This is off at every property until somebody turns it on, and most hotels should leave it off. The ordinary sign in, a passkey on a personal device, is the default and the recommendation. Read on only if the description below is recognisably your front desk.
Who this is for
Some hotels do not allow front desk staff to carry phones on shift, and have one computer that four people use across a day. That breaks the normal arrangement in both directions: a passkey assumes a device that belongs to one person, and an authenticator app assumes a phone within reach. Neither is true at that desk.
For those properties, a manager enrols the machine once. After that the computer shows a list of names and a keypad instead of the usual email form, and each person signs in with their own six digit PIN. Everybody is still signing in as themselves, so the activity log and every permission keep working exactly as before.
Turning it on, once
All of this lives in your own profile, on the Security and sign-in tab, under Shared front-desk computers. It is only visible to owners and administrators, so if you cannot see it, you are not the person who does this.
Prostay numbers the steps on the screen, and there is a fourth that is not numbered because it is just signing out.
| Step | What it does |
|---|---|
| 1. Turn on PIN sign-in for this property | Switches the feature on for the whole property. Nothing changes for anybody yet. |
| 2. Trust the front-desk computer | Do this while sitting at the front desk machine, in the browser staff will actually use. Give it a name you would recognise in a list. Trusting a browser that is already trusted renames it rather than adding a duplicate. |
| 3. Each person chooses their PIN | Staff set their own. Somebody who can sign in normally is asked for a PIN and nothing else. Somebody who cannot needs a temporary PIN from you, covered below. |
| 4. Hand the desk over | Sign out. Trusting the machine deliberately leaves you signed in, because the computer is no use until staff have PINs. Signing out is what puts the keypad on screen. |
What staff do at the desk
On a trusted computer the sign in screen is replaced by a Shared terminal screen asking Who is signing in?. The person picks their name, then types six digits on a keypad big enough to use without looking for the mouse.
The first time, they will not have a PIN yet. Somebody who can also sign in the normal way should do that once from any machine, at which point Prostay asks them to Choose your own PIN and nothing else. No authenticator app, no backup codes, no passkey. For anybody who cannot get in at all, a manager issues a temporary PIN.
Changing a PIN later is in the same place as everything else: the Security and sign-in tab of their own profile, with Change PIN. It asks for the current one first, and it will not accept the PIN they are already using.
Giving somebody a temporary PIN
On Users, edit the person and find Front-desk PIN. Set a temporary PIN lets you type six digits and hand them over. This is for a new starter at a desk with no mailbox to hand, or somebody who has forgotten their PIN in the middle of a shift and needs to work now.
A PIN you set opens the door exactly once. The next time that person signs in, Prostay makes them choose their own before letting them do anything, and it will not accept the one you gave them. Prostay also emails the account holder to say you did it, and both your action and their replacement go into the activity log.
That is deliberate and it is worth explaining to managers who find it inconvenient. A PIN somebody else knows is a PIN that cannot prove who was standing at the desk, and knowing that is the only reason to give people separate PINs in the first place. There is no way to set a permanent PIN for somebody else, and there is no way for anybody, including you, to read an existing one.
Clear PIN is the other tool. It removes the PIN and sets nothing in its place, so the person chooses their own next time they sign in normally. Use it when somebody has left the desk team, or when nobody needs to be let in this minute.
Who cannot use a PIN
Owners and administrators are excluded and keep passkeys and email links. So is any account that can reset a colleague's sign in or change roles, and so are booking source partners who have been given a login to see availability.
The reason is that a PIN is a short secret typed in the open, at a desk, in front of guests. That is an acceptable risk for the account that checks people in and a poor one for the account that can grant permissions to anybody in the building. Those accounts see Sign in another way on the keypad screen, which returns them to the ordinary sign in.
The rules worth knowing before you turn it on
| Rule | Detail |
|---|---|
| Five wrong PINs locks the account | For fifteen minutes, and only that person, on that property. Everybody else can still use the desk. |
| The machine locks after five minutes idle | Rather than the usual thirty. A shared computer changes hands constantly, so it returns to the keypad quickly. Prostay says as much on the enrolment card. |
| Obvious PINs are refused | All the same digit, runs like 123456 or 654321, and repeats like 121212 or 123123. Staff will try these, so warn them. |
| An unused computer stops working after ninety days | A machine nobody has signed in on for ninety days quietly stops accepting PINs. Nothing is broken; a manager trusts it again. |
| Setting a PIN signs that person out everywhere else | Expected, and worth mentioning to somebody who had Prostay open on another machine. |
| A PIN sign in is a full sign in | Same permissions, same activity log, same new device email as any other. Both successes and failures are logged with the name of the terminal. |
When the keypad will not let somebody in
| What the screen says | What to do |
|---|---|
| Too many wrong PINs. This account is locked for 15 minutes. | Wait it out, or have them sign in another way from a different machine. An administrator can clear the PIN and issue a temporary one if the shift cannot wait. |
| This computer is no longer trusted. Ask your manager to set it up again. | The trust was removed, the browser data was cleared, or ninety days passed with nobody using it. An owner or administrator repeats step 2. |
| Nobody has set a PIN on this property yet. Sign in another way to set yours. | Step 3 has not happened. The first person signs in normally and is asked to choose a PIN. |
| Somebody's name is missing from the list | They are an owner or administrator, their role was never configured, or they are a booking source partner. All three are excluded on purpose. See who cannot use a PIN, above. |
| The keypad never appears, only the usual email screen | This browser is not the enrolled one. Check it is the same browser, and that its site data has not been cleared. |
Where to go next
- Signing in without a password, which is what everybody else at the property does.
- Setting up your sign in, for the ordinary three step setup that PIN users skip.
- Users, roles and permissions, for roles, which decide who is eligible for a PIN.