How ApexOS keeps the wrong people out.
Passkeys, two-step verification, sign-in rules you set for your whole team, and firm limits on what Staylist’s own staff can do. Everything below is in ApexOS today.
Signing in
Stronger ways in than a password, and no codes sent by text or email.
Passkeys, up to 10 per person
Each person can add up to 10 named passkeys to their own profile and use them in every account they can reach. Removing one asks them to confirm first.
Sign in with only a passkey
Your team can sign in with a passkey alone, from a button or the browser’s passkey autofill. No email or password to type.
Google or Microsoft
Team members who already have an ApexOS user can sign in with their Google or Microsoft account.
Two-step verification without text messages
When two-step verification is on, ApexOS asks for an authenticator app code, a passkey or a single-use recovery code. It never texts or emails your team a sign-in code.
Recovery codes that work once
Setting up an authenticator app creates single-use recovery codes. They are shown only until you confirm you saved them, and you can make a new set at any time.
Lockouts and deactivated users
Repeated wrong passwords lock sign-in for a while, though a passkey still works. Deactivated users can’t sign in at all.
Rules you set for your team
Decide who has to use strong sign-in, and make the risky changes ask twice.
Require strong sign-in
An organization can require an authenticator app or passkey for no one, for its admins and account owners, or for everyone. People get 7 days to set one up.
Properties can tighten the rule, never loosen it
Each account inside an organization follows the organization’s rule. It can choose a stricter one, and a weaker choice is refused.
Nobody drops their last factor
If your rule requires strong sign-in, ApexOS won’t let anyone remove their last authenticator app or passkey until they add another.
Risky changes ask for a fresh check
Inviting team members, changing roles and permissions, removing, activating or deactivating people, and changing the sign-in rule all need a password or passkey check from the last 15 minutes. Each one is logged.
What Staylist can and can’t do
The limits on our own staff, and what we do when an account may be at risk.
Our staff use strong sign-in too
Staylist staff can open a customer account only after signing in with an authenticator app or a passkey.
We can freeze access fast
If an account may be compromised, Staylist security staff can freeze a user’s access. Every sign-in method is blocked, every session ends and the user is told. Lifting the freeze doesn’t sign them back in.
Lost every sign-in method? Support resets it
Only Staylist support can reset a person’s sign-in methods. Not the person, and not your own admins. A reset removes every passkey, authenticator and recovery code and signs out every session.
A security questionnaire, or a question this page doesn’t answer?
Send it to us. We’ll answer in writing, from what the product does today.
Contact usQuestions teams ask us.
Can I require two-step verification for my whole team?
Yes. An organization can require an authenticator app or a passkey for no one, for its admins and account owners, or for everyone. People get 7 days to set one up, and each property can choose a stricter rule but not a weaker one.
Does ApexOS send sign-in codes to my team by text or email?
No. Two-step verification for your team uses an authenticator app code, a passkey or a single-use recovery code. ApexOS never texts or emails your team a sign-in code.
Can my team sign in without a password?
Yes. Anyone can sign in with a passkey alone. Team members who already have an ApexOS user can also sign in with Google or Microsoft.
Can Staylist staff get into my account?
Staylist staff can open customer accounts, and they must sign in with an authenticator app or a passkey to do it. Staylist security staff can also freeze a user’s access if an account may be compromised.
What happens if someone loses their phone and their passkeys?
They can sign in with one of their single-use recovery codes. If those are gone too, Staylist support resets their sign-in methods. Your own admins can’t do that reset, and the person can’t do it themselves.
