Help Center
Find detailed guides and information for all RosterMates features
Security
The Security page in Settings looks after your own login: the devices that are signed in to your account, two-factor authentication, trusted devices, and account deletion. Every user has their own Security page β it controls your account only, not your team's, so an employee and an administrator each manage their own from the same place. Roles and permissions, which control what other people can do, are set up separately under Settings, Roles.
Why the List Exists
RosterMates keeps you signed in. Once you log in on a browser or in the app, you stay logged in until you sign out β there is no idle timeout that quietly logs you off. That is convenient, but it also means a device you used once and forgot about stays signed in. The Signed-in devices list shows every one of them so nothing is signed in without you knowing.
What the List Shows
Each row is one device that is currently signed in to your account:
- Device β the browser and operating system we can identify from the device, for example "Chrome on Windows 10/11" or "Safari on iPhone". Logins from the RosterMates phone app appear as "RosterMate app on Android" or "RosterMate app on iPhone".
- IP address β the network address the device connected from. Useful for spotting a login from somewhere you have never been.
- Signed in β when that device logged in.
- Last active β the most recent time that device used RosterMates.
The device you are reading the page on is highlighted and marked This device, so you can always tell which row is you.
Signing a Device Out
Click Sign out on any row other than your own, confirm, and that device is signed out immediately. The next thing it tries to do in RosterMates sends it back to the login page. Nothing else about your account changes: your other devices stay signed in, your password stays the same, and the person using that device simply has to log in again if they are entitled to.
The phone app counts as a device in its own right, so signing it out logs it out of the app and it has to log in again. A phone that is signed in both in the app and in its web browser appears as two rows β sign out the one you mean, or use Sign out others to catch both.
Signing Out Everywhere Else
If you have lost a laptop or phone, or you just want a clean slate, use Sign out others. Every device except the one you are using is signed out in one go, so you do not have to work through the list. You stay signed in where you are.
When a Device Drops Off the List Itself
A device leaves the list when it signs out, when you sign it out, or when its login finally expires on its own. Browser logins last a year from the last time they were used; phone app logins last about a month from the last time the app connected. A device you have not touched for longer than that could not get back in anyway, so it stops being listed.
If You See Something You Do Not Recognise
Sign the device out first, then reset your password so the old password cannot be used to log straight back in. Turning on two-factor authentication at the same time is the best way to stop it happening again.
What It Does
Two-factor authentication (2FA) asks for a 6-digit code from an authenticator app on top of your password, so knowing your password alone is not enough to get in. It works with any standard authenticator app, including Google Authenticator, Microsoft Authenticator, Authy and 1Password.
Turning It On
Click Set Up 2FA on the Security page. You will see a QR code and, underneath it, the same secret key in text form. Scan the QR code with your authenticator app, or type the key in by hand if scanning is not an option. The app then starts producing a new 6-digit code every 30 seconds. Enter the code it is showing to confirm the setup, and 2FA is on.
Keep the authenticator app somewhere you will not lose it. If you lose access to it you will need to contact support to get back into your account.
Signing In With 2FA On
After your email and password, you are asked for the current code from your authenticator app. There is a Remember this machine tickbox on that screen β see Trusted Devices below.
2FA applies to the phone app as well as the website, so you are asked for a code when you log in to the app too.
Turning It Off
To disable 2FA you have to enter a current code from your authenticator app first. That is deliberate: if someone else got hold of an open session on your computer, they should not be able to quietly strip the protection off your account. Once it is off, the authenticator key is reset and every trusted device is cleared, so switching 2FA back on later means scanning a fresh QR code.
How a Device Becomes Trusted
When you sign in with 2FA, ticking Remember this machine marks that browser as trusted. For the next 90 days it skips the 6-digit code step and goes straight in after your password. Only tick it on devices that are genuinely yours β not on a shared or public computer.
The Trusted Devices card only appears when 2FA is switched on, because trusted devices are only about skipping the code step.
Revoking Trusted Devices
Revoke All clears the list, so every device has to enter a 6-digit code again at its next login. Revoking also signs your devices out of RosterMates, so expect to log in again afterwards.
Trusted devices and signed-in devices are two different lists doing two different jobs. Trusted devices decide whether a device has to type a 2FA code; signed-in devices decide whether it is logged in at all. Revoking trust does not by itself sign a device out, and signing a device out does not remove its trust.
Changing Your Password
Use Forgot your password? on the login page. We email you a reset link, and the new password takes effect straight away. Resetting your password also ends your sessions on other devices, though a device that is sitting idle can take up to half an hour to notice. If you need a device out right now, sign it out from the Signed-in devices list as well β that takes effect immediately.
Too Many Failed Attempts
Five failed sign-in attempts lock the account for 30 minutes. We email you when it happens, including the time and the IP address the attempts came from, so you know about it even when it was not you. Nobody got in β every attempt during a lockout is refused. If it was you, simply wait the 30 minutes out.
Who Can Delete Their Own Account
Any employee or manager can delete their own RosterMates account from the Security page. Company administrator accounts cannot, because the company's data belongs to that account β transfer ownership to someone else first, or contact support to close the company properly.
The 90-Day Grace Period
Nothing is removed straight away. Your account stays recoverable for 90 days, and simply logging back in during that window cancels the deletion and restores everything. After 90 days the account and your personal data are permanently removed.