> ## Documentation Index
> Fetch the complete documentation index at: https://guide.garde.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & access

> Keep logins and permissions tight.

## How sign-in works

* **Dashboard**: work email magic link, Google, or Microsoft. No passwords to leak or forget.
* **Garde app**: email verification code or Google sign-in.
* Sessions are secured and mobile tokens can be revoked if a phone goes missing.

## Who sees what

Access is gated two ways, and both apply at once:

* **By role**: a line cook doesn't see payroll runs. An accountant doesn't need scheduling.
* **By location**: a manager at one store sees that store, not the whole chain.

Owners and admins control this under **Settings → Member management** in the dashboard.

## Keep it tight

* Invite people with their own work email. Never share a login.
* Give the smallest role that does the job. Upgrade later if needed.
* Someone leaves? Remove them from member management the same day.
* Lost phone? Have the employee sign in from a new device and contact support to revoke the old session if you're worried.

One shared login is one ex-employee who still has your P\&L.
