Skip to main content

Two-step verification: Admin setup

Protect your business and client data with more secure staff login

Written by Jozlyn Miller

How to set up two-step verification

Two-step verification, also known as two-factor authentication (2FA) or multi-factor authentication (MFA), adds an extra layer of protection to your Boulevard account. When you turn on two-step verification, logging in requires not just your password, but also a one-time security code either texted to your phone number or sent via an authentication app. This makes it much harder for anyone else to access your account, even if they know your password. Two-step verification can be required business-wide, for specific staff or groups of staff, or turned on voluntarily by individual employees. (See Choosing which staff are required to use two-step verification below.)

Why use two-step verification?

  • Stronger account security: Passwords alone can be guessed, stolen, or reused. Two-step verification adds another barrier against unauthorized access.

  • Protects sensitive client data: As a self-care business, your Boulevard account contains valuable client information and payment details. Two-step verification helps keep that safe.

  • Reduces risk of fraud: Extra verification prevents attackers from using stolen credentials to log in.

  • Supports compliance needs: Many businesses, especially medspas, require stronger login security for HIPAA and other data privacy standards.

For Business Admins: Turning on two-step verification for your business

  1. Go to Manage Business > Security

  2. Toggle Two-step verification to On to require it for all employees

3. Confirm that you'd like to require two-step verification for all employees.

- All employees will immediately receive an email notification.

Once enabled, every staff member will need to set up one of two ways to authenticate upon login:

  1. They can set up a verification app of their choice (recommended route)

  2. They can enter their mobile number to receive texted verification codes (US or Canadian mobile number (+1) country code required)

Choosing which staff are required to use two-step verification

Turning two-step verification on for your whole business isn't your only option. Admins and staff with the Manage staff login settings permission can also require it for specific people, or for groups of staff who share a permission group or location — without affecting anyone else.

Option 1: Require it for one staff member

  1. Go to the staff member's profile under Manage Location > Staff > [Staff name] or Manage Business > Staff > [Staff name].

  2. Scroll down to Two-Step Verification and toggle it on for that individual.

That staff member will need to set up two-step verification the next time they log in.

Option 2: Require it for a group of staff

  1. Go to Manage Business > Security.

  2. Next to two-step verification, select Manage, then Edit.

  3. Search for the staff name(s) or select Add Filters to narrow the list.

  4. Choose a filter type — Permission group (e.g., Admin, Location Manager) or Location. For example, filtering by Permission group = Admin will pull up everyone in your Admin group.

  5. Review the list of matching staff. You can select all of them, or adjust to include only some.

Automatically include future staff

Toggle on Automatically enable two-step for future staff if you want all new staff added to your business later — regardless of whether they match the same permission group or location — to be automatically required to use two-step verification.

Confirming the change

Select Continue, then confirm. As with the business-wide setting:

  • Every affected staff member will need to set up two-step verification the next time they log in (if they haven't already), and will need to enter a code every time they log in going forward.

  • Affected staff will receive an email notification.

For more on the staff login experience with two-step verification enabled, review the Logging into Boulevard article.


Turning off two-step verification for your business

Follow the same steps as above to turn off two-step verification for your business.

For enhanced security, employees who activated two-step verification while it was enabled for the entire business will be required to continue using it for login. They can turn it off in their individual settings as long as it is not required by the business. If they are unable to access their account, contact support chat for help resetting their account.


Extra verification for billing and payment pages

Separate from signing in, Boulevard requires a verification code before anyone can view or change your most sensitive financial settings:

  • Manage Location > Payment processing

  • Manage Business > Payment processing

  • Manage Business > Billing

Why: one of the threats we actively defend against is an attempt to redirect your payouts to a fraudulent bank account. Requiring a second step here means a stolen password alone isn't enough to move your money.

This applies to everyone with access to those pages, including Admins. It's a protection on the page itself, not something your permission level exempts you from.

What you'll see: a prompt for a 6-digit code when you open one of those pages. Enter the current code from your text message or authenticator app to continue.

If you haven't set up two-step verification yet, you'll be asked to set it up before you can access these pages.

If you enter the wrong code, you won't be locked out of your account. You just won't be able to view or change those pages until you enter a valid code.

Did this answer your question?