request and a link to change their password.

Selecting the link to change your password returns the user to the app where they must enter and confirm their new password before logging in with their new details.

![image](media://fef3764e-7297-445c-a194-ee536bcca571)

> ℹ️ Users will only receive a password reset email if they have an email address associated with their account.

### Password Policy

- Must be at least 10 characters long (and a maximum of 30)
- Contain at least one upper-case character
- Contain at least one lower-case character

By default RetailOS uses [haveibeenpwned.com](http://haveibeenpwned.com) to detect and prevent passwords being used that have appeared in previous data breaches, and will display a message to users to alert them that the password they have entered is considered unsafe.

![Screenshot 2024-06-18 at 11.42.28.png](media://1ef1f30b-b680-4dab-9c5b-fade7cf2a207)

### Forced Password Update

If the password policy for the platform has been updated, the next time a user logs in they will be asked to set a new password that conforms to the new policy.

## Recent Users

The recent user list stores the usernames of the last 15 users (this can be reduced if required) that logged into the platform, including the store they were last logged into. 

> ℹ️ The recent users list is only ever stored locally and is therefore device-specific. There is also an option to remove individuals from the recent users list.

Selecting a user from the recent user's list pre-populates the username/email address field so you only need to enter your password to re-authenticate. This functionality is particularly useful if your store staff are sharing a device.

> ⚠️ If you wish to login to a different store, instead of using the recent users list you will need to manually re-enter your username/email and password before selecting from the list of available stores.

![image](media://db3d28fb-abc6-4eb7-a922-6aae13cfd033)

## Account Lock

If a user enters their password incorrectly **5 times** their account will become locked. To unlock their account they can either reset their password or alternatively they can ask their manager or an admin of the system to unlock their account.

![image](media://327c67f6-a56d-475b-a59a-c4af1b655001)

> ℹ️ Managers or Admins of the system can locate locked user accounts via ‘My Team’ (located within the global menu). To unlock the account, select the user to view their details, select “Unlock” under the “Password” section and set them a new password. The full permissions matrix can be found [here](https://redantdigital.atlassian.net/wiki/spaces/RET/pages/edit-v2/79593517).

### Forced Account Lock

User accounts are automatically locked if they have been inactive for 3 months. These users won’t be able to log in to the platform until their account is unlocked at a database level.

> ℹ️ The inactivity period is derived from the `updatedAt` timestamp located within the users table.

### Screen Lock

If the device is left idle for 10 minutes (the time limit can be adjusted), the screen lock will be invoked requiring the user to enter their password in order re-access the application.

> ℹ️ Alternatively, a user can log the previous user out and log in to begin a new session.

## Learn More

- [SSO (single-sign-on)](https://redantdigital.atlassian.net/wiki/spaces/RET/pages/362250241)
- [User Management](https://redantdigital.atlassian.net/wiki/spaces/RET/pages/79593517)