Account & Security
This section is about who can get into your store and how securely they do it — your own account, the people on your team, and the protections around signing in. Staff sign in with a two-step (password + 2FA) flow, access is controlled by roles and permissions, and sessions are managed. Changes are recorded to an individual account; sign-in itself is not — see Transparency.
Frequently asked questions
Section titled “Frequently asked questions”How do staff sign in to CIQRA?
Section titled “How do staff sign in to CIQRA?”Through a secure two-step flow — your password plus a two-step (2FA) verification code — entered on a dedicated CIQRA identity page, never on the store itself. Keeping credentials on one identity page is what keeps your admin protected. See Sign-in & security, and what is and is not recorded.
What if I lose my two-step (2FA) device?
Section titled “What if I lose my two-step (2FA) device?”For security, 2FA codes can’t be bypassed. Recover access through your workspace owner or by contacting CIQRA support, who can help restore your sign-in. A password reset alone won’t resolve a lost 2FA device.
How do I control what my team can access?
Section titled “How do I control what my team can access?”With roles and permissions. Permissions are scoped to areas of the product — catalog, orders, customers, analytics, CMS and settings — so you grant each teammate a role that fits their job and nothing more. See Staff roles & permissions.
Can I give someone access to just orders?
Section titled “Can I give someone access to just orders?”Yes. Because permissions are scoped by area, you can grant order-related capabilities without also granting the ability to change settings or edit your catalog. Grant the narrowest role that lets someone do their job.
What is a session?
Section titled “What is a session?”A session is an active sign-in tied to your account — what keeps you signed in after you complete the two-step sign-in. Sessions are managed, which is part of how CIQRA keeps access under control. See Your account & sessions.
Is admin access logged?
Section titled “Is admin access logged?”Partly, and the honest answer is worth an extra sentence.
Actions that change something are recorded and can be attributed to an individual account — which is the reason to give each teammate their own sign-in rather than sharing one.
Sign-in and sign-out on the merchant admin are not recorded, and neither are reads: “who looked at this” is not a question the trail can answer today. CIQRA’s own operator console is audited in full, which is a different surface from yours. The measured detail is in Transparency → Sign-in protection & audit.
Is there a central Settings screen?
Section titled “Is there a central Settings screen?”Yes. CIQRA has a central Settings area covering billing, domains, languages, notifications, roles, payments, shipping and more.
This section does not walk through it step by step yet. That is a documentation gap, not a product one — and we would rather name it that way round than let a missing article imply a missing feature.