Skip to content

Your account & sessions

Beyond signing in, your account has a few things worth knowing about: your own profile, the sessions that represent where you’re signed in, and the fact that access is logged. This overview describes how those work today.

Your account holds your own details and is the identity everything you do in the admin is tied to. Because CIQRA gives each staff member their own account, your profile is what lets roles and permissions apply to you specifically — see Staff roles & permissions.

A session is an active sign-in tied to your account — the state that keeps you signed in after you’ve completed the two-step sign-in. Sessions are managed, which is part of how CIQRA keeps access under control rather than leaving you signed in indefinitely and everywhere.

🔴 This section used to say “recording who reached the admin and when” was part of the security baseline. Measured, that is not what happens on your admin, so it has been corrected.

Changes are recorded. An action that alters something can be attributed to an individual account — which is exactly why individual sign-ins beat shared logins.

Sign-in and sign-out are not recorded on the merchant admin, and neither are reads. The identity and token paths are deliberately kept outside the component that writes audit events. CIQRA’s own operator console is audited in full; that is a different surface from yours. The measured detail is in Transparency.

CIQRA has a central Settings area — billing, domains, languages, notifications, roles, payments, shipping and more.

This page still concentrates on your account, staff roles and sign-in security, because those are the parts that have been checked against the real screens. Settings has not been written up step by step yet, and that is a gap in these pages, not in the product.