Description:
When a company has storefront login enabled but specific contacts have been disabled (e.g. only a few approved contacts are allowed to place orders), any new contacts that sync in from the PSA currently default to login enabled. This creates a security/access control gap: an unapproved new starter could find the storefront URL and log in before anyone has had a chance to review their access.
The expected behavior is that new contacts inherit a disabled login state by default, so access has to be explicitly granted rather than revoked after the fact.
Use case:
An MSP enables storefront login for a company but restricts it to a small number of approved contacts. A new employee joins that company and syncs in via the PSA integration. That contact immediately has login access without any action from the MSP, undermining the access control they thought they had in place.
Proposed solution:
Add a setting at the company level that controls the default login state for newly synced contacts. When set to disabled, any new contact synced into that company would have login disabled until manually enabled.
Please authenticate to join the conversation.
New
Feature Request
About 10 hours ago
Get notified by email when there are changes.
New
Feature Request
About 10 hours ago
Get notified by email when there are changes.